AI incident response plan
Short answer
Do not stand up a parallel “AI CSIRT.” Fold AI into the incident process you already have. Name what counts as an AI incident, contain with identity and path (revoke the principal, invalidate tokens, block the destination), notify under the rules you already have, preserve tool-call logs rather than chat screenshots, and write the outcome back into the inventory and the acceptable-use policy.
This page is safeguard 11 of AI agent security for business and controls 36–40 of the 40-control checklist. It is risk management, not a new legal notification duty, and not a CMMC or FedRAMP certificate. NIST SP 800-61r3 remains the incident-handling shape. CSF 2.0 Respond and Recover are voluntary grouping language.
1. Define the incident in the existing playbook
If it is not named, it will be filed as “weird email.” Add a short appendix, not a new binder:
- Restricted data (Confidential, CUI if you hold it, credentials, customer lists, source code) pasted into an unapproved tool.
- An agent that sent, wrote, paid or deleted outside policy.
- A compromised AI account or an OAuth grant nobody will own.
- Prompt-injection that caused an external action.
- A runaway loop (cost cap blown, or repeated writes).
This article does not use health-record examples. If you are a covered entity, your existing privacy incident process owns that mapping — point at it.
2. Contain with identity and path
A stern Slack message is not containment. Microsoft’s kill-switch metric is mean time to revoke or disable an agent identity, including token invalidation. Sequence:
- Disable the user or agent identity in Entra (or the equivalent IdP).
- Invalidate tokens and revoke OAuth grants. Confirm a cached grant cannot still call Graph or MCP.
- Disable the tool, Copilot agent, or MCP server registration.
- Block the destination on DNS / proxy / firewall if the path is consumer SaaS.
- Preserve first; do not wipe the laptop or the chat history to “clean up.”
If you cannot do steps 1–2 on a non-production agent in a scheduled test, you do not have a kill switch. You have a belief. How to scope the principal beforehand: AI agent permissions and least privilege.
3. Notify under the rules you already have
This article does not create a US AI-incident statute. Use:
- Customer contract notification clauses.
- State breach statutes that already apply to the data involved.
- CUI reporting if you are in that scope.
- Vendor incident channels (Microsoft, OpenAI, Anthropic, Zoom) when their platform is in the path.
Do not skip those because “it was only a chatbot.” A prompt is a data transfer. Counsel decides whether a given event is a notifiable breach; this page tells operators not to hide the facts from counsel.
4. Preserve what you will be asked for
Chat transcripts are not enough. Microsoft’s usual gap is logs that capture the reply and miss the tool call, the scope and the authorization decision. Collect:
- Prompts and retrieved context (without copying more regulated data into a ticket than you must).
- Tool-call logs: tool name, arguments, result, role, scope, correlation ID, “on behalf of.”
- Identity logs: sign-in, consent, role assignment, disable events.
- Network records: DNS, proxy, firewall, for the same window.
If those logs do not exist, that is a finding for the inventory and for safeguard 8 on the pillar, not a reason to invent them after the fact.
5. Feed the outcome back
CSF 2.0 Recover includes improving. Minimum close-out:
- Add or move the tool on the approved / restricted / blocked list, with a date.
- Tighten the data class or the allowlist.
- Update the acceptable-use examples so the next person does not repeat it.
- Re-test the kill switch.
- If the root cause was Shadow AI, run intake rather than a gotcha — unless it was malicious, which is rare.
If you do not know which agents can send mail, the first hour of the incident is discovery. The Shadow AI Assessment is a private way to see that gap before 2 a.m.
What this plan is not
- Not a CMMC Level 2 or FedRAMP certificate.
- Not EU AI Act conformity. Article 50 transparency (from 2 August 2026) and Article 4 literacy (from 2 February 2025) are Union-market duties for in-scope providers and deployers, not a US IR filing.
- Not a retelling of the July 2026 lab evaluations as if they were customer ChatGPT. Those were specialized cybersecurity tests; the pillar qualifies them against primary disclosures.
Frequently asked questions
Should we stand up a separate AI CSIRT?
No. Fold AI into the incident process you already have. A parallel team that nobody will call at 2 a.m. is how AI incidents get filed as “weird email.” NIST SP 800-61r3 is still the incident-handling shape; AI adds identity, tool-call logs and a kill switch, not a new org chart.
Does this plan create a new legal notification duty?
No. Notify under the rules you already have: customer contracts, state breach statutes, CUI reporting if you are in that scope. Do not skip them because it was only a chatbot. This article does not invent a US AI-incident statute.
What counts as an AI incident?
Name it in the playbook or it will be filed wrong. Examples: restricted data in an unapproved tool; an agent that acted outside policy; a compromised AI account or OAuth grant; prompt-injection that caused an external action; a runaway agent loop (cost or writes).
How do you contain an agent?
Identity and path, not a Slack message. Disable the agent identity, invalidate tokens, revoke OAuth grants, disable the tool, block the destination. Microsoft measures mean time to revoke including token invalidation. Confirm the agent cannot still call tools with a cached grant.
What evidence should we preserve?
Prompts, tool-call logs (request, tool, result, scope, correlation ID), identity logs, OAuth consent records, and network/DNS records. Wiping the chat history or rebooting the laptop is how you destroy the only evidence you will be asked for.
Does writing this plan certify us for CMMC or FedRAMP?
No. A playbook is a control artifact, not a certificate. It does not make the organization CMMC Level 2 certified or FedRAMP authorized.
Are the July 2026 lab incidents a template for our IR?
They are specialized cybersecurity evaluations (OpenAI ExploitGym; Anthropic CTF evals with a partner), not customer ChatGPT or Claude.ai. The transferable lesson is containment and logging, not a claim that your Copilot will pentest vendors. Primary links are on the 12-safeguard pillar.
What happens after the incident?
Add the tool to approved / restricted / blocked, tighten the data class, update the acceptable-use examples, and test the kill switch again. CSF 2.0 Recover includes feeding lessons back. An incident that does not change the inventory will recur.
Related articles
- AI agent security for business: 12 safeguards — the pillar; this page is safeguard 11.
- AI security checklist for businesses: 40 controls — incident response is controls 36–40.
- AI governance framework for small and mid sized businesses — who owns the playbook when there is no GRC department.
- What happens after a hacker gets into your server? — persistence and why restore-from-backup is not eradication; the non-AI companion.
References
- NIST SP 800-61r3 — Incident Response Recommendations and Considerations for Cybersecurity Risk Management— the incident-handling shape this page folds AI into. Not an AI-specific statute.
- NIST CSWP 29 — CSF 2.0— Respond and Recover. Voluntary.
- Microsoft Learn — Least privilege for AI agents— mean time to revoke including token invalidation; audit fields needed for reconstruction.
Managed network and communications services, SDVOSB. Containment is identity plus a path you can see. This is not a CMMC or FedRAMP certificate and not a new notification law. Support: (888) 989-4872 · support@adampulse.us