AI tool data leak or misuse: incident response playbook
Use it when: Confidential or personal data was pasted into an unapproved AI tool, an AI agent took an unexpected action, or AI output caused harm.
First 15 minutes
- Record what data, which tool, which account and when.
- Delete the conversation or data in the tool if possible, and check the tool's retention and training settings.
- Revoke the tool's or agent's access to company accounts, files and APIs.
- Rotate any secrets or keys that were exposed.
Set the severity and download a first-response checklist
What the full playbook covers
- Contain (2 steps)
- Eradicate (1)
- Recover (1)
- Who to notify
- Evidence to keep
The full playbook is in the Incident Response & Business Continuity Kit with 8 more, the IR plan, a BCP/DR plan and 6 tabletop exercises.