RB-007 Medium
AI-generated content identified in external communications
Manual report or DLP detection of AI-generated content in outbound emails, reports, or client deliverables. Triggered by DET-MS-PV-001 content-inspection policies flagging AI-characteristic patterns, or DET-MS-SEN-005 detecting unusual volumes of content with AI markers.
Triggers
Immediate response (first hours)
- AI Governance triage: Identify the scope of the AI-generated content: which documents, emails, or deliverables are affected. Determine whether the content has been sent externally or is still in draft.
- AI Governance triage: Assess whether the content is client-facing, regulatory-facing, or has potential legal or reputational impact. If regulatory filing: escalate to Legal immediately.
- AI Governance triage: Preserve evidence: capture the content metadata, AI-generation indicators, and distribution list. Do not alter or recall the content without Legal guidance. (Within 24 hours)
Short-term response (within days)
- AI Governance triage + Content owner: Review the AI-generated content for accuracy, hallucinations, and factual errors. Document any inaccuracies found. (Within 5 business days)
- Legal + Compliance: Determine disclosure obligations. Consider: industry-specific AI disclosure requirements, contractual obligations with clients, and regulatory guidance on AI-generated content in the applicable jurisdiction. (Within 10 business days)
- AI Governance triage: If disclosure is required: draft disclosure communication in coordination with Legal. If not required: document the determination and rationale.
Long-term response (weeks+)
- AI Governance Committee: Develop or update the organization's AI content disclosure policy. Define which content types require human review, disclosure, or prohibition of AI generation.
- AI Governance triage + IT: Implement a content review workflow for high-risk content types (regulatory filings, client deliverables, press releases). Consider AI-content detection tooling in the review pipeline.
- AI Governance triage: Issue all-employee education communication (comms/all-employee-education) reinforcing expectations around AI-generated content and disclosure requirements.
Decision tree
- Has the AI-generated content been sent externally?
- Yes → Assess regulatory and client impact immediately.
- No → Review and correct before distribution.
- Does the content contain factual errors or hallucinations?
- Yes → Initiate correction and consider recall/retraction with Legal guidance.
- No → Focus on disclosure obligations.
- Are there regulatory or contractual AI disclosure requirements?
- Yes → Draft and issue disclosure per Legal guidance.
- No → Document determination; update policy to prevent recurrence.
RACI
- Responsible: AI Governance triage
- Accountable: AI Governance lead
- Consulted: Legal, Compliance, Content owner, Client relationship manager (if client-facing)
- Informed: AI Governance Committee, Communications / PR (if public-facing)
Metrics to capture
- Number of AI-generated content incidents per quarter
- Percentage involving client-facing or regulatory content
- Time from detection to content review completion (target: ≤ 5 business days)
- Number of required disclosures issued
- Recurrence rate after employee education (target: declining trend)
Comms templates
comms-all-employee-education
Framework mappings
- NIST AI RMF: GOVERN-4.1, MAP-3.3, MANAGE-4.1
- ISO/IEC 42001: 8.2, 8.4
- NIST CSF: RS.AN-1, RS.CO-2