Skip to content

Incident Response for AI Systems

Preparing for and handling security incidents involving AI applications, models and agents.

Editorial team 1 min read

AI incidents need the same discipline as other security incidents, plus some AI-specific steps.

Types of AI Incidents

  • Data leaked through model outputs.
  • An agent taking unauthorised actions after prompt injection.
  • Poisoned data or a compromised model discovered.
  • Model weights or prompts stolen.
  • Harmful content generated publicly.
  • Runaway costs from abuse.

Prepare

  • Include AI systems in incident response plans.
  • Maintain an inventory of models, data sources, tools and owners.
  • Build the ability to quickly disable tools, switch models, roll back prompts and take features offline.
  • Keep logs sufficient for investigation.

Respond

  1. Contain: disable affected features or tools; revoke credentials.
  2. Investigate: review logs of prompts, retrievals and actions.
  3. Eradicate: remove poisoned data, fix vulnerabilities, update controls.
  4. Recover: restore service with fixes verified.
  5. Notify: meet legal obligations for data breaches.

Learn

Hold a blameless review. Add the attack to test suites and update the threat model.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025