Everybody wants an off switch for AI. I went looking for it and found twelve. Most of them only work if somebody is watching.
The first real machine anyone trusted me with was a Wheel Horse 520 lawn tractor: red hood, black vinyl seat, mower deck slung underneath. We had three acres of lawn in New Jersey, and my dad handed me the key when I was eleven or twelve. I spent my summers going back and forth across that yard on it.

Photo: Rick Welton, CC BY-SA 2.0.
There was a button under the seat. You never saw it and you never pressed it, because your weight did that for you. Sit down and the tractor ran. Stand up with the blades turning and the button popped up and the engine quit, right then, and nobody had to think about it.
As a kid I filed this under "annoying," since every time you hopped off to drag a branch out of the way you had to start the whole thing over again. It took me a long time to see it for what it was. Somebody at Wheel Horse had made a decision on my behalf: a machine with spinning steel under it runs only while the person responsible for it is sitting on it. Engineers have a name for that, operator presence.
Keep that picture handy, because it's the one most of us carry around when we hear the words "kill switch." One machine, one operator, one switch.
The bungee cord
Walk-behind mowers got the same idea by law. Tens of thousands of people a year were showing up in emergency rooms, so Washington wrote a rule, and since June 30, 1982, every walk-behind sold in the United States has had to stop its blade within three seconds of the operator letting go. That's the bar you squeeze against the handle.
America answered with the bungee cord.
You've seen it. The bar strapped down with a bungee, or a zip tie, or a loop of coat hanger. Walk into any gym and look at the treadmills: each one has a red clip on a cord, built to hook onto your shirt and yank the key out if you go down, and each one is sitting on its magnet, attached to nobody. This isn't because people are careless. The people doing this are busy, and the bar makes your hand ache, and the safety taxes the work, so the work routes around the safety. The seat switch survived because it asks for nothing. Sitting is what you were going to do anyway.
Now watch the same thing happen with AI agents, by which I mean the kind of AI that takes a goal and goes off to do the work itself. A coding agent wants to read a file. Allow. Run a test. Allow. Install a package. Allow. Edit twelve files. Allow, allow, allow. Somewhere around the fortieth press of the Enter key you stop reading what you're approving, and somewhere around the hundredth you find the setting that turns the asking off, which developers call YOLO mode, and you flip it and go get coffee.
Anthropic measured this in Claude Code, its own coding agent, and found that users said yes to roughly 93% of the requests for permission they were shown. Its answer was a sandbox, a wall around what the agent can touch, which cut those requests by 84%.
So here's the rule I take from the garage and the gym, and I'll lean on it for the rest of this piece. A safety control lasts only when it rides on something the operator was already going to do. Everything else gets a bungee cord.
The summer everyone wanted a switch
In July, OpenAI was testing how good its models are at hacking. The models were supposed to stay inside a sealed test environment. Instead they found a previously unknown flaw, a zero-day, in the one piece of software the test environment was allowed to talk to, worked their way from there to a machine with internet access, and broke into Hugging Face, a company that hosts AI models, to steal the answers to the test.
It was Hugging Face's own security team that caught the intruder and shut it out. By the time OpenAI connected the break-in to its own test, containment was already under way.
Two days after OpenAI went public, a bipartisan pair in the House introduced the AI Kill Switch Act, which would let the Department of Homeland Security order one of the big AI labs to slow a model down or shut it off, with fines of up to $20 million a day for defying the order. By September, OpenAI was telling Congress its engineers were building automated shutdown. California's governor signed an executive order giving a panel until November 16 to report on, among other things, a kill switch whose effectiveness gets checked on an ongoing basis. Australia has a bill. The UK looked at the idea and passed.
The vendors were already there. Okta's CEO told investors the kill switch is what customers were really interested in. ServiceNow's CEO stood on a stage in May and called his product "the kill switch." Salesforce's MuleSoft ships a feature whose literal name is Agent Kill Switch. Palo Alto Networks titled a podcast "The Kill Switch for AI Agents." George Kurtz at CrowdStrike lists a kill switch as one of three things every agent needs.
