Explore our AI courses, practical training for non-technical teamsExplore courses Explore AI courses
MarketingCommsHow-To

How to Use AI for Crisis Communications

In one survey, half of companies had no documented crisis plan at all, and rehearsal is rarer still. AI fixes that problem cheaply, which is a far better use of it than letting it write your holding statement at 11pm.

TLDR: Use AI heavily before a crisis: scenario lists, message matrices, tabletop rehearsals. Use it narrowly during one: monitoring, triage, first drafts. Never let it speak for you unreviewed.
84%Of consumers say response speed shapes a crisis view
49%Of surveyed US businesses had a documented plan
98%Of leaders who activated a plan called it effective

Share this article

The Short Version

The instinct with AI and crisis comms is to reach for it in the moment, which is exactly backwards. The moment is when your facts are still moving, your liability is highest and your tolerance for a confident wrong sentence is zero. The real value sits in the preparation nobody does: in Capterra’s survey of US business leaders, only 49% had a documented crisis communications plan, and rehearsal is rarer still. AI makes that preparation cost hours instead of weeks. This guide covers what to build in advance, what AI can safely do during a live incident, the tribunal ruling and the incidents that define where the line sits, the deepfake scenario missing from every plan written before 2024, and the fact that your two regulatory clocks start at different moments.

The clock you are actually racing

Sprout Social surveyed 2,250 social media users across the US, UK and Australia in May 2026 and found something that should reorganise how most companies think about this. 84% said a brand’s response speed directly affects their view of the crisis. 64% said it matters that brands respond publicly on social media rather than through a press release or a statement buried on a website.[1]

The good news in the same research is that recovery is real. 51% of consumers would consider buying from a brand within a few months of a crisis being properly addressed, and 20% would come back within days.[1] People are more forgiving than comms teams assume. They are just not patient.

What is at stake, meanwhile, is not a news cycle. Weber Shandwick’s 2020 research with KRC, covering 2,227 executives across 22 markets, found they attributed on average 63% of their company’s market value to reputation.[2] And crises are not rare events you can plan around. PwC’s global survey of 1,812 business leaders across 42 countries found 91% had experienced at least one significant disruption beyond COVID, averaging 3.5 disruptions in two years, with 76% saying their most serious one had a medium to high operational impact.[3]

So the brief is: respond fast, respond where the audience is, and be right. The temptation is to use AI to solve the “fast” part. That is the one part where speed and accuracy trade directly against each other, and it is the worst place to put a tool that produces fluent text at a uniform level of confidence whether or not it is correct.

Almost nobody has a plan

Here is the actual problem, and it is not a technology problem.

Capterra surveyed 243 US business leaders at director level and above in January 2023. Only 49% had a formal, documented crisis communications plan. 28% had something informal and undocumented. 23% had nothing at all or did not know.[4]

Deloitte’s 2018 study of more than 500 senior crisis management, business continuity and risk executives found the same confidence gap from the other end. 84% said their organisation had a crisis management plan, and nearly 90% were confident they could handle a corporate scandal, yet only 17% had actually tested that scenario in a simulation.[5] Organisations that involved their board in crisis exercises were far more likely to report crises declining over the decade. That study is old now, and it surveyed senior executives at large organisations rather than the businesses most of us run, but nothing in the more recent survey data suggests rehearsal has become common since.

There is one more finding from the Capterra data that quietly demolishes the single-scenario plan. Crisis triggers were spread across cyberattacks (28%), technology failures (22%), workplace violence or threats (19%), health-related issues (16%), natural disasters (9%) and public relations crises (6%).[4] If you wrote your plan around one scenario, you have prepared for a coin flip.

And yet the numbers on the other side of that research are extremely encouraging: of leaders who actually activated a plan, 98% said it was effective, including 77% who said it was very effective.[4] The plans work. Most companies just do not have one, because writing one takes a fortnight of somebody’s life and there is always something more urgent.

That is the sentence AI changes. Not the response. The preparation.

Where AI earns its money

Everything below is peacetime work. A human reviews it with time to think, mistakes cost nothing, and the output is reusable. This is where I would put 80% of your AI effort.

Build the scenario list

Most plans cover the three crises the leadership team has personally experienced. Give an AI your business model, your suppliers, your channels, your regulatory footprint and your customer base, and ask it to generate forty plausible failure scenarios grouped by type, including ones you have not experienced. Then have your team score each on likelihood and severity. You will get a handful of genuinely uncomfortable additions to the list, which is the point.

