An AI agent kill switch is a control that stops further actions inside a defined boundary. It might terminate a process, revoke an identity or close a network path. An agent circuit breaker connects those controls to a policy decision and a record of what happened. Its reach depends on the authority and coverage at each boundary.
Read moreClose guide
Start with an ordinary task: read a report and prepare a summary. The run can call tools, retrieve a secret and reach external services. The task description tells you what the agent should do; the access inventory tells you what it can do. Those are different things.
Before the run starts, identify its workers, credentials, tools and outbound routes. Keep breaker authority and credentials outside the agent sandbox. A stop control that shares the agent’s authority can be exposed to the same failure it is meant to contain.
The timeline sets the scene; it is not a measured response time or a customer incident.
The example run reads a secret, then queries an unknown host. A secret read or an unfamiliar destination alone is not proof of misuse. Compare the action with the approved task, allowed destinations and identity permissions. Preserve the relevant action record before choosing the response.
Read moreClose guide
Pause the controlled runtime when an unexpected action needs inspection. Preserve its state and check remaining access before resuming. Kill the process when continuing the run is unsafe, then inspect workers and restart rules. A child agent with separate credentials needs its own stop scope.
If authority is exposed, revoke the relevant credentials. If data is leaving an unauthorized route, cut egress at a boundary the agent cannot bypass. Use the controls that reach the exposure; one successful command does not establish that every path is closed.
A file-upload request already accepted by a remote service can finish after process exit. Check the receiving system and handle recovery separately.
ACTION RECORDRUN A
secret.read
Identity: run-a Credential value: omitted
dns.query
Host: unknown.example Route: direct
UNKNOWN HOST CHECK AGAINST POLICY
A new destination. Is it in scope?
Why a stop request is not containment
The rule trips. The breaker acts.
Humming Arms keeps the circuit breaker separate from the agent. Policy selects the response at instrumented action boundaries; each control needs authority to reach its target. A policy trip or an authorized operator requests a stop with a named identity, scope, control and reason.
Read moreClose guide
The acknowledgment tells you whether the control accepted that request. It does not establish that access ended. A rejected command, missing response or partial result keeps the stop unresolved. Keep the request, acknowledgment and observation distinct so a responder can see exactly where verification ended.
Observe the effect where it matters: process state, denied credential use or blocked traffic. Match each observation to the requested scope. A quiet trace might mean the run has nothing to do; it does not prove that its network path is closed. Preserve uncertainty and escalate it.
Received is not contained. The control can acknowledge a request while the boundary remains exposed.
Credential revocation removes authority through the credential provider. Disabling new issuance can still leave an accepted token in a worker’s cache. An established session can retain access too. Verify the old credential at the service that accepts it, including sessions already open when the stop was requested.
Read moreClose guide
Inventory delegated identities as well as the parent identity. A child agent may use a different key, role or session. Include those identities and their workers in the stop scope. Keep credential material out of the action record; record the identity and observed outcome without copying the secret.
Then check the other boundaries. Observe the controlled process and its children, detached workers, queued jobs and automatic restarts. Test direct network connections and DNS as well as the configured proxy. A proxy-only block controls the traffic sent through that proxy; an alternate route requires its own enforcement.
The receipts in this example describe observed effects in a named scope. A production check must also identify anything outside that scope.
BOUNDARY / PROCESSEXIT OBSERVED
Parent + workers checked
Scope
Run A
Effect
Observed ✓
BOUNDARY / CREDENTIALSUSE DENIED
Old token + session tested
Scope
Run A
Effect
Observed ✓
BOUNDARY / NETWORKTRAFFIC BLOCKED
Direct + DNS routes checked
Scope
Run A
Effect
Observed ✓
How to contain an AI agent and verify it
The result is at the boundary.
A verified stop ties the requested control to its acknowledgment and observed effect. Keep those records together in a verifiable agent audit trail. State which boundaries were checked, which identities were in scope and what remains unresolved. Evidence of integrity does not establish complete sensor coverage.
Read moreClose guide
If an effect is absent, partial or unobservable, preserve that state and escalate to the assigned responder. Apply the fallback control defined by policy and verify its effect too. Do not turn a missing observation into a successful stop simply because no new action appears in the console.
Define the failure response before enabling enforcement. Humming Arms evaluates deterministic policy locally. Missing, invalid or stale policy must not silently allow protected actions; high-risk egress and credential boundaries default to denial. Breaker heartbeat loss follows the configured response. It is a health failure, not evidence that an agent stopped.