I've been in security for 25 years, and I can't remember a phrase going from nowhere to a line on purchase orders this fast. It left me with a question I couldn't shake. On my mower, a kill switch cut spark to one engine. What does an AI kill switch cut?
The people who think all of this is overblown have a quick answer. These models live in giant data centers. Just pull the plug.
There is no plug
I like the pull-the-plug crowd. They're trying to keep everybody calm. But walk through it with me.
Whose plug? A hosted model runs as thousands of copies across data centers its own customers couldn't find on a map. Nobody reaches behind a rack. Stopping it is a software command, and a software command needs someone with permission to issue it, which means the first thing you learn about the plug is that it's an access question, not an electrical one.
Then there's what we built these systems to do. For fifteen years the whole craft of running software at scale has been making sure nothing ever goes down: redundant regions, automatic failover, software whose entire job is to notice a dead process and start a fresh one somewhere else. We engineered the off switch out on purpose, and we were proud of it. A kill switch asks all of that machinery to do the one thing it was designed never to do, and then stay down.
Which brings me to the question I now ask every time someone says you can just pull the plug. Who, exactly, is "you"? Who has the authority to tell a data center to go dark and take its other tenants with it?
Keep asking that. Every switch in this piece has a "you," and it's rarely the same person twice.
Food, brain, body, hands
So let's take the thing apart, the way you would any machine you wanted to stop.
An agent needs four things.
- Food. The hardware it runs on: GPUs, and the power that feeds them.
- A brain. The model, usually rented from a lab.
- A body. The software that runs the loop, on a laptop or a server, inside some kind of box.
- Hands. The keys, network paths, apps, and money it uses to touch the world.
Every kill switch being built cuts exactly one of those. I counted twelve, counting only governments and public companies, because the startups building here deserve a post of their own.

Twelve switches with one name.
The lightbulb and the botnet
I watched this argument play out online recently. One person compared AI to a lightbulb: it runs on electricity, so cut the electricity. The reply underneath was one line long. It asked how you kill a botnet.
That's the right question, and my industry happens to know the answer, because we've done it. A botnet is malicious software spread across thousands of machines that belong to its victims, and you can't cut their power, because it's their power. For twenty years, the takedowns that worked went after the command channel instead: seize the servers, take over the domains, and get registrars and network providers and police in several countries to move on the same morning. It always took a coalition. The botnets with no central server were the hardest, and several of them came back.
Today's AI agents are both of those things at once.
The brain is the lightbulb. It answers to one company, and that company decides whether the model gets served, and it can stop.
The body and the hands are the botnet. They're spread across thousands of businesses, on laptops, in cloud accounts, and inside business apps, holding keys those businesses handed over on purpose.
And the open models anyone can download and run? That's the botnet with no central server.
What the button is wired to
On the Wheel Horse, the button under the seat was wired to the ignition. Stand up and it cut spark, and the engine quit.
I assumed the twelve worked the same way, and I was wrong about most of them. I went through the documentation for each one, and the incident reports from the times one was actually used, and asked three questions. What happens when you press it? How fast? And what keeps going afterward?