Build the message matrix

This is the deliverable that actually saves you at 11pm. A grid: scenario down the side, audience across the top (customers, staff, investors, regulator, press, partners), with a pre-approved holding statement in each cell. AI is genuinely excellent at generating the first version of that grid, because it is a large, structured, repetitive drafting job with a clear format.

What matters is that a human edits every cell and legal signs the sensitive rows, in peacetime, when there is time. A holding statement written and approved in March is worth ten written in a panic in October.

Run a tabletop exercise without hiring anyone

This is my favourite use and almost nobody does it. The usual barrier is cost, because a properly facilitated exercise is not cheap.

You can run a decent version yourself in ninety minutes. Ask the AI to act as facilitator: it presents a scenario, your team responds, and every fifteen minutes it injects a complication (a journalist calls, a staff member posts on LinkedIn, the fix does not work, a customer’s video goes viral). Ask it to end by producing a list of every question your team could not answer. That list is your action plan, and it is worth more than the exercise itself.

Pre-write the operational assets

Dark site page, email templates, an internal FAQ for whoever answers the phone, social bios that can be swapped, an out-of-hours contact tree. Boring, quick with AI, and completely useless if produced during the incident.

Who does what, by phase

PhaseAI doesA named human does
BeforeScenario generation, message matrix drafts, tabletop facilitation, template production, translationEdits every cell, gets legal sign-off, owns the plan and the review date
DuringSocial listening and sentiment triage, summarising inbound volume, first drafts from approved templates, translating approved copyVerifies every fact, decides materiality, approves every word before it publishes, speaks to press and regulators
AfterCoverage analysis, sentiment recovery tracking, drafting the post-incident review, spotting patterns across inboundDecides what changes, updates the plan, briefs the board

Division of responsibility across the three phases of an incident. The structure follows the crisis communication and crisis leadership clauses of ISO 22361:2022.[6]

What AI can do in a live incident

Once something is actually happening, the useful list gets short. Four things.

Monitoring and triage. This is the strongest live use case by a distance. Volume is the enemy in the first hours: hundreds of mentions, comments, emails and messages arriving faster than a small team can read them. AI clusters that into themes, flags the accounts with reach, tracks sentiment movement over time, and tells you which specific claim is spreading. That is real work, it is fast, and being slightly wrong about a sentiment score costs you nothing.

Summarising inbound for the people making decisions. Your decision-makers do not need 400 comments. They need to know that three distinct allegations are circulating, which one has traction, and what the most-shared post actually says. A rolling AI summary every thirty minutes, checked by a human before it goes into the room, is genuinely valuable.

First drafts from your approved templates. Note the phrasing. Not “write a statement.” Take the pre-approved holding statement from your matrix, feed it the confirmed facts, and ask for an adaptation for a specific channel and audience. You are asking it to adapt approved language, not to originate a position. Those are different jobs with completely different risk profiles.

Translation and channel adaptation. If you operate in multiple markets, translating an approved statement is the fastest hour AI will ever save you, provided a native speaker reviews it before it goes out. Our guide to translating marketing content with AI covers the review process properly.

What is not on that list: deciding what your position is, determining whether something is material, verifying a fact, talking to a journalist, talking to a regulator, or publishing anything without a named human reading every word. None of those are speed problems. They are judgement problems, and the tool has no judgement.

For the customer-facing side of a live incident, our guides on AI in customer service and handling reviews and testimonials cover the day-to-day version of the same problem.

Where AI must not go

I want to make this argument with cases rather than opinions, because the opinion version is easy to wave away.

The liability is already settled. In Moffatt v. Air Canada, decided in February 2024, the British Columbia Civil Resolution Tribunal held Air Canada liable in negligent misrepresentation for incorrect bereavement fare information given by its website chatbot. Air Canada argued that the chatbot “was a separate legal entity that is responsible for its own actions.” The tribunal rejected that outright, holding the company responsible for all information on its website whether it came from a static page or a chatbot, and adding that a consumer cannot be expected to cross-check one part of a website against another.[7] The award was small: C$650.88 in damages plus interest and tribunal fees, roughly C$812 in total. The principle is not.

