ADAM PULSE Knowledge Base
Incident Response · AI Agents · NIST SP 800-61r3 · CSF 2.0

AI incident response plan

Short answer

Do not stand up a parallel “AI CSIRT.” Fold AI into the incident process you already have. Name what counts as an AI incident, contain with identity and path (revoke the principal, invalidate tokens, block the destination), notify under the rules you already have, preserve tool-call logs rather than chat screenshots, and write the outcome back into the inventory and the acceptable-use policy.

This page is safeguard 11 of AI agent security for business and controls 36–40 of the 40-control checklist. It is risk management, not a new legal notification duty, and not a CMMC or FedRAMP certificate. NIST SP 800-61r3 remains the incident-handling shape. CSF 2.0 Respond and Recover are voluntary grouping language.

1. Define the incident in the existing playbook

If it is not named, it will be filed as “weird email.” Add a short appendix, not a new binder:

This article does not use health-record examples. If you are a covered entity, your existing privacy incident process owns that mapping — point at it.

2. Contain with identity and path

A stern Slack message is not containment. Microsoft’s kill-switch metric is mean time to revoke or disable an agent identity, including token invalidation. Sequence:

  1. Disable the user or agent identity in Entra (or the equivalent IdP).
  2. Invalidate tokens and revoke OAuth grants. Confirm a cached grant cannot still call Graph or MCP.
  3. Disable the tool, Copilot agent, or MCP server registration.
  4. Block the destination on DNS / proxy / firewall if the path is consumer SaaS.
  5. Preserve first; do not wipe the laptop or the chat history to “clean up.”

If you cannot do steps 1–2 on a non-production agent in a scheduled test, you do not have a kill switch. You have a belief. How to scope the principal beforehand: AI agent permissions and least privilege.

3. Notify under the rules you already have

This article does not create a US AI-incident statute. Use:

Do not skip those because “it was only a chatbot.” A prompt is a data transfer. Counsel decides whether a given event is a notifiable breach; this page tells operators not to hide the facts from counsel.

4. Preserve what you will be asked for

Chat transcripts are not enough. Microsoft’s usual gap is logs that capture the reply and miss the tool call, the scope and the authorization decision. Collect:

If those logs do not exist, that is a finding for the inventory and for safeguard 8 on the pillar, not a reason to invent them after the fact.

5. Feed the outcome back

CSF 2.0 Recover includes improving. Minimum close-out:

  1. Add or move the tool on the approved / restricted / blocked list, with a date.
  2. Tighten the data class or the allowlist.
  3. Update the acceptable-use examples so the next person does not repeat it.
  4. Re-test the kill switch.
  5. If the root cause was Shadow AI, run intake rather than a gotcha — unless it was malicious, which is rare.
You cannot contain what you have not named

If you do not know which agents can send mail, the first hour of the incident is discovery. The Shadow AI Assessment is a private way to see that gap before 2 a.m.

Run the assessment →

What this plan is not

Frequently asked questions

Should we stand up a separate AI CSIRT?

No. Fold AI into the incident process you already have. A parallel team that nobody will call at 2 a.m. is how AI incidents get filed as “weird email.” NIST SP 800-61r3 is still the incident-handling shape; AI adds identity, tool-call logs and a kill switch, not a new org chart.

Does this plan create a new legal notification duty?

No. Notify under the rules you already have: customer contracts, state breach statutes, CUI reporting if you are in that scope. Do not skip them because it was only a chatbot. This article does not invent a US AI-incident statute.

What counts as an AI incident?

Name it in the playbook or it will be filed wrong. Examples: restricted data in an unapproved tool; an agent that acted outside policy; a compromised AI account or OAuth grant; prompt-injection that caused an external action; a runaway agent loop (cost or writes).

How do you contain an agent?

Identity and path, not a Slack message. Disable the agent identity, invalidate tokens, revoke OAuth grants, disable the tool, block the destination. Microsoft measures mean time to revoke including token invalidation. Confirm the agent cannot still call tools with a cached grant.

What evidence should we preserve?

Prompts, tool-call logs (request, tool, result, scope, correlation ID), identity logs, OAuth consent records, and network/DNS records. Wiping the chat history or rebooting the laptop is how you destroy the only evidence you will be asked for.

Does writing this plan certify us for CMMC or FedRAMP?

No. A playbook is a control artifact, not a certificate. It does not make the organization CMMC Level 2 certified or FedRAMP authorized.

Are the July 2026 lab incidents a template for our IR?

They are specialized cybersecurity evaluations (OpenAI ExploitGym; Anthropic CTF evals with a partner), not customer ChatGPT or Claude.ai. The transferable lesson is containment and logging, not a claim that your Copilot will pentest vendors. Primary links are on the 12-safeguard pillar.

What happens after the incident?

Add the tool to approved / restricted / blocked, tighten the data class, update the acceptable-use examples, and test the kill switch again. CSF 2.0 Recover includes feeding lessons back. An incident that does not change the inventory will recur.

References

  1. NIST SP 800-61r3 — Incident Response Recommendations and Considerations for Cybersecurity Risk Management— the incident-handling shape this page folds AI into. Not an AI-specific statute.
  2. NIST CSWP 29 — CSF 2.0— Respond and Recover. Voluntary.
  3. Microsoft Learn — Least privilege for AI agents— mean time to revoke including token invalidation; audit fields needed for reconstruction.
Prepared by ADAM Pulse (USA Telecom Consulting LLC)

Managed network and communications services, SDVOSB. Containment is identity plus a path you can see. This is not a CMMC or FedRAMP certificate and not a new notification law. Support: (888) 989-4872 · support@adampulse.us