HD Field Guide 13
AI incident response: the first 60 minutes
Contain an unsafe or compromised AI workflow while preserving prompts, tools, identities, data and downstream evidence.
AI incidents may involve leaked data, compromised identity, malicious retrieval or over-permissioned agents. Preserve the chain.
Contain without erasing evidence
Disable capability and credentials while preserving logs and configuration.
Avoid deleting histories until evidence needs are understood.
Restore trust deliberately
Re-enable from known-good configuration with reduced permissions.
Document root cause and improvements before restoring autonomy.
Before you close the guide
- Workflow contained
- Credentials revoked
- Evidence preserved
- Downstream impact reviewed
Continue with primary guidance
This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.