An AI channel you own can be steered into saying things, in public. DPD disabled the AI element of its customer service chatbot in January 2024 after a customer told it to disregard its rules, got it to swear, and then asked it for a poem about a chatbot that cannot do anything. The bot produced one calling itself useless and describing DPD as “a customer’s worst nightmare.” DPD’s statement: “We have operated an AI element within the chat successfully for a number of years. An error occurred after a system update yesterday. The AI element was immediately disabled and is currently being updated.”[8]

Be precise about what that shows, because both the dramatic version and the reassuring version are wrong. The customer did deliberately push it, so this was not a bot spontaneously turning on its employer. But nobody told it to name DPD, and it named DPD. And the company has never said publicly what the update actually changed. What you are left with is the bit that should concern you: a channel speaking in your name, that a determined stranger can steer, whose behaviour changed without anyone noticing until it was a screenshot. A crisis is precisely when people start pushing.

A single wrong fact in a public AI output is expensive. Google’s own promotional demo of Bard contained a factual error about which telescope took the first image of an exoplanet. Alphabet shares fell 7.7%, wiping roughly $100bn off market value.[9] That was a marketing asset with presumably several people’s eyes on it, in peacetime.

Now add the environment you are operating in. Edelman’s 2026 Trust Barometer, based on roughly 34,000 respondents across 28 countries, found that the increasing prevalence of misinformation is the second-largest shaper of trust over five years, and nearly seven in ten people fear institutional leaders are deliberately misleading the public.[10]

That last finding is the one that should decide your policy. In 2026, a hallucinated fact in a crisis statement does not get read as a mistake. It gets read as a lie. You do not get the benefit of the doubt you would have had five years ago, and you will spend the rest of the incident defending the correction rather than the original issue.

The rule I would write into your plan, in one sentence: AI can monitor, summarise, translate, draft and rehearse. No AI system speaks autonomously to customers, press or regulators during an active incident, and a named human approves every word that publishes.

The crisis you did not cause

Every crisis plan written before 2024 assumes the crisis originates from something your company did. There is now a category that does not.

The engineering firm Arup lost roughly $25.6m across 15 transactions after an employee in Hong Kong joined a video call populated by deepfaked versions of the CFO and colleagues. An Arup spokesperson confirmed to Fortune: “We can confirm that fake voices and images were used.” The company’s CIO, Rob Greig, went on record saying: “This is an industry, business and social issue, and I hope our experience can help raise awareness of the increasing sophistication and evolving techniques of bad actors.”[11]

This is not a one-off. The FBI’s Internet Crime Complaint Center issued a public service announcement in July 2026 warning that scammers “generate videos for real time video chats with alleged company executives, law enforcement, or other authority figures,” and noting that AI-generated videos of a senior FBI leader had been posted on social media to drive victims to a spoofed site.[12]

The World Economic Forum’s Global Cybersecurity Outlook 2026 found 94% of respondents expect AI to be the most significant driver of change in cybersecurity in the coming year, 87% identified AI-related vulnerabilities as the fastest-growing cyber risk, and CEOs now rank cyber-enabled fraud as their top concern, ahead of ransomware.[13]

So add the scenario: a convincing fake of our CEO is circulating. The response to that is a communications deliverable, not an IT one, and it needs building now:

  • A pre-registered verification channel. One place, stated publicly and in advance, where genuine company statements appear. “If it did not come from here, it is not from us.”
  • An internal challenge protocol. A named phrase or a callback rule for any unusual financial or access request made over video or voice, however senior the person appears to be.
  • A pre-drafted “this is not us” statement. Written now, approved now, sitting in the matrix. Trying to write that under pressure while your CEO is being impersonated is not a position you want to be in.
  • Primed journalist contacts. The two or three reporters who cover you, who you can reach directly and who will believe you.

None of this is expensive. All of it is missing from most plans I have read.

Two clocks, two start times

This one catches people out, and it is worth thirty seconds of your attention because the two clocks do not start at the same moment.

If you are a US public company, a material cybersecurity incident must be disclosed on Item 1.05 of Form 8-K within four business days of determining that the incident is material, not of discovering it. The determination itself must be made “without unreasonable delay.”[14]

Under UK GDPR, a reportable personal data breach must be reported to the ICO without undue delay and, where feasible, not later than 72 hours after becoming aware of it. The clock runs from awareness, not from when the breach actually happened.[15] Partial information can be filed and supplemented later.

