I see what you mean but… think of a conventional security issue around an AI like you would a chemical spill. Even though the failure may have been something boring like a bad seal, we could still call it a “hazardous chemical incident” or such.
If OpenAI feeds their staff lunch that's gone off and everybody gets sick, is that really an AI incident?
AI didn't get accidentally or wrongfully or damagingly applied to anyone. The thing that leaked was not AI.
So it's like having hazardous chemicals around, but the bad seal wasn't on a container that had hazardous chemicals in it.