AI Processing Guard
- Reference
- INC-2026-0036
- Status
- Remediating
- Severity
- High
- Nature
- unauthorised disclosure
- Detected
- 28 Jul 2026, 08:18
- Became aware
- 28 Jul 2026, 09:30
- Contained
- 28 Jul 2026, 12:30
- Lead
- Vikram Saxena
- Affected sources
- Grievance Case Management
- Data categories
- NameGrievance historyMobile number
No sanctioned drafting tool available; shadow AI not blocked at the gateway.
Response tasks — 6 of 16 complete
Grouped by phase. Mandatory tasks are the ones a regulator will ask you to evidence.
Rule 7(2) prescribes the content: the nature, extent and timing of the breach, its likely consequences, the mitigation measures taken, the remedial measures to prevent recurrence, and the status of notification to Data Principals.
Nature, extent and timing
Staff pasted grievance narratives into a consumer AI assistant to draft replies. The AI Processing Guard flagged classification hits in outbound prompts across 6 unsanctioned services.
Likely consequences
Assessed and communicated to affected Data Principals.
Mitigation measures taken
Containment completed; controls strengthened.
Remedial measures
No sanctioned drafting tool available; shadow AI not blocked at the gateway.
Data Principal notification status
Completed