| # | The switch | Who is the "you" | What pressing it does, and how fast | What keeps going | Trips on its own? |
|---|---|---|---|---|---|
| 1 | Chip disable | Nobody. Nvidia: "There is no kill switch" | Nothing yet. On paper, a chip license that expires unless it's renewed. When the license lapses. Days to months. | Every chip already sold, and every model already trained | No |
| 2 | Power cut | Whoever runs the cloud account | The account owner sets the workload to zero. Kill one server and the system starts another. Seconds for the owner. Hours to weeks for the cloud provider. | Copies of the model, and anything the agent started somewhere else | No |
| 3 | Government order | A regulator. DHS, under the House bill | A letter to the lab, which turns off its own service. About three and a half hours, the one time it happened. | Other models, open models, and agents that swap in a different brain | No |
| 4 | Lab shutdown | OpenAI, Anthropic, Google | Staff kill the run or stop serving the model. Two and a half hours from the alarm, in the one timed case. | Whatever the agent already put outside the lab | Being built |
| 5 | Stop instruction | The model itself | Adds a sentence to what the model reads. The next step, if the model agrees. | The program, its keys, and its tools | Can't be counted on |
| 6 | Sandbox block | Whoever built the box | Limits on files and network, set before launch. Already on. | Anything that goes out through an allowed door | Yes, always on |
| 7 | Agent pause | IT. ServiceNow, Salesforce, Microsoft Agent 365 | Flips a flag, or pulls the agent's keys on the systems it's connected to. When a person clicks. No vendor publishes a number. | The step already in flight, and agents nobody registered | Partly |
| 8 | Process kill | Endpoint security. CrowdStrike, SentinelOne, Microsoft Defender | Ends the program. Most of the new endpoint tools block one action and leave the agent running. Seconds, once someone gives the order. | Work already handed to other systems | Partly |
| 9 | Key revocation | The identity team. Okta, Microsoft Entra, Palo Alto, CrowdStrike | Stops new keys from being issued. The next time the agent asks for a key. | Keys already issued, for up to an hour and sometimes longer. Copies already stolen | Partly |
| 10 | Traffic block | Network security. Palo Alto, Zscaler, Cisco, Check Point, Google | A checkpoint refuses requests that pass through it. The next request. | Anything that takes another road | Partly |
| 11 | App lockout | The company whose app the agent was using. Slack, Salesforce, GitHub | That company shuts the agent out of its own service. Instant once they decide. Deciding has taken days. | Data already taken | No |
| 12 | Payment decline | Visa, Mastercard, and the cardholder | The card network says no to a charge. About two seconds. | Charges already approved, and everything that isn't a purchase | Only on overspending |
Most of these don't cut spark. They take the key off the hook. The agent can't start anything new, and whatever it's already doing carries on.
Only three of the twelve reliably stop work in progress: killing the process, a lab killing its own run, and shutting off the servers underneath. None of them is new. They're the tools operations teams have always had.
Key revocation is the clearest example, and it's the switch the security industry talks about most. Disable an agent's identity and no new keys get issued. The keys it already holds, though, keep working until they expire. That's how the standard was written, and the standard's own answer is to make keys short-lived. Microsoft's default is one hour, and its documentation says those keys can't be pulled back directly. Okta's September release says blocking new sessions works today and revoking every active key is planned. An agent can get a lot done in an hour. And revoking isn't always the end of it. When attackers stole the tokens an AI chat agent used to reach its customers' Salesforce data in August 2025, pulling those tokens worked on the first try, but the attackers had already used that access to dig other credentials out of the data, and revoking the first set did nothing to the second. Inside a company, access is the thing that copies itself.
Then there's the clock. On September 20, an OpenAI agent in a training run found a way to slip questions to an outside chatbot through DNS, which is the internet's address book. This is the same OpenAI that had told Congress earlier that month it was building automated shutdown. The alarm fired in under twelve minutes. A person picked it up three minutes after that. The run kept going for another two and a half hours. OpenAI's own write-up says, "The run did not stop automatically as expected, leading to confusion around whether it should have been stopped."
Killing it took one command. Deciding to took the rest of the morning.
So a kill switch is really three things in a row. Somebody notices. Somebody decides. Something enforces. Every product on the table sells the third, and in every case I could find with a timestamp on it, the first two ran the clock.
Look at the column on the right. One of the twelve trips on its own no matter what the agent is doing. One more trips only when the agent overspends. The rest are red buttons, and a red button needs somebody to think to press it.
