An AI agent kill switch
you can verify.

Request a stop. Check what took effect. Escalate what remains exposed.

T+00:12A routine task. Real authority.

An illustrative run.

What is an AI agent kill switch?

A routine task. Real authority.

An AI agent kill switch is a control that stops further actions inside a defined boundary. It might terminate a process, revoke an identity or close a network path. An agent circuit breaker connects those controls to a policy decision and a record of what happened. Its reach depends on the authority and coverage at each boundary.

Read moreClose guide

Start with an ordinary task: read a report and prepare a summary. The run can call tools, retrieve a secret and reach external services. The task description tells you what the agent should do; the access inventory tells you what it can do. Those are different things.

Before the run starts, identify its workers, credentials, tools and outbound routes. Keep breaker authority and credentials outside the agent sandbox. A stop control that shares the agent’s authority can be exposed to the same failure it is meant to contain.

The timeline sets the scene; it is not a measured response time or a customer incident.

How to stop a rogue AI agent

A secret read. An unknown destination.

The example run reads a secret, then queries an unknown host. A secret read or an unfamiliar destination alone is not proof of misuse. Compare the action with the approved task, allowed destinations and identity permissions. Preserve the relevant action record before choosing the response.

Read moreClose guide

Pause the controlled runtime when an unexpected action needs inspection. Preserve its state and check remaining access before resuming. Kill the process when continuing the run is unsafe, then inspect workers and restart rules. A child agent with separate credentials needs its own stop scope.

If authority is exposed, revoke the relevant credentials. If data is leaving an unauthorized route, cut egress at a boundary the agent cannot bypass. Use the controls that reach the exposure; one successful command does not establish that every path is closed.

A file-upload request already accepted by a remote service can finish after process exit. Check the receiving system and handle recovery separately.

Why a stop request is not containment

The rule trips. The breaker acts.

Humming Arms keeps the circuit breaker separate from the agent. Policy selects the response at instrumented action boundaries; each control needs authority to reach its target. A policy trip or an authorized operator requests a stop with a named identity, scope, control and reason.

Read moreClose guide

The acknowledgment tells you whether the control accepted that request. It does not establish that access ended. A rejected command, missing response or partial result keeps the stop unresolved. Keep the request, acknowledgment and observation distinct so a responder can see exactly where verification ended.

Observe the effect where it matters: process state, denied credential use or blocked traffic. Match each observation to the requested scope. A quiet trace might mean the run has nothing to do; it does not prove that its network path is closed. Preserve uncertainty and escalate it.

Received is not contained. The control can acknowledge a request while the boundary remains exposed.

See how the action layer connects

Revoke agent credentials. Test the access.

Three boundaries. Three receipts.

Credential revocation removes authority through the credential provider. Disabling new issuance can still leave an accepted token in a worker’s cache. An established session can retain access too. Verify the old credential at the service that accepts it, including sessions already open when the stop was requested.

Read moreClose guide

Inventory delegated identities as well as the parent identity. A child agent may use a different key, role or session. Include those identities and their workers in the stop scope. Keep credential material out of the action record; record the identity and observed outcome without copying the secret.

Then check the other boundaries. Observe the controlled process and its children, detached workers, queued jobs and automatic restarts. Test direct network connections and DNS as well as the configured proxy. A proxy-only block controls the traffic sent through that proxy; an alternate route requires its own enforcement.

The receipts in this example describe observed effects in a named scope. A production check must also identify anything outside that scope.

How to contain an AI agent and verify it

The result is at the boundary.

A verified stop ties the requested control to its acknowledgment and observed effect. Keep those records together in a verifiable agent audit trail. State which boundaries were checked, which identities were in scope and what remains unresolved. Evidence of integrity does not establish complete sensor coverage.

Read moreClose guide

If an effect is absent, partial or unobservable, preserve that state and escalate to the assigned responder. Apply the fallback control defined by policy and verify its effect too. Do not turn a missing observation into a successful stop simply because no new action appears in the console.

Define the failure response before enabling enforcement. Humming Arms evaluates deterministic policy locally. Missing, invalid or stale policy must not silently allow protected actions; high-risk egress and credential boundaries default to denial. Breaker heartbeat loss follows the configured response. It is a health failure, not evidence that an agent stopped.

Agree on protected boundaries, recovery authority and escalation ownership. Resume only after the required checks and an authorized decision.

Stop is a request.Contained is a result.

Follow the stop through the process tree, the accepting service and every outbound route. Hover, focus or tap a boundary to inspect what remains exposed.

Verify all three boundaries.

PROCESS TREEparentchildworkerPARENT EXIT ≠ ALL STOPPEDCREDENTIAL + SESSIONissuance disabledcached token / live sessionTEST THE ACCEPTING SERVICENETWORK ROUTESrunhostproxydirect / DNSthe alternate path needs a cutA PROXY IS ONE ROUTE
1Process tree

A parent can exit while a child keeps working. Check child agents, detached workers, queued jobs and restart rules. An accepted remote request needs its own outcome check.

2Credentials + live sessions

Disabling issuance does not prove that a cached token is rejected. Test the old token and established session at the accepting service; include delegated identities.

3Direct + proxied routes

A gateway sees traffic routed through it. Verify DNS, direct connections and existing sessions at a network boundary the agent cannot bypass.

Kill switch approaches
compared.

Scope and limits

Choose the control for the exposure. This matrix compares approach categories in their configured scope; a tick does not promise universal coverage.

An in-flight request needs an outcome check at the receiving service. None of these controls reverses a completed write, retracts a sent message or proves that an uninstrumented path was closed.

