Rogue or misbehaving AI agent: incident response playbook
Use it when: An AI agent sent, deleted, bought, changed or shared something nobody approved, is looping or spending, or is acting outside the task it was given.
First 15 minutes
- Stop the agent: use its kill switch, pause the workflow or disable its account.
- Revoke its tokens, API keys and connections to email, files, payments and code.
- Record what it was asked to do, when it started and who owns it.
- Tell the incident lead and set the severity: SEV2 or higher if it touched customers, money or production.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (2 steps)
- Eradicate (2)
- Recover (1)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 11 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.
Other playbooks
- Phishing and business email compromise
- Ransomware
- Lost or stolen device
- Data sent to the wrong person or exposed
- Compromised account or cloud admin access
- Malware on a device
- Major outage or denial of service
- Supplier or third-party breach
- Data leaked to an AI tool
- Prompt injection against an AI assistant or agent
- Deepfake or voice-clone payment fraud