Notifications
Clear all
Topic starter
16/07/2026 5:49 pm
Just finished a SOC 2 audit and realized our incident response playbook feels... outdated. We have steps for data breaches, DDoS, etc., but nothing addressing AI-specific issues.
For example, what’s the procedure if a vendor's AI model our team uses starts generating harmful or sensitive outputs? Or if there's a prompt injection attack against an internal tool? Our current plan just says "contain the affected system," but that seems too vague for AI. Are others running into this? What scenarios are you adding? Thanks in advance!
Still learning.