HD Field Guide 13

AI incident response: the first 60 minutes

Contain an unsafe or compromised AI workflow while preserving prompts, tools, identities, data and downstream evidence.

Control area
Incident response
Audience
Security & IT teams
Reading time
8 min
Reviewed
11 August 2026
Control areaIncident response AudienceSecurity & IT teams Reading time8 min Reviewed11 August 2026

AI incidents may involve leaked data, compromised identity, malicious retrieval or over-permissioned agents. Preserve the chain.

Contain without erasing evidence

Disable capability and credentials while preserving logs and configuration.

Avoid deleting histories until evidence needs are understood.

Restore trust deliberately

Re-enable from known-good configuration with reduced permissions.

Document root cause and improvements before restoring autonomy.

Completion check

Before you close the guide

  • Workflow contained
  • Credentials revoked
  • Evidence preserved
  • Downstream impact reviewed

Trusted references

Continue with primary guidance

Defensive guidance boundary

This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.