Home · AI Security & Identity · AI Incident Response

When an AI goes wrong,
you'll have a plan — and someone to call.

An agent emails the wrong list. An assistant leaks a file. An automation is hijacked. Most small firms have no plan for any of it, and no way to tell whether a person or the AI did it. We give you the plan, the kill switches and the evidence trail. Then we're on the end of the phone when it happens.

THE FIRST DAY, WITH A PLAN0 minDetectsomeone notices4 minStopkill switch run1 hourTraceAI vs human actionsSame dayNotifyICO · customers toldWeek 1Learnfix the causeWithout a plan: a week of panic and a 72-hour ICO clock already running

The first hour decides the week

No plan for AI incidents

Your IT or cyber plan was written before AI agents could act on their own.

Can't switch it off fast

Nobody knows every place an agent is connected, or how to revoke its keys.

Can't tell who did it

Logs don't separate human actions from AI actions.

72 hours

Serious personal data breaches must be reported to the ICO within 72 hours. Could you work out what happened in time?

Insurer questions

Cyber insurers increasingly ask about AI use and controls. “We don't know” is a bad answer.

Customers to tell

If an AI sent something it shouldn't, who tells customers, and what do they say?

Ready before it happens

  • ✓An AI incident plan: who does what in the first hour, the first day and the first week
  • ✓Kill switches: how to stop every agent and revoke every key and connector, tested in advance
  • ✓An evidence trail: logging set up so you can separate what the AI did from what people did
  • ✓Templates: internal notes, customer notices, and an ICO breach assessment and report
  • ✓An insurer-ready record of your AI agents and the controls around them
  • ✓A response retainer: we're on call when something happens, and we run a practice drill once a year

Incident response is a known discipline in security. The AI twist is that your “employee” may have acted thousands of times before anyone noticed. Speed and evidence matter more than ever.

The first hour

Who does what, written down before it's needed.

WhenWhoDoes
0:00AnyoneSpots it · calls the owner
0:05OwnerRuns the kill switch for that agent
0:10OwnerCalls Eutaxis · opens the incident log
0:20EutaxisConfirms the agent is stopped everywhere
0:30Eutaxis + ITPulls the logs · AI actions vs human
1:00OwnerDecides: ICO assessment? customers?

Then the first day and the first week, on one page.

Prepare, drill, respond, learn

Set-up for a small firm takes two to three weeks. The drill is a two-hour session. The retainer runs from the day the plan is signed off.

1

Prepare

Agent register, kill switches, logging and templates put in place. Roles agreed.

2

Drill

A tabletop exercise: we walk your team through a realistic AI incident and fix the gaps it shows.

3

Respond

When it happens, you call us. We help contain it, work out what happened, and support the reporting.

4

Learn

After the incident, a short review: what to change so it doesn't happen twice.

What this looks like in practice

A recruitment agency's automation sent 400 candidates an email meant for one client, including a salary. With a plan, the owner stopped the flow in four minutes, we traced which records were touched within the hour, and the ICO assessment and the candidate notice went out the same day. Without a plan, that's a week of panic.

Illustrative example, drawn from typical findings. Not a named client.

“Access control is the part most AI suppliers wave at. It's the part we came from.”

Michael LewisFounder, Eutaxis · 13 years in identity & access management

The things everyone asks first

What counts as an AI incident?

Any time an AI agent or automation does something it shouldn't: sends the wrong thing, leaks or deletes data, takes an action nobody approved, or is taken over by someone outside. Also, a person using an AI tool in a way that exposes data.

We have cyber insurance. Isn't that enough?

Insurance pays some of the costs afterwards. It doesn't stop the agent, find the cause or write the ICO report, and most policies expect you to have reasonable controls in place. This gives you the controls and the evidence that you had them.

What does the retainer include?

Being on call during agreed hours, a set number of response hours a year, the annual drill, and keeping your plan and register current as your AI use changes. Anything beyond that is quoted before we start.

Can you work with our IT provider?

Yes, and we'd rather. They know your systems; we know AI agents and identity. The plan says who does what.

Do we have to report every incident to the ICO?

No. Only personal data breaches likely to risk people's rights and freedoms must be reported, within 72 hours of becoming aware. Our template walks you through that assessment so you make the decision properly and record it.

How much does it cost?

The set-up is a fixed price after a free discovery call. The retainer is a monthly figure based on your size and the hours of cover you want.

The other AI Security & Identity services

See how the five fit together →

If an AI agent went wrong tonight, who would you call?

Let's make sure the answer isn't “nobody”.