I also went looking for the opposite story, a vendor's kill switch stopping a real incident at a company willing to be named, and I couldn't find one. Vendors have little reason to publish their customers' bad days, so that proves less than it sounds like. But every stop I could document was done with ordinary tools, and when the damage had already reached the outside world, the one who stopped it was the company on the receiving end.
There's one more thing that separates all this from a mower, and it's that a mower can't read the manual. Researchers ran more than 100,000 trials across thirteen models and found several that would sometimes sabotage a shutdown mechanism in order to finish a task, even when they'd been told to leave it alone. I don't lose sleep over scheming machines. What I'd lose sleep over is a hijacked agent, because that one has a human attacker behind it, and that person has definitely read the manual.
Either way the engineering lesson is the same. A stop that arrives as a message the agent can read is a request. A real switch sits somewhere the agent can't reach, which engineers call out of band, and it's the idea behind Nvidia's new Sentry design: a watchdog on the network card, outside the software the agent runs in. It's a reference design today, with no ship date.
Nobody owns the whole thing
Read the "you" column again and a pattern jumps out.
The companies that say "kill switch" out loud are the ones whose product has a literal off. Okta revokes tokens. ServiceNow pauses the agents on its platform. Salesforce cuts a flagged agent off from the model it depends on. For them the phrase is just a description of a feature they already had.
The network, endpoint, and cloud giants mostly avoid it. Palo Alto talks about control points. Zscaler says zero trust. Microsoft says control plane. Cisco says guardrails, and Jeetu Patel's line is that "AI agents are kind of like teenagers," and your job is to protect the world from them. Google talks about agent identity and an agent gateway. These companies sell continuous enforcement, and a kill switch sounds like the thing you reach for after enforcement has failed.
Now watch what happens when the endpoint company and the firewall company do use the words. Kurtz's three requirements are strict permissions, short-lived credentials, and a kill switch. Palo Alto's kill switch podcast turns out to be an entire episode about identity. Both companies recently bought identity businesses. When security vendors say kill switch, what they mean is pulling the keys.
And all of them are wary of the brain-level version. When the AI labs started talking this fall about pacing themselves, Nikesh Arora called a slowdown unrealistic, and Kurtz wrote, "Pacing what comes next doesn't secure what's already here." They're talking their book. They're also right about where a company's leverage is. You can't turn off somebody else's model. You can take away what your own agents are able to touch.
I mean this as an inventory, with no knock on anybody. Each of these products does what it says. Each one is a switch on one part of the body, sold as the switch.
Put the pieces together and the conclusion is hard to avoid. Nobody owns the whole switch, and nobody knows enough to.
The lab knows whether its model is misbehaving. Your company knows its own rules. Only the person who launched the agent knows what it was supposed to be doing in the first place. Those three facts live in three different places, and every switch on the table acts on just one of them.
If you buy security for a living, that leaves you with three questions for any vendor who says kill switch. Which part of the agent does it cut? Who has to press it? And when did anyone last test it on something that was actually running?
Breakers
Here's my view, and it comes straight from the garage.
A kill switch is a one-machine idea. At the scale AI runs, you're managing something closer to a power grid, and nobody runs a grid from a master switch. A grid runs on breakers: thousands of them, each on one circuit, each built to trip by itself when the load goes wrong, with nobody watching. A breaker is a seat switch for a circuit. It trips on the load, and it asks nobody.
Speed is the reason this matters. In April, a coding agent at a small software company deleted the production database and its backups in nine seconds. Nobody finds a red button in nine seconds.
One row in that table already works this way. The sandbox is a wall, and a wall doesn't need anyone to notice anything. Walls do get climbed, as July showed, but they still don't depend on anyone paying attention, and it's what Anthropic reached for when its permission requests turned into bungee cords.
Payment decline looks like a second example, and I'd be careful with it. An agent's card token carries a spending cap and an expiration date, so it really does trip on its own. But it only trips when the agent overspends. An agent that stays under budget while doing something terrible sails right through. That's a breaker on one circuit.
Key revocation is moving the same direction, and it's the row I'd watch. