Prompt injection against an AI assistant or agent: incident response playbook
Use it when: An AI assistant or agent followed instructions hidden in an email, document, web page, ticket or tool description, instead of its user's.
First 15 minutes
- Stop the assistant or agent and disconnect the tools it can use.
- Keep the input that carried the instruction (email, file, page, ticket) without opening it again in the AI tool.
- Record what the AI did after reading it: messages sent, data shown, actions taken.
- Rotate any secret or token the AI could see.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (2 steps)
- Eradicate (2)
- Recover (1)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 11 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.
Other playbooks
- Phishing and business email compromise
- Ransomware
- Lost or stolen device
- Data sent to the wrong person or exposed
- Compromised account or cloud admin access
- Malware on a device
- Major outage or denial of service
- Supplier or third-party breach
- Data leaked to an AI tool
- Rogue or misbehaving AI agent
- Deepfake or voice-clone payment fraud