Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Scan for outdated or missing drivers - takes under a minute3Clear out junk files and repair common Windows errorsStop the agent and limit its access first. Then preserve the relevant records, use system evidence to establish what happened, notify the right people, and resume only after containment and review. The response should match the incident’s impact: a read-only mistake differs from data sent outside your organization, a financial transaction, or a destructive change.
1. Stop the agent from continuing
Pause the active run and any connected automations that could repeat or extend the action. If you can do so safely, restrict the agent’s credentials and tool permissions to the minimum needed to contain the incident. If there is no reliable pause or you cannot identify what to disable, contact the system or platform administrator to isolate the affected component.
Prioritize stopping access to sensitive data and systems where the agent could make external, financial, destructive, or administrative changes. CISA and partner agencies’ May 1, 2026 announcement on careful adoption of agentic AI stresses limiting autonomy and avoiding broad or unrestricted access, particularly to sensitive data and critical systems.
2. Preserve evidence securely
Record the incident timeline and preserve relevant audit logs through your organization’s approved process. Useful details include:
#1 Best Overall
- When the activity began and was stopped.
- The agent or model version, if known, and the user or service identity involved.
- Tool calls, affected systems and resources, and the action or output at issue.
- Destinations or recipients, and whether an action completed or was interrupted.
- Containment steps already taken, including permission changes or credential revocations.
Do not paste exposed passwords, tokens, or other secrets into ordinary tickets, email, or chat. Handle them only through approved secure channels. The OWASP AI Agent Security Cheat Sheet recommends audit trails for decisions and actions and structured metadata for high-risk operations.
3. Find out what actually happened
Separate attempted actions from completed ones. Check platform and tool logs, identity events, affected files or database records, messages sent, and external destinations. Determine what data the agent accessed, whether it left the system, and who could have seen it. If the agent interacted with multiple systems or triggered other agents or automations, trace those effects too.
Rank #2
Use system records and affected resources as evidence; the agent’s own explanation is not a substitute. Record what remains unknown rather than treating an incomplete log or model-generated account as proof. OWASP’s guidance on audit trails and NIST’s January 12, 2026 announcement on AI-agent threat categories support investigating the actual actions and failure path.
4. Escalate to the people responsible
Notify your organization’s security or incident-response lead and the owner of the affected system or data. Involve privacy and legal staff if personal, regulated, confidential, or third-party data may be involved. Use applicable contractual and platform incident channels as well.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Do not assume a single notification deadline applies everywhere. Duties and timing depend on jurisdiction, sector, contract, data type, and incident facts. NIST SP 800-61 Rev. 3 is a general incident-response framework, not legal advice or a universal notification rule.
5. Choose the response based on impact and scope
Three questions help determine how urgently to escalate and how extensive the review should be:
Rank #4
- How reversible was the action? A read-only operation differs from an external communication, financial action, destructive change, or administrative action.
- How sensitive was the data? Public information differs from personal, regulated, confidential, or third-party data.
- How broad was the access? One resource or run differs from shared credentials, multiple systems, or a chain of agents and automations.
The more consequential or difficult to reverse the action, the more important independent validation and human approval become. OWASP recommends explicit approval for high-impact or irreversible actions.
6. Recover only after containment and review
Once you understand the effects, repair or reverse unintended changes where it is safe to do so. Revoke or rotate credentials and tokens that were exposed or misused. Restore service with narrower permissions, independent approval for high-impact actions, and close monitoring. Before restarting, verify that containment worked and review the agent’s tool access and oversight controls.
Best Value
NIST SP 800-61 Rev. 3, published in April 2025, places incident response and recovery within broader cybersecurity risk management. OWASP’s agent-security guidance also recommends least privilege, approval for high-impact or irreversible actions, and interrupt and rollback capabilities.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.7. Investigate the cause and prevent a repeat
Document the cause, impact, decisions made, and unresolved facts. Tighten access, approval boundaries, monitoring, or testing in response to what the incident revealed. Do not presume that an attack occurred: possible failure paths include indirect prompt injection, excessive autonomy, sensitive-data exposure, supply-chain issues, or harmful action without adversarial input. Investigate the evidence for this incident before deciding which controls need to change.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

