AI Incident Response Plan: What to Do When Data Leaks into an AI Tool
Last updated: June 2026 · Guardrail Studio
It will happen: someone pastes a client contract, a customer list, or a password into a chatbot. What you do in the first hour decides whether it's a contained issue or a crisis. Here's a 5-step AI incident response plan you can adopt today.
The most common AI incident — and why speed matters
The typical AI incident isn't a hacker; it's a well-meaning employee pasting sensitive data into a free tool to save time. Once submitted, you may not be able to retrieve or delete it, and the clock on any notification obligation starts ticking. A plan everyone knows turns panic into a fast, contained response.
The first hour — 5 steps
- Stop. Stop using the tool. Don't delete chats or files — they may be evidence.
- Report. Tell the named contact immediately. Early reporting is rewarded, not punished.
- Capture. Note what was shared, which tool, when, and by whom.
- Contain. Rotate exposed credentials, request deletion from the vendor, restrict further access.
- Assess. Judge severity, data sensitivity, and whether notification obligations apply.
When it becomes a notifiable breach
If personal data was exposed, data-protection law may require notification. Under Singapore's PDPA, breaches that pose a risk of significant harm — or reach a scale threshold — must be reported to the PDPC and affected individuals. The GDPR has its own 72-hour regulator-notification rule. The point isn't to memorize thresholds; it's to assess quickly and get advice when a real personal-data exposure occurs.
Roles: who does what
- Reporter — stop, report, preserve information.
- Incident owner — coordinate containment, assessment, resolution.
- IT/Security — technical containment, credential rotation, vendor liaison.
- Leadership — decisions on high-severity incidents and external notifications.
Free incident-response starter
AI INCIDENT — FIRST HOUR 1. STOP using the tool. Do not delete anything. 2. REPORT to [security@company] immediately. No blame for early reports. 3. CAPTURE: what data, which tool, when, who. 4. CONTAIN: rotate exposed secrets; request vendor deletion; restrict access. 5. ASSESS: severity + whether PDPA/GDPR notification applies. Escalate if personal data or client confidential data was exposed. Contact: [name] · [email] · [phone] Out-of-hours: [contact]
Build it into your policy
Guardrail's AI Policy OS includes a full incident-response playbook with a severity guide and roles, alongside the policy, risk register, and training that prevent most incidents in the first place. The PDPA angle is covered in our Singapore guide.
Get the incident-response playbook
Policy, 25-risk register, staff training, playbooks, and proof — editable and live in an afternoon.
Get the AI Policy OS from S$129 →Frequently asked questions
Is data pasted into ChatGPT a reportable breach?
It can be. If personal data was exposed, PDPA and GDPR both have thresholds that can require notifying the regulator and affected individuals. Whether it crosses the line depends on the data and the risk of harm — which is why the assessment step matters. When unsure, get advice quickly.
What should an employee do the moment they realize?
Stop using the tool, don't delete anything (you may need the trail), and report it immediately to the named contact. Speed limits the harm — and early reporting should never, by itself, lead to discipline.
Do small companies really need an incident plan?
Yes — a one-page plan is enough, and it's the difference between a contained issue and a scramble. It also demonstrates to clients and insurers that you manage AI risk, not just hope to avoid it.