
AI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0, OWASP Top 10 for Agentic Applications 2026, ISO/IEC 42001, EU AI Act.
Why an overlay, not a replacement. The thesis.
Part of the AI IR Overlay™ framework. See CONTENT_MAP.md for the full repository map.
Current release: v0.35.0 · 2026-07-09 · CHANGELOG
A practical incident-response baseline for AI agents in production. Adapt and critique freely.
Traditional incident response (codified in NIST SP 800-61 r3, which superseded r2 in April 2025) was built around unauthorized access vectors: malware, exploits, credential theft, lateral movement. AI agents change the failure mode.
AI incidents often manifest through authorized channels:
When the actor is authorized, the question shifts from "who got in?" to "what could it touch, and what did it do?" Crucial evidence now lives in prompts, tool calls, retrieval traces, and configuration state. Not on endpoints.
The core mechanics of effective incident response remain unchanged:
AI doesn't rewrite the rules of effective IR. It changes the map.
The AI IR Overlay operationalizes deployer obligations for AI systems in production. A deployer is the organization that uses an AI system in its own operations, under its own oversight (per EU AI Act Article 3). This framework is for the security team responding to incidents in agents the deployer's organization runs.
Out of scope:
Vendor copilots that an organization deploys are in scope for the deployer (the customer side). The vendor's provider obligations are not addressed here.
The AI IR Overlay adds four agent-aware controls (the Minimum Viable Overlay, or MVO) on top of your existing IR program.
Note: The phases shown below align with NIST SP 800-61 r3 (April 2025), unpacked into seven operationally-distinct columns per
MATRIX.mdSection 1. NIST SP 800-61 r3 restructures incident response around NIST CSF 2.0 functions (Govern, Identify, Protect, Detect, Respond, Recover); see the AI IR Overlay to CSF 2.0 crosswalk atcrosswalks/nist-csf-2.mdfor the function-level mapping.
┌───────────────────────────────────────────────────────────────────────┐
│ AI IR Overlay Response Flow (NIST SP 800-61 r3, unpacked) │
│ │
│ Preparation → Detection → Triage → Containment → Evidence → │
│ Recovery → Closure │
└───────────────────────────────────────────────────────────────────────┘
│
▼
┌───────────────────────────────────────────────────────────────────────┐
│ AI IR Overlay · MVO Controls (4) │
│ │
│ 1. INVENTORY · Agents · Identities · Tools · Write Targets │
│ 2. SAFE MODES · Kill-Switch Ladder (M0–M5; 6 M3 + 2 M4 variants) │
│ 3. EVIDENCE · Minimum AI Evidence Set (Types A–F) │
│ 4. CONTROLLED · Staged, validated re-enablement │
│ RE-ENABLE │
└───────────────────────────────────────────────────────────────────────┘
For the full phase-by-control matrix view, see MATRIX.md Section 1.
If you are responding to an AI agent incident right now, start with RESPONSE-START.md for the four-file navigation path that takes you from 3am page to a defensible 60-minute checkpoint.
New here? Start with QUICKSTART.md for the standard 30-day adoption path. For startups and small security teams (5 or fewer people, limited platform control), QUICKSTART-startup.md is the 4-week minimum-viable path targeting Maturity Level 2. For a worked end-to-end example, see examples/incident-walkthrough.md. For working code examples of the framework's API contracts, see reference-impls/.
For the full conceptual reading order, items 1 through 8 are the core, items 9 through 15 are the working artifacts.
For a self-contained tabular reference (matrix view of the framework: phases, kill-switch ladder, evidence types, metrics, MVO controls, maturity levels, playbook index, standards crosswalk), see MATRIX.md.