A complete incident response plan for shadow AI security incidents. Covers detection through recovery with severity levels, communication templates, and GDPR breach assessment guidance.
Updated March 2026 · 6 response phases · GDPR Article 33, ISO 27001, NIST IR aligned
Shadow AI incidents have unique characteristics that standard IT security incident response plans are not designed to handle. Unlike a traditional data breach, you often cannot recall data submitted to an AI service — and the legal implications of AI provider training terms create novel GDPR exposure that requires specialist assessment.
Click each phase to expand. Customise the highlighted placeholders and adapt severity thresholds to your organisation's risk appetite.
Shadow AI incidents are classified by the severity of data exposure and the regulatory implications. Use this matrix to determine the appropriate response track.
Confirmed exposure of Restricted data (PII of 100+ individuals, credentials, health data, financial account data) to an external AI service with potential training data retention. Regulatory notification likely required.
Immediate escalation to CISO + DPO. Incident Commander activated. 72-hour GDPR clock may be running.
Confirmed exposure of Confidential data (strategic plans, IP, contracts, limited PII) to unapproved AI service. No confirmed training data retention but cannot be excluded.
Security team lead notified within 2 hours. Legal/Privacy engaged. Containment initiated same business day.
Unapproved AI tool usage confirmed with Internal-classified data. No personal data confirmed but investigation required to verify scope.
Security analyst assigned within 4 hours. Manager of affected employee notified. Investigation initiated.
Unapproved AI tool usage confirmed with Public or non-sensitive Internal data only. Policy violation but no data exposure risk identified.
Logged and tracked. Manager notified. Policy reminder issued. No emergency response required.
An incident response plan only works if it has been operationalised before an incident occurs. Follow these steps to go from template to live process.
Aona continuously discovers unapproved AI tools across your organisation, detects sensitive data being submitted to external AI services, and alerts your security team in real time — before a shadow AI incident becomes a GDPR breach.
Book a Demo