What is AI detection and response (AIDR)?
By Identra · Updated
AI detection and response (AIDR) is the practice of identifying, investigating and containing security threats involving AI applications and agents. It connects AI activity to the people, permissions and data involved so teams can establish what happened and stop further harm.
What counts as an AI security incident?
Some examples. An engineer pastes an AWS access key into Gemini while signed in to a personal Google account. Claude Code runs a destructive shell command in a directory it was never asked to touch. A support agent sends an internal runbook to a URL it found in a ticket.
Nobody has to be attacking you. Accidental sharing alone can cause AI data leakage. An authorized agent can also follow instructions hidden in something it reads.
Keep the outcomes apart. A new AI app showing up is a finding. A blocked upload is an attempt. A completed transfer is an exposure. Severity should follow the evidence, whatever the alert happens to be called.
How does AIDR work?
It pulls AI activity into an investigation and gives responders a way to act on it. The useful evidence is plain: who started the task, which account or agent did the work, which tool calls it made, what they touched and whether they finished.
Identity is the hard part. A person kicks off a task. An agent runs it. A connected app reaches the data with its own OAuth token. Pin every action on the person who opened the chat and the investigation goes wrong from the first line.
Detections come from policy hits, odd behavior and users reporting things. Ask whether the action was allowed, whether it finished and what the same access could do next. Then respond against the specific account, integration or agent.
What does an AI incident look like in practice?
Say an agent's job is to summarize customer tickets. One ticket tells it to fetch an internal troubleshooting doc and post it to an external URL. That's indirect prompt injection. The instructions came in through content the agent was asked to process.
Reading the ticket is not the incident. An outbound tool request is evidence of an attempt. Tool execution records and proxy logs tell you whether anything left. The model saying it sent the file proves nothing either way.
Pause the agent. Cut the integration's access. Rotate anything that may have been exposed. Keep the malicious ticket. Before the agent goes back into service, narrow which docs it can read and where it can send data.
How is AIDR different from EDR, ITDR and AI posture management?
One incident often needs several of them. A coding agent that launches a malicious binary is an endpoint case. If it used a stolen token, it's an identity case too. AIDR adds the AI side: what task was running and what the agent did on someone's behalf.
Identity threat detection and response handles credential and session abuse. AI security posture management catches risky access before anything happens. Vendors use these labels loosely, so check what each product can actually see and do.
AIDR
- Focus
- Threats involving AI activity
- Typical question
- Did the agent send data outside its task?
EDR
- Focus
- Endpoint threats
- Typical question
- What process ran, and what did it change?
ITDR
- Focus
- Identity and access threats
- Typical question
- Is this session or credential being abused?
AI posture management
- Focus
- AI configuration and exposure
- Typical question
- Does this agent have access it doesn't need?
When should you alert, block or revoke?
Alert when someone needs to look. Block when a control can stop the action before it completes. Pause the agent or pull its access when letting it keep going makes things worse.
Know the limits. Blocking a prompt doesn't undo yesterday's upload. Revoking an OAuth grant doesn't pull back copied data, and refresh tokens or live sessions may need their own revocation. Check that containment held. A successful API call to revoke is not the same as revoked.
Decide ahead of time which responses run on their own and which need a business owner to sign off. Cutting one agent's access is easier to verify and undo than disabling a shared integration half the company depends on.
What do you need in place before the first incident?
Start with the AI workflows that touch sensitive data or can change important systems. Give each an owner and list its accounts, sources, tools and destinations. Apply least privilege so a planted instruction can't turn into a broad action.
- Severity criteria based on data sensitivity, the access involved and confirmed effect.
- An AI audit trail that shows who started the task, which identity acted, what it touched and whether it completed, without copying full prompts into tickets.
- Runbooks for leaked credentials, poisoned content and unauthorized tool calls.
- A tested way to pause agents, remove grants and kill sessions in each service you rely on.
How Identra thinks about it
Identra ties browser, endpoint and identity provider activity to the person involved and groups it into incidents on one timeline. Every AI agent run on an endpoint is recorded with the user, device, AI client and whether it was allowed or blocked. Teams can block risky prompts and agent tool calls by policy, revoke risky OAuth grants and revoke sign-in sessions with approval. Optional AI triage explains an incident but does not act, and every response records its result.
Go deeper: AI security, built on identity
Frequently asked questions
Does AIDR mean using AI to detect cyberattacks?
Not here. AIDR means detecting and responding to threats that involve AI apps and agents. A SOC tool that uses AI to sort ordinary alerts doesn't give you that.
Can AIDR stop every prompt injection?
No. Detection misses things, and some findings land after the action ran. Tight data access, tool permissions and outbound destinations limit the damage.
Does AIDR require storing every prompt?
No. Account, tool, resource and outcome records support most investigations. When content is needed, collect only what the case requires and protect it.
Who should own AI incident response?
The security incident team runs it with the workflow owner. Identity, endpoint, app and data owners often carry out the containment.
Is a wrong AI answer a security incident?
Not by itself. It becomes one when it exposes protected data, triggers an unauthorized action or otherwise puts company systems at risk.