One clock starts at determination. The other starts at awareness. Both are shorter than the internal escalation process at most companies I have worked with, where a Friday evening issue routinely reaches the right person on Monday.

The first hour, in order

0 to 10 minutes

Verify it is real and verify the source. Do not respond to anything you have not confirmed.

10 to 20 minutes

Assemble the named team. Start the AI monitoring sweep so you know what is actually circulating.

20 to 35 minutes

Establish the facts you can state with confidence, and write down explicitly what you do not yet know.

35 to 45 minutes

Decide which clocks have started and who owns each. Materiality is a human call.

45 to 60 minutes

Adapt the pre-approved holding statement, get a named human to approve it, publish where the audience is.

A sequence for the first hour of an incident. The clock references reflect the SEC four-business-day rule from materiality determination and the ICO 72-hour rule from becoming aware.[14][15]

Build a one-page grid alongside this: who declares an incident, who drafts, who signs off, and which clock has started. AI can pre-populate every notification template you will need. It cannot make the materiality call, and you should not want it to.

If disclosure obligations in marketing are on your list generally, our AI marketing compliance checklist covers the everyday version.

Build the kit this week

Concretely, here is what I would do with two afternoons.

Afternoon one. Generate the scenario list with AI, score it with your team, and pick the top eight. Build the message matrix for those eight across your six audiences. Edit every cell. That is 48 holding statements, which sounds enormous and takes about three hours with a tool doing the first pass.

Afternoon two. Run the AI-facilitated tabletop on the two scenarios that scored highest. Ninety minutes. Capture every question your team could not answer. Fix the top five. Send the sensitive statements to legal for sign-off while you do it.

Then put a review date in the calendar, because a crisis plan written in August and never opened again is a document, not a capability. ISO 22361:2022 is the international standard here if you want a structure to check yourself against: it covers crisis leadership, decision-making under pressure, crisis communication, and validation and learning.[6]

The honest summary is this. AI will not make you better at handling a crisis in the moment. Nothing does, except having decided most of it in advance. What AI does is make the deciding-in-advance cheap enough that you might finally do it. Given that half of businesses have no documented plan at all, and rehearsal is rarer still, that is a much bigger prize than a faster holding statement.[4][5]

For the media relationships that make all of this land, our guide on AI for public relations and media outreach covers building the contacts before you need them, and AI for brand guidelines covers keeping the voice consistent when several people are drafting under pressure.

Frequently Asked Questions

Can AI write a crisis statement?

It can adapt one you approved earlier, which is a different and much safer job. Asking AI to originate a position while facts are still moving puts fluent, confident text in front of the public at the moment your tolerance for error is lowest. In Moffatt v. Air Canada the tribunal held the company liable for incorrect information given by its own chatbot and rejected the argument that the bot was a separate legal entity.[7] Build a pre-approved message matrix in peacetime and have AI adapt from it.

What is the best use of AI in crisis communications?

Preparation, by a wide margin. Only 49% of US businesses have a documented crisis communications plan, and rehearsal is rarer still: in Deloitte’s 2018 study 84% claimed a crisis management plan, but only 17% had simulated the corporate scandal scenario they felt confident about.[4][5] AI turns scenario generation, message matrices and tabletop exercises from a fortnight of work into two afternoons. During a live incident, its strongest use is monitoring and triage: clustering hundreds of mentions into themes so your team knows what is actually spreading.

How fast do we need to respond to a crisis?

Faster than most escalation processes allow, and in public. Sprout Social found 84% of consumers say response speed directly affects their view of the crisis and 64% expect the response on social media rather than in a press release.[1] Regulatory clocks are separate: the SEC requires disclosure within four business days of determining a cyber incident is material, while the ICO requires breach reporting within 72 hours of becoming aware of it.[14][15]

Should our crisis plan include deepfakes?

Yes, and most plans written before 2024 do not. Arup lost roughly $25.6m after an employee joined a video call populated by deepfaked colleagues, and the company confirmed publicly that fake voices and images were used.[11] The FBI warned in July 2026 that criminals are generating real-time video chats impersonating company executives.[12] The comms deliverables are a pre-registered verification channel, an internal challenge protocol, a pre-drafted denial statement and primed journalist contacts.

Can we use an AI chatbot to handle customers during a crisis?

