Incident Response KitFree severity check

Rogue or misbehaving AI agent: incident response playbook

Use it when: An AI agent sent, deleted, bought, changed or shared something nobody approved, is looping or spending, or is acting outside the task it was given.

First 15 minutes

  1. Stop the agent: use its kill switch, pause the workflow or disable its account.
  2. Revoke its tokens, API keys and connections to email, files, payments and code.
  3. Record what it was asked to do, when it started and who owns it.
  4. Tell the incident lead and set the severity: SEV2 or higher if it touched customers, money or production.

Set the severity and download a first-response checklist

What the full playbook covers

The full playbook is in the Incident Response & Business Continuity Kit with 11 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.

Other playbooks

Incident Response & Business Continuity Kit

More free security and AI governance tools