Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an AI agent takes an action you did not authorize, stop the activity if you can do so safely, contain every identity and access path it may still use, and preserve records before making changes that could erase evidence. Then reconstruct what happened across the agent, its tools, and downstream systems. A disabled agent may still have valid tokens or credentials, and a chat transcript alone may not show what it did.

What to do first when an AI agent acts without authorization

Start your incident process and assign someone to coordinate containment and evidence preservation. Record when the incident was detected, who is responding, and who authorized each response action. If the activity is still in progress, use the platform’s reliable pause or stop mechanism if available.

Do not assume that stopping the agent’s front-end process revokes access it already has. An agent may be hosted, custom-built, or split across an orchestrator and connected services. Its authority can include a service identity, delegated tokens, API keys or other credentials, enabled tools and connectors, and permissions in downstream applications.

Choose containment actions for the system you have

The order depends on whether the activity is continuing, whether credentials are shared with other services, and how the system can be recovered. Preserve the access and change records needed to explain the decision. Consider each action against its actual effect rather than treating any one as a universal kill switch.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FortiGate-40F Firewall Appliance - 5 Gigabit Ethernet RJ45 Ports, Ideal for Small Businesses (Appliance Only, No Subscription) (FG-40F)
  • Compact and Efficient Design: The FortiGate 40F is designed for small to mid-sized businesses and enterprise branch offices, featuring a compact, fanless desktop form factor that ensures quiet operation and minimizes space usage.
  • Robust Connectivity Options: Equipped with 5 GE RJ45 ports, including 1 WAN port and 4 internal ports, this model provides essential connectivity and flexibility for various network configurations in a small-scale environment.
  • High-Performance Security: Offers up to 1 Gbps IPS throughput and 600 Mbps threat protection throughput, using Fortinet’s purpose-built security processor technology to deliver industry-leading performance and protection for SSL encrypted traffic.
  • Advanced Threat Protection: Integrated with Fortinet’s AI-powered FortiGuard Labs, the FortiGate 40F offers comprehensive cybersecurity, identifying and mitigating both known and unknown threats to maintain robust security across your network.
  • Simplified Management and Deployment: Features a user-friendly management console that provides comprehensive network automation and visibility, coupled with Zero Touch Integration with Fortinet’s Security Fabric for easy deployment.
Response action What it may contain What to verify Potential trade-off
Pause or stop the current run Further actions by that run, if the platform’s control reaches it. Confirm the run stopped and check whether queued or parallel work continues. May leave issued tokens, credentials, or downstream permissions valid.
Disable the agent identity or revoke its tokens Use of that identity or tokens, depending on the identity provider and token lifecycle. Test revocation and check for other credentials or identities the agent can use. A shared identity or credential may support unrelated services.
Rotate or disable credentials and remove permissions Use of affected keys, secrets, or access grants after the change takes effect. Check for copied or shared secrets, stale grants, and permissions enforced by downstream systems. Rotation or permission removal can disrupt dependent services or complicate recovery.
Disable a tool, connector, or connected service path Actions through the specific tool or connection that was disabled. Check for alternate connectors, direct API access, and outstanding operations already accepted downstream. Other workflows may rely on the same connector or service.

Microsoft Learn’s guidance on least privilege for AI agents recommends testing revocation paths, including disabling the agent, rotating credentials, invalidating tokens, and removing stale permissions. Verify the result in the relevant systems; do not infer that a control worked merely because its interface reported success.

How to preserve evidence without exposing more data

Collect records from the systems involved before routine retention, cleanup, or recovery activity makes them unavailable. Follow your organization’s incident-handling process for preserving original records. There is no single retention period or chain-of-custody procedure established for every organization and jurisdiction.

  • AI-system security and event logs: agent runs, tool activity, errors, state changes, and privilege changes, where recorded.
  • User interaction and prompt logs: requests, retrieved or supplied material, and agent responses, subject to privacy and confidentiality controls.
  • Application and connector logs: requests and results recorded by the tools and applications the agent contacted.
  • Identity and permission audit records: identities used, grants, token or credential events, and changes to access.
  • Device, connection, and infrastructure records: relevant execution, network, host, or service events.

Preserve records from the orchestrator, tool, and downstream system in a way that lets responders correlate them. Microsoft Learn’s shared-responsibility guidance recommends logging tool invocations with inputs, outputs, the identity used, and the decision rationale. Those fields may not exist in every deployment; note what is missing rather than assuming an absent record means an action did not occur.

Rank #2
FortiGate-60F Network Security Appliance Plus 1 Year FortiGuard Unified Threat Protection (UTP) and FortiCare Premium (FG-60F-BDL-950-12)
  • HARDWARE PLUS SECURITY SERVICES: FortiGate-60F Firewall Appliance bundled with 1 year of FortiCare Premium and FortiGuard Unified Threat Protection.
  • UNIFIED THREAT PROTECTION (UTP): Secures against advanced online threats with comprehensive web filtering and anti-botnet technologies.
  • OPTIMIZED FOR MEDIUM-SIZED BUSINESSES: Tailored for businesses needing robust security without the infrastructure of larger enterprises.
  • RELIABLE CUSTOMER SUPPORT: FortiCare Premium ensures high-quality support and service continuity.
  • EFFECTIVE PROTECTION: Employs advanced filtering technologies to safeguard against sophisticated threats.

