Skip to main content
ShadowAI Defense GitHub
← All runbooks
RB-005 High

AI use detected in restricted department (Legal, HR, Finance)

Detection of AI service access from users in restricted departments (Legal, HR, Finance) via DET-MS-SEN-001 enriched with department data, DET-MS-MCAS-002 user-scope filtering, or DET-NET-001 correlated with identity source.

Triggers

Immediate response (first hours)

  1. L1 SOC analyst: Verify the user's department against the HR system. Confirm the department is on the restricted list per the AI Acceptable Use Policy.
  2. L1 SOC analyst: Confirm the restriction policy is current and applies to the detected service. Check for any department-level exceptions or approved pilots.
  3. L2 SOC analyst: Notify the department manager within 4 hours. Provide factual summary: user identity (pseudonymized in logs), service accessed, timestamp, and applicable policy section. (Within 4 hours of alert)

Short-term response (within days)

  1. AI Governance triage + Department manager: Interview the user to understand the business context. Determine if a legitimate business need exists and whether sensitive departmental data (attorney-client privilege, employee PII, financial non-public information) was involved. (Within 5 business days)
  2. AI Governance triage: Assess data exposure. Review DLP events for the user in the detection window. If sensitive data egress is confirmed, escalate to RB-002. (Within 5 business days)
  3. AI Governance triage: If no data exposure: issue department-appropriate warning using comms/individual-warning-first. If data exposure: coordinate remediation with Privacy/Legal per RB-002. (Within 10 business days)

Long-term response (weeks+)

  1. AI Governance Committee + Department leadership: Review the department restriction policy. Determine whether the restriction remains appropriate or whether approved alternatives should be evaluated for the department's specific workflows.
  2. AI Governance triage: If department leadership identifies legitimate use cases: initiate approved-alternative evaluation with enterprise-grade tools that meet the department's regulatory and privilege requirements.
  3. AI Governance triage: Update detection rules to add department-specific alerting thresholds. Add the department to enhanced monitoring for 90 days.

Decision tree

  • Is the user confirmed to be in a restricted department?
    • Yes → Proceed with restricted-department response.
    • No → Re-route to standard RB-001 process.
  • Is the department restriction still current and applicable?
    • Yes → Enforce per policy.
    • No → Update restriction list; handle as standard RB-001.
  • Did the user handle sensitive departmental data (privileged, PII, MNPI)?
    • Yes → Escalate to RB-002 for data-exposure response.
    • No → Issue warning and monitor.

RACI

  • Responsible: L1/L2 SOC analyst
  • Accountable: AI Governance triage lead
  • Consulted: Department manager, Department head, Legal (for Legal dept incidents), HR Business Partner (for HR dept incidents), CFO office (for Finance dept incidents)
  • Informed: AI Governance Committee, CISO

Metrics to capture

  • Time from detection to department manager notification (target: ≤ 4 hours)
  • Time from notification to user interview (target: ≤ 5 business days)
  • Rate of data exposure confirmed in restricted-department cases
  • Number of restricted-department cases converting to approved-alternative evaluations
  • Repeat rate by department (target: < 5% within 90 days)

Comms templates

  • comms-manager-talking-points
  • comms-individual-warning-first
  • comms-department-level-briefing

Framework mappings

  • NIST AI RMF: GOVERN-4.1, MANAGE-2.2, MANAGE-4.1
  • ISO/IEC 42001: 8.2, 8.4, 10.2
  • NIST CSF: RS.AN-1, RS.MI-1, PR.AC-1

Related AI Controls Catalog entries