AI Provider or Model Gateway Third-Party Incident
A hosted AI provider, model gateway, proxy, marketplace, or external tool service reports or exhibits compromise, abuse, outage, unexpected behavior, model substitution, key exposure, or data-handling failure.
Trigger: A hosted AI provider, model gateway, proxy, marketplace, or external tool service reports or exhibits compromise, abuse, outage, unexpected behavior, model substitution, key exposure, or data-handling failure.
Severity guide: Severity 1 when customer data or prompts are exposed, provider authority is abused, model behavior changes materially, or business-critical service is unavailable.
First 15 minutes
- Validate the incident through provider status, security contact, and client telemetry.
- Identify affected accounts, models, regions, deployments, credentials, data classes, and business services.
- Freeze configuration changes and preserve provider, gateway, and application evidence.
- Apply planned failover or disable high-risk routes.
- Open provider, legal, procurement, and business-continuity workstreams.
First 60 minutes
- Compare provider statements with client-observed requests, responses, routes, model IDs, and costs.
- Review fallback and multi-provider routing for changed data custody or security properties.
- Rotate or constrain provider credentials when indicated.
- Assess prompt, output, file, tool, and customer-data exposure.
- Identify contractual notification, SLA, and evidence rights.
- Monitor for model substitution, region drift, and attacker adaptation.
Evidence checklist
- provider incident notices and ticket IDs
- account, deployment, model, and region
- request IDs, model IDs, routing decisions, and response metadata
- credentials, sign-ins, and key lifecycle
- prompt and output handling references
- cost and availability impact
- fallback routes and data-custody differences
- contractual controls and assurances
Containment options
- disable affected route or provider
- switch to approved fallback with explicit data boundary
- rotate credentials
- block suspicious provider origins or endpoints
- reduce entitlements and logging content
- isolate customer workloads with separate accounts
Recovery and durable controls
- provider concentration and fallback review
- independent gateway telemetry
- model and route attestation where available
- contractual evidence and notification clauses
- per-provider data classification
- quarterly failover and incident exercise
Communications
- Business continuity and product own service decisions.
- Legal and procurement own provider notices and contract action.
- Customer communication distinguishes provider statement from client-confirmed evidence.
Closure criteria
- Provider and client evidence are reconciled.
- Affected data, accounts, and services are scoped.
- Safe route is restored and tested.
- Credentials and contracts are remediated.
- Provider incident lessons enter detection and architecture backlog.
Required conversion to practice
Before closure, produce:
- one updated attack-path or trajectory diagram
- one root-cause finding
- one production or candidate hunt analytic
- one safe replay or regression test
- one remediation-validation memo
- one owner and residual-risk decision
How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.
- Leaked AI or Model API Credential
- Inference Cost Spike or Token-Jacking
- MCP Tool Poisoning, Impersonation, or Rug Pull
- Persistent Memory or RAG Poisoning
- Unauthorized Agent Action or Data Exfiltration
- Shadow or Exposed AI Infrastructure
- Malicious Model, Artifact, Skill, Plugin, or Extension
- Confidential or Sovereign AI Boundary Failure
- AI Coding Agent Repository or CI Compromise
Happening now?
Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.