Prompts and interaction logs can contain personal, confidential, or otherwise sensitive information. Restrict access to the investigation materials, protect copies, and handle them under applicable privacy and security controls. Avoid collecting or circulating more content than responders need.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to reconstruct what the agent did and under whose authority

Build a timestamped timeline that links the initiating event to each attempted and completed operation. Use timestamps and identifiers from connected systems where possible, and distinguish observed facts from inferences.

  1. Identify the trigger: record the requesting user, scheduled task, external event, or other initiating event, and the time it reached the system.
  2. Identify the acting identity: establish the agent identity, role, delegated identity, effective permissions, and scope at the time—not only the configuration visible after containment.
  3. Trace the input: capture the relevant user instruction and any external or retrieved content the agent received, such as a webpage, document, or email, subject to access controls.
  4. Follow the tool call: connect the agent run to the selected tool, its recorded parameters, the target resource, and the tool’s response.
  5. Check downstream authorization and results: determine which identity the application saw, whether it allowed or denied the operation, and what state change or external side effect followed.
  6. Check for continuation: look for retries, repeated actions, queued work, later activity, or propagation to connected agents and systems.

OWASP’s AI Agent Security Cheat Sheet emphasizes that classifying an action does not itself authorize a tool call: the execution component must independently check the actor’s authorization and any required approval for the exact action. Treat a model’s explanation of why it acted as context to investigate, not as proof of permission or a complete event record.

Rank #3
Sale
GL.iNet GL-MT5000 Brume 3 Wired VPN Security Gateway NO Wi-Fi
  • 【Up to 1100 Mbps VPN Speed 】 Hardware-accelerated WireGuard and OpenVPN-DCO deliver up to 1100 Mbps VPN throughput, over 3× faster than Brume 2 for smooth remote access and file transfers.
  • 【Three 2.5G Ports & Multi-WAN】Tri-port 2.5GbE design with flexible WAN LAN configuration supports multi-gigabit wired setups, dual-ISP Multi-WAN and failover to keep home and SOHO networks online.
  • 【Stealth VPN Obfuscation】VPN obfuscation disguises VPN traffic as regular HTTPS, helping you evade blocking, bypass restrictive networks and maintain stable, private connections.
  • 【DPI protection】Deep Packet Inspection with visual dashboards blocks adult/gambling/malicious sites, while SQM and QoS prioritize gaming, calls, and video when bandwidth is tight
  • 【OpenWrt & USB 3.0 Expansion】OpenWrt with 1GB DDR4 and 8GB eMMC lets you install plugins and build VPN, ad-blocking or NAS, while USB 3.0 Type‑C connects high-speed storage or 4G/5G dongles

Investigate possible causes without assuming prompt injection

Prompt injection is one possibility, not a conclusion to reach from an unexpected action alone. It can be introduced in direct user input or embedded in untrusted material the agent reads, such as a webpage, document, or email. Excessive permissions or weak authorization checks can let such input lead to an operation the user did not authorize.

Also examine whether the task was misunderstood, permissions had accumulated beyond what was needed, credentials were shared or compromised, an unexpected tool was exposed, memory or a multi-agent workflow carried instructions forward, or a loop allowed repeated actions. Use logs and system behavior to support any cause you report; where records are incomplete, state what cannot be established.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to determine scope and impact

For each confirmed or suspected operation, identify the affected resource and the nature of the effect. Depending on the system, that may be data accessed or changed, a recipient contacted, a permission altered, or an external action initiated.

Rank #4
Ubiquiti Cloud Gateway Ultra (UCG-Ultra)
  • Runs UniFi Network for full-stack network management
  • Manages 30+ UniFi Network devices and 300+ clients
  • 1 Gbps routing with IDS/IPS
  • Multi-WAN load balancing
  • 0.96" LCM status display
  • Determine whether each operation was attempted, allowed, completed, repeated, or followed by another action.
  • Check the connected application for resulting state changes and later activity, not just the agent’s own record of a tool call.
  • Record what is supported by logs separately from what remains uncertain—for example, if tool inputs, outputs, or downstream events were not retained.
  • Route affected-data and reporting decisions through your organization’s incident, privacy, legal, and regulatory processes.

Reporting duties and deadlines depend on factors such as jurisdiction, sector, data type, and contractual commitments. An incident record alone is not enough to determine which obligations apply.

How to remediate and recover safely

Fix the authority or execution boundary that allowed the action, not just the input or prompt that preceded it. Remove unnecessary or compromised permissions, narrow tool and connector access, validate tool parameters, and require independent authorization for high-impact operations. Check that downstream applications enforce access decisions themselves rather than relying only on the orchestrator.

Restore affected systems through approved recovery procedures. If an operation needs to be undone, use a documented rollback where safe; if it cannot be reversed, use an appropriate compensating action with scoped authority and change tracking. For agents that perform remediation, Microsoft Learn recommends scoped resource permissions, approval or just-in-time elevation, rollback procedures, and change tracking.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What to verify before returning the agent to service

  1. Confirm that the containment controls took effect, stale permissions were removed, and relevant tokens or credentials were invalidated or rotated as intended.
  2. Verify that downstream systems enforce the expected authorization checks, including for direct access paths that bypass the orchestrator.
  3. Re-test the relevant abuse cases and approval rules after changing prompts, tools, memory, retrieval, or credential scopes.
  4. Require updated tests when high-risk policies or credential scopes change. OWASP recommends adversarial regression testing and blocking releases when such changes lack updated tests.

Microsoft Learn recommends reliable, system-level mechanisms to pause or stop agents safely and immediately. The operational test is whether those mechanisms stop the relevant work and whether the agent’s other access paths are contained—not whether a stop control exists in the interface.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.