Incident Response KitFree severity check

AI tool data leak or misuse: incident response playbook

Use it when: Confidential or personal data was pasted into an unapproved AI tool, an AI agent took an unexpected action, or AI output caused harm.

First 15 minutes

  1. Record what data, which tool, which account and when.
  2. Delete the conversation or data in the tool if possible, and check the tool's retention and training settings.
  3. Revoke the tool's or agent's access to company accounts, files and APIs.
  4. Rotate any secrets or keys that were exposed.

Set the severity and download a first-response checklist

What the full playbook covers

The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.

Other playbooks

Incident Response & Business Continuity Kit

More free security and AI governance tools