Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an AI agent has taken an action you did not authorize, stop it from doing more, preserve evidence, and check what it accessed or changed. Then revoke or limit the relevant access, investigate the cause, and restore the agent only after the issue is fixed and a recovery plan is in place. The right containment step depends on the agent’s tools, permissions, and role in your systems.

1. Stop further activity without causing avoidable disruption

Use the response procedure designed for the specific agent and deployment. Depending on the situation, that may mean pausing a tool or connector, isolating an affected component, invoking a human override, or disengaging or deactivating the agent. NIST’s AI Risk Management Framework calls for post-deployment monitoring that includes appeal and override, decommissioning, incident response, and recovery. Its Playbook recommends bypassing, disengaging, or deactivating when risks exceed tolerance or cannot be mitigated in time.

Before taking a broad shutdown action, consider which business processes or systems depend on the agent. A full stop may prevent additional harm but can also interrupt dependent services. Follow your deployment’s decision criteria and escalation authority when time allows; prioritize preventing continuing harm when it does not. NIST AI RMF Playbook

2. Preserve evidence before cleaning up

Record the event and retain relevant logs and artifacts before deleting data, resetting the agent, or changing the environment. Preserve originals where possible, note timestamps and time zones, and record who discovered the action and what response steps were taken.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Agent activity and tool-call records, including prompts or instructions and approval events.
  • Identity, access, and connected-system logs.
  • The resulting changes, such as modified records, sent messages, or transactions.
  • Relevant alerts, configuration state, and communications about the incident.

Preserving this material supports investigation and any later forensic, regulatory, or legal review. The FTC advises businesses not to destroy forensic evidence during investigation and remediation. FTC Data Breach Response: A Guide for Business

3. Determine what happened and how far it reached

Establish what the agent did, when it did it, whether activity is continuing, and which accounts, systems, data, or people may be affected. Check both the agent’s own activity and the connected identities and services it could use; an action in one tool may have consequences elsewhere.

  • Which action was outside authorization, and what triggered it?
  • What information did the agent view, change, send, or delete?
  • Which accounts, integrations, systems, external recipients, or business processes were involved?
  • Were there financial, operational, privacy, or security effects?
  • Could the same permissions or workflow have affected other resources?

Maintain an incident record and coordinate the investigation with the relevant security or IT staff, system and business owners, and legal or communications teams as appropriate. NIST SP 800-171 Rev. 3 describes incident handling as preparation, detection and analysis, containment, eradication, and recovery. It applies to protecting controlled unclassified information in nonfederal systems; its incident-handling sequence is useful here as a general process, not as a claim that the standard governs every organization. NIST SP 800-171 Rev. 3

4. Restrict the agent’s connected access

Review the privileges assigned to the agent and the authorizations for each connected account, tool, or integration. Suspend or revoke the specific authorization through the provider’s or administrator’s process. Rotate exposed secrets when appropriate, and check whether other credentials or tokens could still enable access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If an account itself may be compromised, the FTC recommends changing its password, signing out of all devices, enabling two-factor authentication where available, and reviewing recovery details and account activity. Those account-recovery steps do not replace revoking an agent’s specific integration or authorization. The exact controls and labels vary by product, so use the documentation or administrator process for the actual service. FTC: What To Do if You Were Scammed

5. Address possible data exposure and notification duties

If personal information may have been exposed, determine what information was involved and who could be affected. Consult qualified counsel and assess the laws, regulations, contracts, and sector requirements that apply to your organization and the people affected. Do not assume there is one notification deadline for every incident: duties and timing depend on the facts and applicable law.

Notify internal incident leadership and affected service providers as appropriate. When notification is required, communicate clearly and avoid sharing details that could create additional risk. The FTC’s business guide offers U.S.-oriented general guidance; it does not determine an organization’s legal obligations. FTC Data Breach Response: A Guide for Business

6. Fix the cause and recover deliberately

Identify and correct the permission, configuration, integration, or workflow issue that allowed the unauthorized action. Check for the same weakness in other resources, then validate the correction before restoring operation. Set recovery criteria that match the system’s risk and define who has authority to approve reactivation.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Document the decision to bypass, disengage, or deactivate the agent and assess downstream effects. NIST’s AI RMF Playbook recommends root-cause analysis and change management so the effects of deactivation or bypass are understood. Resume through a defined recovery process rather than simply turning the agent back on. NIST AI RMF Playbook

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

7. Review the incident and improve safeguards

After immediate response and recovery, document lessons and update controls that can prevent or reduce a repeat: access limits, monitoring, approval requirements, override paths, and the incident plan. Communicate relevant incidents and errors to appropriate stakeholders, including affected communities when relevant. NIST AI RMF 1.0 identifies this communication as part of incident management; the framework is voluntary and NIST reports that it is being revised. NIST AI RMF Playbook

Make the response plan specific to the deployment

This is general operational guidance, not a substitute for a provider-specific runbook or jurisdiction-specific legal advice. An agent’s connectors, identity model, permissions, and deployment context determine the practical containment and recovery steps. Document the available override, access-revocation process, evidence sources, escalation authority, and safe restoration criteria before an incident occurs.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.