Not autonomously. DPD disabled the AI element of its chatbot in January 2024 after a customer who had told it to disregard its rules got it to swear and to write a poem describing DPD as “a customer’s worst nightmare.” The company said only that an error had occurred after a system update.[8] During an active incident, route customer contact to humans working from approved messaging, and use AI behind the scenes to summarise inbound volume and flag the issues that are gaining traction.

About This Article

This guide draws on survey research from Sprout Social, Capterra, Deloitte, PwC, Weber Shandwick, Edelman and the World Economic Forum, alongside primary sources: the SEC and ICO on disclosure timing, the FBI Internet Crime Complaint Center on deepfake fraud, ISO 22361 on crisis management, and published reporting on the Air Canada tribunal decision, the DPD chatbot incident and the Arup deepfake fraud. Widely circulated crisis statistics that could not be traced to an original study were deliberately excluded.

Sources

  1. Sprout Social. Social Media Is Now the Primary Channel for Brand Crisis Response. 2026. https://investors.sproutsocial.com/news/news-details/2026/Social-Media-Is-Now-the-Primary-Channel-for-Brand-Crisis-Response-New-Research-Finds/default.aspx
  2. Weber Shandwick and KRC Research. The State of Corporate Reputation in 2020. 2020. https://webershandwick.com/news-insights/the-state-of-corporate-reputation-in-2020-everything-matters-now
  3. PwC. Global Crisis and Resilience Survey 2023. 2023. https://www.pwc.com/gx/en/news-room/press-releases/2023/pwc-global-crisis-and-resilience-survey.html
  4. Capterra. 2023 Crisis Communications Survey. 2023. https://www.capterra.com/resources/crisis-communications-plan/
  5. Deloitte. Stronger, fitter, better: Crisis management for the resilient enterprise. 2018. https://www.prnewswire.com/news-releases/despite-rising-crises-deloitte-study-finds-organizations-confidence-exceeds-crisis-preparedness-300671209.html
  6. ISO. ISO 22361:2022 Security and resilience, Crisis management guidelines. 2022. https://www.iso.org/standard/50267.html
  7. American Bar Association, Business Law Today. BC Tribunal Confirms Companies Remain Liable for Information Provided by AI Chatbot. 2024. https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-february/bc-tribunal-confirms-companies-remain-liable-information-provided-ai-chatbot/
  8. ITV News. DPD disables AI chatbot after customer service bot appears to go rogue. 2024. https://www.itv.com/news/2024-01-19/dpd-disables-ai-chatbot-after-customer-service-bot-appears-to-go-rogue
  9. CNN Business. Google shares lose $100 billion after company’s AI chatbot makes an error during demo. 2023. https://www.cnn.com/2023/02/08/tech/google-ai-bard-demo-error
  10. Edelman. 2026 Edelman Trust Barometer. 2026. https://www.edelman.com/news-awards/2026-edelman-trust-barometer-society-slides-into-insularity
  11. Fortune. Arup deepfake fraud: finance worker paid out $25 million after video call with fake CFO. 2024. https://fortune.com/europe/2024/05/17/arup-deepfake-fraud-scam-victim-hong-kong-25-million-cfo/
  12. FBI Internet Crime Complaint Center. Public Service Announcement I-072026-PSA. 2026. https://www.ic3.gov/PSA/2026/PSA260720
  13. World Economic Forum. Global Cybersecurity Outlook 2026. 2026. https://www.weforum.org/publications/global-cybersecurity-outlook-2026/in-full/executive-summary-6efae97d74/
  14. U.S. Securities and Exchange Commission. Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure: Small Entity Compliance Guide. 2023. https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/cybersecurity-risk-management-strategy-governance-incident-disclosure
  15. Information Commissioner’s Office. 72 hours: how to respond to a personal data breach. 2026. https://ico.org.uk/for-organisations/advice-for-small-organisations/personal-data-breaches/72-hours-how-to-respond-to-a-personal-data-breach/
Hina Mian
Hina Mian, Co-Founder of Future Factors AI

Hina is a marketing strategist with over a decade of hands-on campaign experience across B2B and consumer brands. She writes about using AI to run leaner, sharper marketing without losing the human touch. Future Factors offers AI Bootcamps, Corporate Workshops, and Speaking & Consulting for teams that want to put AI to work properly.

More about Hina →

Psst, Hey You!

(Yeah, You!)

Want helpful AI tips flying Into your inbox?

Weekly tips. Real examples. Practical help for busy professionals.

We care about your data, check out our privacy policy.