Define AI incident categories
Examples include data disclosure, unauthorized tool action, model or dataset compromise, persistent prompt injection, abusive output, evaluation bypass, runaway cost, service denial, and unapproved model change. Each needs an owner and severity criteria tied to impact.
Decide how to disable tools, revoke agent identities, roll back models or indexes, preserve evidence, notify affected owners, and communicate uncertainty.