Start here. This is the direct spoken answer to practice first.
Overview
AI incidents can affect prompts, data, indexes, tools, provider state, and external actions at the same time.
I first contain the impact by disabling the affected tool, source, model route, egress path, or feature while preserving a safe degraded mode where possible. I preserve versioned traces, audit events, approvals, tool receipts, source lineage, and provider identifiers, then determine which users, tenants, data, and external actions were affected. Credentials and compromised integrations are revoked through their normal security systems.