RB-001 Medium
Repeated consumer LLM use by individual employee
Sentinel rule DET-MS-SEN-001 (or platform equivalent) fires for an individual user with > 5 connections to consumer LLM domains in 24 hours, OR DLP records repeated paste-to-AI events over a 7-day window.
Triggers
Immediate response (first hours)
- L1 SOC analyst: Triage alert in SIEM. Confirm the user identity, device, and pattern. Rule out service accounts, security testing, and explicit approved-pilot membership.
- L1 SOC analyst: Check the AI Approved-Pilot register (link maintained in AI-Governance-Toolkit). If user is in an approved pilot for the detected service, close as benign with note.
- L1 SOC analyst: If NOT in approved pilot: enrich the alert with recent DLP events for the user (last 30 days), recent file uploads to consumer services, and manager from HR system. Escalate to L2.
- L2 SOC analyst: Determine if any DLP event indicates sensitive-data egress (regulated, IP, customer). If yes: ESCALATE to RB-002. If no: proceed to short-term.
Short-term response (within days)
- L2 SOC analyst + AI Governance triage: Use the comms template comms/individual-warning-first-occurrence. Send to user via email, CC their direct manager. Use approved-tool launch communication (comms/approved-tool-announcement) so user has a constructive path forward. (Within 5 business days of alert)
- AI Governance triage: Log the case in the AI Governance Risk Register (or local issue tracker) with: user pseudonym (do not store name in register), service detected, business context, recommendation issued. (Within 5 business days)
- Direct manager: 1:1 conversation with employee. Confirm awareness of AUP. Identify whether legitimate business need exists; if so, route to AI Use-Case Intake (link to AI-Governance-Toolkit /inventory).
Long-term response (weeks+)
- AI Governance triage: Add user to 30-day enhanced monitoring list (lower threshold on DET-MS-SEN-001 to flag any further consumer LLM use).
- AI Governance triage: If repeat occurrence within 90 days: ESCALATE to escalation comms template (comms/individual-warning-repeat-occurrence) with manager + HR partner involved.
- AI Governance triage (quarterly): Aggregate cohort metrics (total cases, repeat rate, conversion-to-approved-pilot rate). Report to AI Governance Committee and adjust program based on patterns observed.
Decision tree
- Is user in approved AI pilot for this service?
- Yes → Close as benign with note.
- No → Proceed to sensitive-data check.
- Did DLP record sensitive-data egress in the window?
- Yes → Escalate to RB-002.
- No → Issue first-occurrence warning + approved-tool comms.
- Repeat occurrence within 90 days?
- Yes → Escalate to repeat-occurrence comms with HR partner.
- No → 30-day enhanced monitoring; close after 30 days clean.
RACI
- Responsible: L1/L2 SOC analyst
- Accountable: AI Governance triage lead
- Consulted: Direct manager, HR Business Partner (for repeat), Legal (only if disciplinary)
- Informed: AI Governance Committee (quarterly aggregate)
Metrics to capture
- Time from detection to first response (target: ≤ 24 hours)
- Time from first response to user notification (target: ≤ 5 business days)
- Repeat occurrence rate (target: < 10% within 90 days)
- Conversion to approved-pilot enrollment rate (target: > 30%)
- Hours of SOC analyst effort per case
Comms templates
comms-individual-warning-firstcomms-approved-tool-announcementcomms-individual-warning-repeatcomms-manager-talking-points
Framework mappings
- NIST AI RMF: GOVERN-4.1, MANAGE-2.2, MANAGE-4.1
- ISO/IEC 42001: 8.2, 8.4, 10.2
- NIST CSF: RS.AN-1, RS.MI-1