Skip to main content
ShadowAI Defense GitHub
← All runbooks
RB-002 High

Sensitive data egress to AI service confirmed (DLP positive)

Purview DLP (DET-MS-PV-001) or Falcon Data Protection (DET-CS-FALCON-002) detects confirmed sensitive content egress to a consumer AI service, with an override or attempted bypass.

Triggers

Immediate response (first hours)

  1. L1 SOC analyst: Treat as candidate data-loss incident. Preserve DLP event with full metadata and content fingerprint (do not retain raw sensitive content).
  2. L2 SOC analyst: Identify what data class was egressed (PII / PHI / PCI / IP / regulated). If regulated or customer data: ESCALATE to AI-CTRL-009 Incident Response runbook within 1 hour.
  3. L2 SOC analyst + Privacy/Legal: If user override was applied, capture the override justification. Validate the justification is consistent with policy. (Within 4 hours)

Short-term response (within days)

  1. AI Governance triage + Privacy: Assess regulatory notification triggers (GDPR Article 33, sectoral). Privacy/Legal own the determination. (Within 24 hours for regulated data)
  2. AI Governance triage: Initiate contact with vendor (where contractual) to request deletion of the egressed content. Track deletion certificate. (Within 5 business days)
  3. Direct manager + HR: Conduct formal conversation with the user. Document outcomes per HR process. Determine if user requires additional training, restriction, or further action. (Within 10 business days)

Long-term response (weeks+)

  1. AI Governance triage: Add user to enhanced monitoring (60 days). Add data class to review list for additional Sensitive Info Type tuning.
  2. AI Governance Committee: If pattern across multiple users: program-level review of approved-tool gaps, comms effectiveness, and policy clarity.

Decision tree

  • Is the egressed data regulated (PHI / PCI / PII subject to GDPR-like rights)?
    • Yes → Escalate to AI-CTRL-009 IR. Privacy/Legal lead notification determination.
    • No → Manage internally per this runbook.
  • Was the user override appropriate per policy?
    • Yes → Close after manager conversation and AUP attestation.
    • No → HR involvement; consider disciplinary path.

RACI

  • Responsible: L2 SOC analyst
  • Accountable: CISO (or designated incident commander)
  • Consulted: Privacy lead, Legal, Vendor manager, Direct manager, HR Business Partner
  • Informed: AI Governance Committee, Audit committee (per incident severity threshold)

Metrics to capture

  • Time from DLP detection to triage (target: ≤ 1 hour for High)
  • Time from confirmation to regulator notification (target: per applicable law)
  • Vendor deletion certificate obtained (Yes/No, time-to-receipt)
  • Recurrence rate by user / by data class / by business unit

Comms templates

  • comms-incident-notification-sensitive-data-egress
  • comms-manager-talking-points-sensitive-data
  • comms-regulator-notification-template

Framework mappings

  • NIST AI RMF: GOVERN-4.1, MANAGE-2.2, MANAGE-4.3
  • ISO/IEC 42001: 8.3, 8.5, 10.1
  • NIST CSF: RS.RP-1, RS.AN-1, RS.MI-1, RC.CO-2

Related AI Controls Catalog entries