When a workplace accident is narrowly avoided, a responsible organisation doesn't record "no harm" and move on. It records the near miss, asks what made it possible and strengthens the process before somebody is injured.

Public bodies should apply the same discipline to AI.

An AI near miss doesn't prove the process was safe. It shows an error reached the point where harm was possible, and was stopped, sometimes by a control and sometimes because somebody happened to notice.

In July 2026, the High Court recorded in Andreea-Maria Tobosaru v Court of Law Craiolva, Romania that two non-existent legal authorities had appeared in formal submissions made on behalf of the Crown Prosecution Service. The CPS said generative AI may have been the immediate source but identified the operative cause as inadequate verification.

The false authorities passed from one document into another and survived the permission stage. They were identified before the substantive extradition hearing, did not affect the outcome, and were not put forward deliberately. The CPS apologised, reviewed 78 other cases handled by the same lawyer and shared the learning internally.

That was a proportionate response, and a good example of an organisation learning from what happened.

It also raises a broader question for any near-miss review. Checking one person’s other cases answers whether that person repeated the error, a narrower question than it first appears. The broader one is whether the same workflow remains available to others doing similar work. Then it is whether the next error will be caught by a designed control or only because an individual questions material they cannot verify.

The recovery happened, but not because the earlier stages were designed to catch this kind of error. The absence of harm should not be mistaken for evidence of a safe process.

Health and safety practice has long recognised that distinction. HSE's own guidance on investigating incidents asks organisations to identify immediate, underlying and root causes, not just record that harm was avoided. The absence of injury doesn't prove the controls were sound.

AI-assisted work should be treated in the same way.

An invented source caught before filing, an inaccurate summary corrected before a decision, personal information almost entered into an unsuitable tool, or an automated recommendation challenged before action may leave no obvious victim. Each still reveals a weakness that could recur when the final barrier doesn't hold.

Many organisations still treat AI as a technology to be approved rather than a process to be governed. Responsibility sits with digital, legal, procurement or information-governance teams, while the consequences show up in ordinary work: court submissions, safeguarding assessments, police reports, consultation summaries, benefit decisions and council correspondence.

Digital teams can assess a tool. Process owners need to understand what it changes in the work.

AI doesn't need a parallel universe of governance. It requires a route into the risk registers, quality systems, supervision and incident review organisations already use to manage operational work.

A useful near-miss review asks more than whether the model was wrong. It asks whether the task was suitable for AI, whether the organisation could reconstruct what the system produced and what the user changed, which safeguard failed and which one worked, and whether the person who found the problem felt able to report it.

Record-keeping is essential. Axon's Draft One generates draft police narratives from body-worn camera audio. It’s current US documentation allows agencies to configure retention of the original AI-generated draft and records use through audit logs. That gives organisations a basis for comparing the machine output with the final report. Without it, a corrected error can disappear inside the finished document, taking the learning opportunity with it.

The harder problem is institutional memory. If one public body identifies an AI failure mode, another shouldn't have to discover it independently.

NIST's guidance on generative AI already recommends recording and tracking errors, near misses and negative impacts. Government should bring that principle into routine operational governance, using a common reporting language and sharing anonymised themes and safeguards across sectors.

The reporting culture matters just as much. An honest error disclosed promptly isn't equivalent to reckless use, concealment or deliberate fabrication. Treat every disclosure as misconduct, and the most valuable warnings stay hidden until the consequences are harder to contain.

More reported near misses doesn't necessarily mean an organisation is becoming less safe. It may mean staff are noticing problems, speaking up and letting the system learn.

One public body's close call should become another's safeguard.

This is written in a personal capacity and does not represent the views of apolitical or the author's workplace.