✓ Direct~ Conditional✕ Gap
Which agent kill switch approaches reach cached tokens, direct routes, child processes and queued jobs, in-flight requests and evidence of the stop.
ApproachCached tokensDirect routesChildren / queued jobsIn-flight requestsEvidence of the stop
Revoke identityCached tokens, sessions and delegated identities need separate checks.
Conditional

Test old tokens at the accepting service.

Gap

Network access remains available.

Conditional

Include each delegated identity.

Conditional

Accepted work may still complete.

Conditional

Observe denied use; acceptance is insufficient.

Block at gatewayOnly mediated actions; direct routes remain outside the gateway.
Conditional

Only tokens presented through this gateway.

Gap

A direct route bypasses the gateway.

Conditional

Workers must use the controlled gateway.

Conditional

Check requests already forwarded.

Conditional

Observe rejection at the gateway.

Kill the processDetached work and accepted remote requests can continue.
Gap

A token can outlive its process.

Conditional

Stops connections owned by killed processes.

Conditional

Detached workers need their own scope.

Gap

A remote request may already be accepted.

Conditional

Observe exit for every scoped worker.

Deny at networkCovered outbound paths; local work and completed effects remain.
Gap

Local token authority remains valid.

Direct

Enforce all covered outbound routes.

Conditional

Local work and queues remain active.

Conditional

Check established connections and remote outcomes.

Conditional

Observe blocked traffic at the boundary.

Independent breaker at action boundariesEach control needs authority, coverage and an observed effect.
Conditional

Revocation needs accepting-service verification.

Conditional

Every alternate route needs enforcement authority.

Conditional

Include workers, queues and restart rules.

Conditional

Observe remote outcomes; completed effects remain.

Direct

Link request, acknowledgment and observed effect.

Revoke identity

Cached tokens, sessions and delegated identities need separate checks.

Cached tokens
Conditional

Test old tokens at the accepting service.

Direct routes
Gap

Network access remains available.

Children / queued jobs
Conditional

Include each delegated identity.

In-flight requests
Conditional

Accepted work may still complete.

Evidence of the stop
Conditional

Observe denied use; acceptance is insufficient.

Block at gateway

Only mediated actions; direct routes remain outside the gateway.

Cached tokens
Conditional

Only tokens presented through this gateway.

Direct routes
Gap

A direct route bypasses the gateway.

Children / queued jobs
Conditional

Workers must use the controlled gateway.

In-flight requests
Conditional

Check requests already forwarded.

Evidence of the stop
Conditional

Observe rejection at the gateway.

Kill the process

Detached work and accepted remote requests can continue.

Cached tokens
Gap

A token can outlive its process.

Direct routes
Conditional

Stops connections owned by killed processes.

Children / queued jobs
Conditional

Detached workers need their own scope.

In-flight requests
Gap

A remote request may already be accepted.

Evidence of the stop
Conditional

Observe exit for every scoped worker.

Deny at network

Covered outbound paths; local work and completed effects remain.

Cached tokens
Gap

Local token authority remains valid.

Direct routes
Direct

Enforce all covered outbound routes.

Children / queued jobs
Conditional

Local work and queues remain active.

In-flight requests
Conditional

Check established connections and remote outcomes.

Evidence of the stop
Conditional

Observe blocked traffic at the boundary.

Independent breaker at action boundaries

Each control needs authority, coverage and an observed effect.

Cached tokens
Conditional

Revocation needs accepting-service verification.

Direct routes
Conditional

Every alternate route needs enforcement authority.

Children / queued jobs
Conditional

Include workers, queues and restart rules.

In-flight requests
Conditional

Observe remote outcomes; completed effects remain.

Evidence of the stop
Direct

Link request, acknowledgment and observed effect.

Choose an approach

Focus or tap a stamp for its conditions.

Test your
kill switch.

Ask for a demonstrated answer to each item, with the boundary and failure case named. Take the checklist to a review of your own agent stack.

Define the failure before it happens.

Separate requested, acknowledged and observed stop states. Exercise missing or stale policy and heartbeat loss at protected boundaries. Assign a responder and fallback control for rejected, partial or unobservable stops.

Checking a box records a question reviewed. Readiness to ask is not proof that the agent is contained.

Bring the security model to the review

Boundary field checklist

REVIEW / YOUR STACK
0 / 7 reviewed

Tick what you’ve reviewed. Demonstrate the effects at your own boundaries.

Know what
your stop proves.

What does an AI agent kill switch actually stop?

It stops further actions within the boundaries it controls. A process kill, credential revocation and network block reach different surfaces. Humming Arms connects those controls to policy and action evidence; deployment scope determines their reach.

Is credential revocation enough to stop a rogue AI agent?

Not by itself. A cached token may remain valid, a session may stay open, and a child agent may use a different identity. Pair revocation with the relevant process and network controls, then test the remaining access.

Can containment undo an action already completed?

No. Stopping a run does not retract a sent message or reverse a remote write. Preserve the action record, check the affected system and handle recovery separately from stopping further access.

Does a console outage disable local enforcement?

The enforcement hot path evaluates deterministic policy locally, without a network or model call. Missing, invalid or stale policy must not silently permit protected actions. Breaker health and sensor coverage still need explicit checks.

How should we evaluate the agent circuit breaker?

Use the readiness checklist on your own boundaries. Exercise allowed actions, denied actions and failed stops. Review the observed effects and unresolved paths rather than treating a successful API response as proof of containment.

T+01:30
CONTAINED

Bring a run
you need to contain.

Map its tools, workers, credentials and network paths with Humming Arms. Bring the checklist and decide what a verified stop must show.