All resources
eBooks

Containing an Authorized Actor: AI Incident Response for Agents

Your existing incident response playbook was written for an intruder. Your agent was invited in, and that changes how you contain it.

Key Takeaways:

  • Your agent was authorized, until it wasn’t. Containment has to constrain an approved system, not revoke a breach.
  • Agents move faster than a human can approve. An agent completes hundreds of tool calls before an alert renders, so the top rungs of containment have to be automated.
  • The attack often arrives through what the agent reads. Goal hijack hides inside a retrieved email or document. An audit trail that only holds user input and model output shows you nothing.
  • Two compliant actions can add up to an incident. A policy engine that scores each tool call alone will pass every step of a cascading failure it was meant to catch.
  • The EU AI Act’s reporting clock starts at detection. Article 73 allows as little as two days for a widespread infringement.

If one of your production agents took an unauthorized action tomorrow, could you disable it in under a minute, and explain why it happened?

Most IR programs assume an intruder gained access, that malicious activity trips a policy at the point of action, and that forensics means pulling artifacts off a disk. Agentic incidents break all three. The agent was granted access on purpose. Each step can pass policy while the sequence still exceeds intent. And forensics means replaying retrieval, reasoning, and tool calls in order, which only works if your audit trail captured them.

Download the report for the severity model, the four rung containment ladder, five runbooks, and the 30 day plan to find which of the seven required capabilities your stack is missing.