TLDRocket
Sign in

AI changed how you respond to incidents. Your tabletops haven’t caught up.

The New Stack Andy Gombar ● Covered by 2 sources

AI is now part of incident response, so your tabletop drills need to test the bots too. If you only drill humans, you’re missing the new failure mode sitting in the middle.

Based on reporting by The New Stack, Andy Gombar — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Tabletop exercises were built for a simpler world: systems failed, people reacted, and the drill measured whether the right humans made the right calls fast enough. That logic breaks once AI starts doing real work in the response path.

Webflow says it spent a year putting AI into incident response tasks that used to be handled by people alone: triaging alerts, pulling the right playbook, suggesting responses, and drafting post-incident analysis and follow-up items. That doesn’t replace the security team, the company argues. It changes what needs to be tested. If the AI is now helping decide what responders see and do, then a tabletop that only checks human judgment is only checking half the process.

The failure modes are subtle, which is exactly the problem. An AI tool may not crash during an incident. It may simply summarize alerts badly, retrieve an outdated playbook because the keywords fit, or suggest something that sounds sensible and is quietly unsafe. Those errors are easy to miss in the moment and embarrassing to discover later. A calm demo won’t flush that out. Pressure might.

The article makes a sharp point for security teams, but it applies more broadly to support, SRE, and IT as well. Anywhere AI sits between a team and the action it takes, the exercise has to include what happens when that AI is wrong, unavailable, or too trusted. The human muscle memory can also atrophy. If a team has leaned on AI for months, many people may not remember how to do the job manually under stress.

The fix isn’t to tear up the existing tabletop program. It’s to add the AI layer into the scenario. Include the people building and maintaining the tooling. Debrief not just whether the runbook was followed, but whether the team trusted the system the right amount. And don’t treat one tabletop as a permanent answer; the models, retrieval sources, and guardrails keep changing anyway.

My take — AI-written commentary, not fact-checked reporting

The basic mistake here is treating AI like a helpful bystander instead of a new dependency with its own failure modes. That’s classic enterprise behavior: automate the risky part, then act surprised when the drill still assumes a human is doing the hard bit. If the AI can nudge the response, it can also nudge the team straight into trouble, which is why the tabletop needs to stop worshipping the runbook and start testing the plumbing.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.