Incident response for AI
How teams respond when AI features leak data, cause harm, or get abused—playbooks, severity, comms, and fixes.
What it is
How teams respond when AI features leak data, cause harm, or get abused—playbooks, severity, comms, and fixes.
Why it matters
Minutes matter. AI incidents look like security incidents plus model/prompt specifics.
How it works (plain)
Detect → contain (disable tools/features) → eradicate (patch prompts/filters/ACLs) → recover → lessons learned → update safety suites. Cross-link Course 29 what-to-do for users.
Try it
Draft a one-page IR card: owner, severity table, kill switch location.
Myths
- ⚠️ Myth: “The model did it” ends responsibility.
- ✓ Reality: Deployers own the system.
Sources
- Course 29 what-to-do; Course 17 rollback; NIST AI RMF
- https://www.nist.gov/itl/ai-risk-management-framework ↗
