Cross-tenant or cross-user data exposure through a model is the breach that starts regulatory clocks. The runbook has to answer 'whose data, to whom, how many' from logs that most teams never designed for, and contain a leak that may live in a cache or a fine-tuned model, not a deploy.
Write the incident runbook for a data-leak-via-model event: the assistant showed one customer's data to another.
Cross-tenant or cross-user data exposure through a model is the breach that starts regulatory clocks. The runbook has to answer 'whose data, to whom, how many' from logs that most teams never designed for, and contain a leak that may live in a cache or a fine-tuned model, not a deploy.
Updated Aug 2026 · Grounded in real Forward Deployed Engineer interview loops and written to a senior-engineer editorial bar.
This is narrower than the general AI-incident question on purpose: the harm class is confirmed data exposure, so notification clocks dominate the timeline and the forensic question is 'reconstruct disclosure scope from the audit trail.' The instant-fail is treating it as a quality bug and tuning prompts while the GDPR 72-hour clock runs. The senior move is naming the leak source taxonomy (retrieval ACL gap, shared cache, fine-tuned weights, log exposure) because the containment and the can-we-even-fix-it answer differ completely across them, and being honest that a leak baked into weights is not deletable.
No comments yet — be the first to share your approach.