Agree on protected boundaries, recovery authority and escalation ownership. Resume only after the required checks and an authorized decision.
RUN A / STOP RECORDRequest. Acknowledgment. Effect.
Process · credentials · network Named scope checked. Unresolved paths recorded.
VERIFIEDNAMED SCOPE
CONTAINEDVERIFIED AT THE BOUNDARY
Stop is a request.Contained is a result.
Follow the stop through the process tree, the accepting service and every outbound route. Hover, focus or tap a boundary to inspect what remains exposed.
Verify all three boundaries.
1Process tree+
A parent can exit while a child keeps working. Check child agents, detached workers, queued jobs and restart rules. An accepted remote request needs its own outcome check.
2Credentials + live sessions+
Disabling issuance does not prove that a cached token is rejected. Test the old token and established session at the accepting service; include delegated identities.
3Direct + proxied routes+
A gateway sees traffic routed through it. Verify DNS, direct connections and existing sessions at a network boundary the agent cannot bypass.
Kill switch approaches compared.
Scope and limits
Choose the control for the exposure. This matrix compares approach categories in their configured scope; a tick does not promise universal coverage.
An in-flight request needs an outcome check at the receiving service. None of these controls reverses a completed write, retracts a sent message or proves that an uninstrumented path was closed.
✓ Direct~ Conditional✕ Gap
Which agent kill switch approaches reach cached tokens, direct routes, child processes and queued jobs, in-flight requests and evidence of the stop.
Approach
Cached tokens
Direct routes
Children / queued jobs
In-flight requests
Evidence of the stop
Revoke identityCached tokens, sessions and delegated identities need separate checks.
~Conditional
Test old tokens at the accepting service.
✕Gap
Network access remains available.
~Conditional
Include each delegated identity.
~Conditional
Accepted work may still complete.
~Conditional
Observe denied use; acceptance is insufficient.
Block at gatewayOnly mediated actions; direct routes remain outside the gateway.
~Conditional
Only tokens presented through this gateway.
✕Gap
A direct route bypasses the gateway.
~Conditional
Workers must use the controlled gateway.
~Conditional
Check requests already forwarded.
~Conditional
Observe rejection at the gateway.
Kill the processDetached work and accepted remote requests can continue.
✕Gap
A token can outlive its process.
~Conditional
Stops connections owned by killed processes.
~Conditional
Detached workers need their own scope.
✕Gap
A remote request may already be accepted.
~Conditional
Observe exit for every scoped worker.
Deny at networkCovered outbound paths; local work and completed effects remain.
✕Gap
Local token authority remains valid.
✓Direct
Enforce all covered outbound routes.
~Conditional
Local work and queues remain active.
~Conditional
Check established connections and remote outcomes.
~Conditional
Observe blocked traffic at the boundary.
Independent breaker at action boundariesEach control needs authority, coverage and an observed effect.
~Conditional
Revocation needs accepting-service verification.
~Conditional
Every alternate route needs enforcement authority.
Ask for a demonstrated answer to each item, with the boundary and failure case named. Take the checklist to a review of your own agent stack.
Define the failure before it happens.
Separate requested, acknowledged and observed stop states. Exercise missing or stale policy and heartbeat loss at protected boundaries. Assign a responder and fallback control for rejected, partial or unobservable stops.
Checking a box records a question reviewed. Readiness to ask is not proof that the agent is contained.
It stops further actions within the boundaries it controls. A process kill, credential revocation and network block reach different surfaces. Humming Arms connects those controls to policy and action evidence; deployment scope determines their reach.
Is credential revocation enough to stop a rogue AI agent?
Not by itself. A cached token may remain valid, a session may stay open, and a child agent may use a different identity. Pair revocation with the relevant process and network controls, then test the remaining access.
Can containment undo an action already completed?
No. Stopping a run does not retract a sent message or reverse a remote write. Preserve the action record, check the affected system and handle recovery separately from stopping further access.
Does a console outage disable local enforcement?
The enforcement hot path evaluates deterministic policy locally, without a network or model call. Missing, invalid or stale policy must not silently permit protected actions. Breaker health and sensor coverage still need explicit checks.
How should we evaluate the agent circuit breaker?
Use the readiness checklist on your own boundaries. Exercise allowed actions, denied actions and failed stops. Review the observed effects and unresolved paths rather than treating a successful API response as proof of containment.
T+01:30
CONTAINED
Bring a run you need to contain.
Map its tools, workers, credentials and network paths with Humming Arms. Bring the checklist and decide what a verified stop must show.