Defend and operate / Module 14

Prepare evidence, response, disclosure, and governance before failure

Connect technical controls to incident handling, responsible disclosure, risk ownership, and the EU operating context.

60 minutes Beginner to intermediate Practical lab
01

Define AI incident categories

Examples include data disclosure, unauthorized tool action, model or dataset compromise, persistent prompt injection, abusive output, evaluation bypass, runaway cost, service denial, and unapproved model change. Each needs an owner and severity criteria tied to impact.

Decide how to disable tools, revoke agent identities, roll back models or indexes, preserve evidence, notify affected owners, and communicate uncertainty.

02

Preserve the decision trace

Capture the initiating identity, full control-flow metadata, policy and model versions, retrieved source identifiers, tool proposals, authorization decisions, approvals, external side effects, and relevant infrastructure logs.

Preservation must respect privacy and retention rules. Do not solve an investigation gap by collecting every prompt forever.

03

Disclose responsibly and contextually

The source PDF presents 90 days as an industry standard. In practice, disclosure timelines vary with policy, severity, exploitability, coordination, and legal obligations. Follow the vendor's published security policy or bug-bounty terms, report privately, minimize sensitive evidence, and coordinate remediation.

Testing outside authorization can create legal and operational harm even when the intent is research. Seek qualified legal advice for jurisdiction-specific questions.

This field guide is educational, not legal advice. Written authorization and applicable law remain controlling.
04

Connect controls to governance

An AI inventory, risk classification, owner, evaluation record, incident history, and evidence trail make governance operational. Board or risk reporting should show exposure, control effectiveness, exceptions, and time to close—not only policy completion.

For EU deployments, security work should be coordinated with the AI Act, data protection, cybersecurity, product, employment, and sector-specific obligations. The related Vanderburgh.it guide tracks the 2026 amendment timeline.

Practice

Tabletop an unauthorized agent action

Safety boundary: Use a fictional incident with no real customer or employee data.

  1. 01

    Describe an agent that sends a file to an unapproved destination after indirect prompt injection.

  2. 02

    List immediate containment actions for identity, tool, model, and connector.

  3. 03

    Identify the evidence needed to reconstruct the decision path.

  4. 04

    Assign technical, privacy, legal, communications, and business owners.

  5. 05

    Write three preventive and three detective improvements with deadlines.

Checkpoint

Ready to move on?

Go deeper

Primary sources for this module

All resources
Previous module13 · Secure the AI supply chain and cloud runtime Continue toSources and glossary
Share this module LinkedIn Email Permanent link