All scenarios
Cross-industry

The compromised AI assistant

An employee installs an unvetted AI assistant to hit a deadline and connects it to everything. It turns out to harvest tokens and files. Now you must scope what a third-party tool could reach, revoke its access and decide whether a data breach is notifiable, before you even know what left the building.

Free to use for your own tabletop, no email gate.

Scenario brief

The compromised AI assistant, Cross-industry

The threat

Under deadline pressure, an employee downloads a free AI productivity assistant from outside the software catalogue and grants it broad access: local files, browser sessions and an OAuth connection to the company workspace. The tool is a look-alike bundled with an information stealer. For a week it quietly reads mail, documents and access tokens and streams them to an attacker, who now holds a valid foothold in your tenant.

Key injects

  • 01DLP flags a large upload from a workstation to an unknown personal cloud; EDR sees a new signed helper beaconing out.
  • 02The employee admits they installed a free AI assistant last week and connected it to everything to speed up reports.
  • 03Identity logs show the tool holds active OAuth tokens to the company workspace; the sessions are still live.
  • 04A threat-intel feed reports the tool's publisher was pulled for bundled malware, and a sample of your data appears in a paste.

What's assessed

  • Rapid scoping of what a third-party tool could access: accounts, data and tokens
  • Token and session revocation decisions across the tenant under uncertainty
  • Breach-notification judgement (GDPR, NIS2) when exfiltration is probable but unproven
  • AI and tool governance, and an honest internal message that surfaces the next case instead of hiding it

Exercise objectives

  • Within 30 minutes, establish and document what the AI tool could reach (accounts, data stores, tokens) and revoke its access.
  • Contain identity and token abuse across the tenant inside the first hour, with the decision to force re-authentication taken on the record.
  • Decide, before the exercise ends, whether the incident is a notifiable personal-data breach under GDPR Art. 33 (72 hours) and significant under §32 BSIG (24-hour early warning).
  • Agree an AI-tool governance decision and an internal message that makes the next person come forward rather than hide the install.

Roles at the table

  • Crisis team lead · Owns cadence, decision log and escalations; keeps the room on decisions while the blast radius is still moving.
  • IT / SOC / identity lead · Scopes the tool's access, revokes tokens and sessions, and gives the honest answer to what it could already have taken.
  • Legal / data protection (DPO) · GDPR Art. 33/34 assessment, §32 BSIG significance, evidence handling and the definition of probable.
  • Communications · The internal message, and an external line ready if the data surfaces publicly.
  • HR / people lead · The conversation with the employee, and the culture question: how the next shadow-AI install gets reported, not buried.
  • Executive sponsor · Disclosure stance, spending authority and the final call when speed and certainty pull against each other.

Discussion prompts

  • 01The tool held workspace access for a week. What do you assume it took, and how would you prove otherwise to a regulator?
  • 02You can force re-authentication and kill every session to be safe, but it logs the whole company out mid-day. Who authorises that, and when?
  • 03No exfiltration is proven, only possible. Does the 72-hour clock under GDPR Art. 33 start, and who decides what probable means?
  • 04The employee acted to hit a deadline, not to harm anyone. How do you handle them so the next person still comes forward?
  • 05How many other unvetted AI tools are installed across the company right now, and how do you find them without a witch hunt?
  • 06Could you show a regulator exactly which data the tool could reach and what you decided in the first hour?

Suggested timeline

  • 00:00–00:20Detection & triage: DLP/EDR alert, first scoping, crisis team convenes
  • 00:20–01:00Containment: revoke tool access, token and session decisions, map the blast radius
  • 01:00–02:00Escalation peak: threat-intel confirms bundled malware, a data sample surfaces, disclosure pressure
  • 02:00–02:40Reporting & comms: GDPR and §32 assessment, internal message, AI-governance decision
  • 02:40–03:00Hot wash: decisions reviewed against the timestamped log

Run this scenario with your team.