Skip to main content
ShadowAI Defense GitHub
← All runbooks
RB-007 Medium

AI-generated content identified in external communications

Manual report or DLP detection of AI-generated content in outbound emails, reports, or client deliverables. Triggered by DET-MS-PV-001 content-inspection policies flagging AI-characteristic patterns, or DET-MS-SEN-005 detecting unusual volumes of content with AI markers.

Triggers

Immediate response (first hours)

  1. AI Governance triage: Identify the scope of the AI-generated content: which documents, emails, or deliverables are affected. Determine whether the content has been sent externally or is still in draft.
  2. AI Governance triage: Assess whether the content is client-facing, regulatory-facing, or has potential legal or reputational impact. If regulatory filing: escalate to Legal immediately.
  3. AI Governance triage: Preserve evidence: capture the content metadata, AI-generation indicators, and distribution list. Do not alter or recall the content without Legal guidance. (Within 24 hours)

Short-term response (within days)

  1. AI Governance triage + Content owner: Review the AI-generated content for accuracy, hallucinations, and factual errors. Document any inaccuracies found. (Within 5 business days)
  2. Legal + Compliance: Determine disclosure obligations. Consider: industry-specific AI disclosure requirements, contractual obligations with clients, and regulatory guidance on AI-generated content in the applicable jurisdiction. (Within 10 business days)
  3. AI Governance triage: If disclosure is required: draft disclosure communication in coordination with Legal. If not required: document the determination and rationale.

Long-term response (weeks+)

  1. AI Governance Committee: Develop or update the organization's AI content disclosure policy. Define which content types require human review, disclosure, or prohibition of AI generation.
  2. AI Governance triage + IT: Implement a content review workflow for high-risk content types (regulatory filings, client deliverables, press releases). Consider AI-content detection tooling in the review pipeline.
  3. AI Governance triage: Issue all-employee education communication (comms/all-employee-education) reinforcing expectations around AI-generated content and disclosure requirements.

Decision tree

  • Has the AI-generated content been sent externally?
    • Yes → Assess regulatory and client impact immediately.
    • No → Review and correct before distribution.
  • Does the content contain factual errors or hallucinations?
    • Yes → Initiate correction and consider recall/retraction with Legal guidance.
    • No → Focus on disclosure obligations.
  • Are there regulatory or contractual AI disclosure requirements?
    • Yes → Draft and issue disclosure per Legal guidance.
    • No → Document determination; update policy to prevent recurrence.

RACI

  • Responsible: AI Governance triage
  • Accountable: AI Governance lead
  • Consulted: Legal, Compliance, Content owner, Client relationship manager (if client-facing)
  • Informed: AI Governance Committee, Communications / PR (if public-facing)

Metrics to capture

  • Number of AI-generated content incidents per quarter
  • Percentage involving client-facing or regulatory content
  • Time from detection to content review completion (target: ≤ 5 business days)
  • Number of required disclosures issued
  • Recurrence rate after employee education (target: declining trend)

Comms templates

  • comms-all-employee-education

Framework mappings

  • NIST AI RMF: GOVERN-4.1, MAP-3.3, MANAGE-4.1
  • ISO/IEC 42001: 8.2, 8.4
  • NIST CSF: RS.AN-1, RS.CO-2

Related AI Controls Catalog entries