An AI incident rarely starts with a clear alarm. An employee discovers confidential data in a response. An agent sends the wrong file. A summary omits a crucial contract clause. Or a vendor reports a security flaw while the system is already embedded in multiple workflows. In the first minutes, what counts is not a perfect root-cause analysis but controlled action.
A practical AI incident plan in the company connects business units, IT, data protection, legal and communications. It distinguishes types of errors, stops further effects, preserves necessary evidence and initiates secure fallback processes. This guide is aimed at Austrian SMEs and shows a procedure that works even without an in-house Security Operations Center.
An AI error becomes an incident when there is a risk of impact
Not every unusable phrasing requires a crisis team. An incident is likely when people, data, rights, money, operations, or trust could be affected. What matters are the scope and possible consequences, not how spectacular the output looks.
Typical examples are:
- personal or confidential content becomes visible to unauthorized parties;
- incorrect information was sent to customers, authorities, or the public;
- an AI agent triggers an action that has not been authorized;
- a decision disadvantages people or is not explainable;
- prompts, files, or knowledge sources have been manipulated;
- the system fails during a critical process or systematically produces incorrect results;
- the provider changes the model or function with unintended effects.
A low-threshold reporting channel is more important than a perfect definition. Employees must be allowed to report uncertainty without having to provide proof of fault.
The initial report requires only seven pieces of information
The report form should be fillable in a few minutes:
- When was the problem discovered?
- Which system and which workflow are affected?
- What was observed, without presenting speculation as fact?
- Was anything sent externally, published, or executed?
- Could personal data, secrets, or credentials be affected?
- What immediate containment or security measures have already been taken?
- How can the reporting person be reached for follow-up questions?
The report itself must not spread unnecessary copies of confidential content. A link to an access-protected document or an internal case number is better than a screenshot sent to a large distribution list.
Stop, limit, secure – in that order
The first response follows three verbs. Stop: Automatic actions, publications, or affected accesses are halted in a controlled manner. Limit: Permissions are reduced, vulnerable interfaces are isolated, and recipients are temporarily warned if necessary. Preserve: relevant logs, timestamps, configurations, and versions are preserved unchanged.
Hasty deletion can destroy traces and make assessment more difficult. On the other hand, a sensitive output must not be left exposed out of convenience. Therefore, a named incident command decides on the form of preservation, access, and deletion. Where there is acute danger, damage mitigation takes precedence over evidence collection.
A technically proven shutdown mechanism must be available for AI agents. The guideline to AI agents in the office describes approval points and restricted privileges that prevent a single error from continuing unchecked.
Four incident classes determine the appropriate specialist roles
Factual error
The output is factually incorrect, incomplete, or outdated. The business unit stops use, identifies affected results, and organizes correction. Data protection or IT security become involved when data or manipulation are a factor.
Data or confidentiality incident
Personal data, trade secrets, or third-party confidential content have been entered, stored, or disclosed without authorization. Data protection officers and information security teams assess the affected parties, recipients, protection measures, and reporting obligations.
Security or manipulation incident
Unauthorized access, compromised accounts, prompt injection, malicious files, or altered sources are suspected. IT security isolates systems, secures logs, and checks for further access. The functional impact remains part of the analysis.
Inadmissible decision or action
A system influences people, contracts, payments, or external communication outside of its authorization. Responsible management, legal, the relevant department, and, if applicable, equal opportunity or employee representatives must be involved. Automatic decisions are not simply retroactively legitimized by a human click.
Severity based on impact rather than technical elegance
A simple grid uses four levels:
- Level 1 – local: internally detected, no disclosure, easily correctable;
- Level 2 – limited: limited number of recipients or repeated error, controllable consequences;
- Level 3 – significant: sensitive data, external impact, financial or legal risks, multiple processes;
- Level 4 – critical: acute danger to people or essential services, widespread disclosure, active manipulation or rapid spread.
Assess possible impact, number of affected parties, recoverability, duration, and speed. An inconspicuous textual error can be serious if it reaches a thousand customers. A technically complex incident can remain low if it was discovered in the test system without real data.
The incident command maintains a shared timeline
One person coordinates without making all specialist decisions themselves. They open a protected incident file, assign roles, and log events: discovery, containment action, known systems, initial assessment, external contacts, decisions, and approvals. Times are recorded with time zone.
Use functional roles instead of just names: incident command, technical analysis, specialist assessment, data protection, legal, communications, and business continuity. A small company can assign multiple roles to one person, but should not skip those perspectives. For absences there are deputies and reachable contact details outside the AI system.
A AI checklist for managers helps to define ownership and escalation paths before the first incident.
Preserve evidence without exacerbating the data problem
For reconstruction, the prompt, output, model or product version, knowledge source, user role, time, settings, actions, and vendor notes may be necessary. Collect only what is needed for assessment, remediation, and proof. Limit access and retention.
Do not export large chat transcripts to private devices. Do not send access keys or complete personal data records to open tickets. If a secret may have been compromised, it will be replaced according to a coordinated plan. The old key does not belong in the incident log; its identifier is sufficient there.
Successful responses related to the error are also relevant. They show whether it is an isolated case or a systematic change. A small sample can help narrow the scope without keeping the faulty process running in production.
Data breaches have their own timeline
If the incident involves a breach of the protection of personal data, the responsible data protection role will be notified immediately. The WKO summarizes the data-breach reporting obligations under the GDPR: Controllers must report a reportable breach to the supervisory authority without undue delay and, where possible, within 72 hours of becoming aware. A report can be omitted if it is unlikely that there is a risk to the rights and freedoms of natural persons.
Whether a report is required is not decided by the language model. Document the type of data, affected individuals and datasets, possible consequences, recipients, safeguards, and the time of discovery. Missing information must not delay early internal escalation and a timely professional decision.
It must also be examined whether affected individuals need to be informed. The wording should clearly explain what happened, what consequences are possible, what the company is doing, and what steps affected parties can take. Speculation and soothing automated texts are out of place.
Correct false external content in a targeted manner
If an AI response was sent or published, the responsible department creates a recipient list and a verified correction. The correction clearly states which statement must not be used and what applies instead. It does not hide the error behind a general “update”.
With multiple channels – website, newsletter, CRM, document repository – each location is tracked individually. Removal alone may not be sufficient if people have already acted. Then direct information, reversal, or support is needed. Legal and communications coordinate tone, reach, and order.
A public statement is not promised prematurely, but it is also not delayed out of fear. The decision is guided by the affected public, information obligations, and damage limitation. A central, updated set of facts prevents contradictory statements.
Treat trade secrets and access credentials separately and immediately
If a prompt contained API keys, passwords, contract details, or unpublished project information, deleting a chat is not sufficient. Access credentials are revoked and replaced; logs are checked for usage. For trade secrets, an assessment is made of who had access, which contractual relationships apply, and how further dissemination can be prevented.
The practical guide to "trade secrets in AI tools" shows data classes and protection against input. In an incident, the same classification helps to quickly determine priority and the responsible persons.
The provider is a source of information, not the incident command
Open a prioritized support or security ticket for third-party products. Ask about affected services, time frame, data types, access, logs, containment, permanent remediation, and next updates. Note the ticket number, contact person, and promised timelines.
Do not wait for a complete manufacturer analysis before taking your own protective measures. The company remains responsible for its process, communication, and legal assessments. Contractual deadlines and escalation paths should be established during procurement.
In the event of an acute cyberattack, Austrian WKO members can consider the Cyber Security Hotline of the Chambers of Commerce as a support channel. Situations involving danger to life or health and acute criminal matters must, of course, be reported to the relevant emergency or security authorities.
The secure replacement process keeps operations functional
A fallback exists for every important AI step: manual processing, approved templates, read-only mode, a second independent system, or a temporary suspension of acceptance. The replacement path may be slower, but it must maintain minimum quality and rights.
Prioritize processes according to impact. Critical customer cases are handled manually; less urgent tasks wait. Communicate realistic delays. A team that secretly uses private AI accounts during an incident creates a second problem – therefore, permitted alternatives are trained in advance.
Restart only after a documented approval
A vendor note "Problem solved" is not sufficient. Before restarting there must be the root cause or at least effective containment, corrected configuration, renewed access credentials, verified data sources, and a successful test. Particularly important past incidents are repeated as regression tests.
The approval specifies scope and conditions. Perhaps the system may initially only read, but not perform actions. Perhaps a function will be disabled or every output will be additionally reviewed. Monitoring and points of contact remain active for an observation period. If the issue reoccurs, the process stops automatically or after a clear signal.
The NIST AI Risk Management FrameworkLists for deployed systems include, among other things, monitoring, incident response, recovery, change management, and communication about errors. The voluntary framework can be used as a structure for restarting and continuous improvement.
The post‑mortem seeks systemic causes instead of assigning blame
Within a few days a small group meets for a retrospective. They reconstruct triggers, technical and organizational conditions, detection, response, and impact. Don’t only ask who wrote the wrong prompt. Why were the data accessible? Why was there no warning? Was the approval role unclear? Had the provider not sufficiently announced a change?
Measures are made concrete: responsible person, deadline, acceptance criterion. Examples include reduced privileges, new test cases, better data classification, an amended contract, training, or disabling the use case. Each measure is later checked for effectiveness.
The WKO-KI-Guideline on legal framework conditions empfiehlt klare Richtlinien, Schulungen, Kontrollen und die umgehende Meldung schwerwiegender KI-Fehler oder Datenschutzverletzungen an die zuständige Stelle. Ein Vorfallplan macht aus diesem Grundsatz konkrete Handlungen.
A ten-step process for AI incidents
- Acknowledge the report and record the time of awareness.
- Stop automated effects and limit the scope of impact.
- Activate incident management and necessary specialist roles.
- Initially determine severity and incident class.
- Secure evidence in a protected manner and maintain a shared timeline.
- Assess data protection, security, legal, and information obligations.
- Correct affected outputs and notify targeted recipients.
- Run a secure manual or technical replacement process.
- Test the fix and allow a limited restart.
- Track causes, actions, and lessons learned.
An exercise makes the plan resilient.
Run a 45-minute scenario twice a year: an AI assistant sends confidential customer data to the wrong recipient, or an agent creates faulty orders. No one needs to change real systems. The team works with cards, a timeline, and prepared contacts.
Observe how quickly the shutdown path is identified, who decides on a privacy review, and whether a fallback is known. Then update contacts, permissions, and templates. Vendor changes, new integrations, and personnel changes also trigger a brief review of the plan.
Prepared responses protect people and the business.
A AI incident plan in the company ist not an admission of guilt. It is the acknowledgement that probabilistic systems, data flows and automation can produce errors. The organization gains time because roles, kill switches, assessment questions and communication channels are not only invented in the heat of the moment.
The most important sentence for employees is: Early reporting is encouraged. Those who raise a concern without fear often prevent a larger impact. Combined with limited privileges, auditable logs, human approvals and a practised fallback process, an AI error becomes a manageable incident — and the incident a concrete improvement.