ComputerWeekly

The AI kill switch – what actually happens when you press it?


Switch on the TV, or scroll through the news and you won’t have to look far before you find an AI headline.

Some of the stories are inspiring, others are concerning, but what is clear is that a topic that was once the reserve of the technical elite is now a global challenge. The debate around how to use AI safely has so far centred on two fundamental principles – regulate AI and control it.

Approaches to regulating AI vary, from comprehensive European Union (EU) legislation to sector specific regulation, existing legal duties and voluntary standards such as the National Institute of Standards and Technology’s (NIST’s) AI Risk Management Framework. But the direction is clear; organisations must be able to oversee, constrain and, where necessary, stop higher-risk AI systems safely.

Recent research from OneTrust found that 87% of senior business leaders encourage AI agent use, while only 17% say governance is embedded by design. The gap between adoption and control is becoming increasingly significant.

When it comes to controlling AI, there seems to be more of a consensus; we must do more and do it quickly. More organisations are talking about a so-called AI kill switch, a reassuring idea that if an AI system behaves unexpectedly, someone can simply press a button and stop it. But in an agentic world, the switch may be the easy part. The real challenge is the wiring behind it.

The reality is that there may be no single system to stop. An AI agent often operates through a model hosted by one provider, an identity managed by another platform, tools connected through APIs, and workflows distributed across several internal and external services.

For an agentic AI system, emergency shutdown is not simply a matter of stopping the model from generating another answer. It means containing the entire chain through which the agent can act: its runtime, identity, credentials, tools, network access, queued work and delegated authority. Control must start long before anyone reaches for a kill switch.

Organisations need clear governance, decision-making and accountability around what an agent is authorised to do in the first place, and where the boundaries sit.

The risk becomes more immediate when AI moves from generating content or recommendations to taking action. Once an agent can transact, communicate, change records or operate systems, controlling what it is authorised to do becomes as important as controlling its outputs.

What would pressing the kill switch actually mean?

Having the ability to intervene when needed is an important part of giving organisations the confidence to adopt AI at pace. That confidence, though, will depend on knowing how to correctly wire the kill switch. This includes disabling an agent’s workload or identity, to isolating its network and communications access, and restricting its ability to interact with other tools through application programming interfaces (APIs).

You then need to think about how you verify that your actions have been successful and that containment has actually occurred, as well as stopping any queued or scheduled tasks that might be in-flight. It’s important to think about the cleanup and recovery too; an agent that is stopped halfway through a task might leave incomplete transactions, open tickets, partial record changes or inconsistent data.

Each of these actions is technically possible, but the challenge is that many of the underlying capabilities needed to enable these actions need to be re-designed for an agentic world.

Take identity and access management (IAM). IAM has traditionally concentrated on employees and relatively stable machine identities. Agentic AI introduces a more dynamic challenge; identities that can be created at scale, inherit or delegate authority, use multiple tools, and initiate work across organisational boundaries. Organisations, therefore, need to reconsider how they manage access and maintain control as the use of AI agents grows.

And this all assumes we know where agents are deployed and what they’re capable of doing. Whose responsibility that is and the ability of existing governance arrangements to keep pace is another point of debate. Some feel it’s the responsibility of technical teams and the CTO, whilst many feel this is a matter for risk teams and the CRO. There’s no clear answer yet, but a level of independence is needed from those benefiting from the use of AI to make sure there are appropriate checks and balances around safety and security.

As AI becomes more autonomous, we need to ensure safety and control keep pace with adoption. It’s time for boards and technology leaders to put these principles at the centre of their AI strategy as they prepare for an agentic world.

Practical actions that senior leaders can take include maintaining a live agent inventory and ‘mapping’ to systems it works with, improving agentic IAM control and rehearsing the shutdown, recovery and cleanup operation.

Designing an AI kill switch could be a practical solution that helps firms safely deploy AI and focus investment on responsible AI that delivers the greatest value. The challenge is not, should we create a switch, it’s how ready is the wiring?

Adam Stringer is a digital trust and security specialist at PA Consulting



Source link