AI and agent incident response playbook
AI incidents move fast: an agent keeps acting, a hidden instruction keeps working, a cloned voice keeps calling. The first rule is the same for all of them: stop it first, then investigate.
The full AI and Agent Incident Playbook is in the Incident Response & Business Continuity Kit ($249), with the rest of the first hour, containment, recovery, who to notify and a first-hour log for each.
Before it happens
- Keep an inventory of every AI tool and agent in use, with a named owner for each.
- Know how to stop each agent in under five minutes: a kill switch, a paused workflow or a disabled account.
- Give agents their own accounts with only the access their task needs, never a person's login.
- Turn on logging of agent actions and keep the logs for at least 90 days.
- Require a human approval step before an agent sends, pays, deletes or publishes.
- Agree a code word or call-back rule for urgent payment and bank-detail requests.
Data leaked to an AI tool
Use it when: Confidential or personal data, source code or a secret was pasted or uploaded into an AI tool that isn't approved for it, or an AI tool shared it with someone it shouldn't.
First 15 minutes
- Record what data, which tool, which account and when.
- Delete the conversation or data in the tool if possible, and check the tool's retention and training settings.
- Revoke the tool's access to company accounts, files and APIs.
- Rotate any secrets or keys that were exposed.
Data leaked to an AI tool playbook page · Set the severity now
Rogue or misbehaving AI agent
Use it when: An AI agent sent, deleted, bought, changed or shared something nobody approved, is looping or spending, or is acting outside the task it was given.
First 15 minutes
- Stop the agent: use its kill switch, pause the workflow or disable its account.
- Revoke its tokens, API keys and connections to email, files, payments and code.
- Record what it was asked to do, when it started and who owns it.
- Tell the incident lead and set the severity: SEV2 or higher if it touched customers, money or production.
Rogue or misbehaving AI agent playbook page · Set the severity now
Prompt injection against an AI assistant or agent
Use it when: An AI assistant or agent followed instructions hidden in an email, document, web page, ticket or tool description, instead of its user's.
First 15 minutes
- Stop the assistant or agent and disconnect the tools it can use.
- Keep the input that carried the instruction (email, file, page, ticket) without opening it again in the AI tool.
- Record what the AI did after reading it: messages sent, data shown, actions taken.
- Rotate any secret or token the AI could see.
Prompt injection against an AI assistant or agent playbook page · Set the severity now
Deepfake or voice-clone payment fraud
Use it when: Someone was asked to pay, change bank details or share access by a call, voice note or video that sounded or looked like a colleague, executive or supplier.
First 15 minutes
- If money was sent, call your bank's fraud line now and ask them to recall or freeze the payment.
- Call the real person on a number you already had, not one from the message.
- Keep the recording, voice note, video link, call log and any messages.
- Stop any other payment or bank-detail change linked to the same request.
Deepfake or voice-clone payment fraud playbook page · Set the severity now
What's in the kit's AI and Agent Incident Playbook
- 4 AI incident playbooks: data leaked to an AI tool, rogue or misbehaving AI agent, prompt injection against an AI assistant or agent, deepfake or voice-clone payment fraud
- Minutes 15–60 for each (16 more steps), then containment, eradication and recovery
- Who to notify and the evidence to keep, for each
- A severity starting point and a first-hour log for each incident
- A tabletop exercise, "The helpful AI agent", and AI incident types in the workbook's incident log
Governing the AI tools themselves (policy, inventory, risk register)? The AI Governance Toolkit pairs with this playbook.
Not legal advice: notification duties depend on your laws, contracts and insurance.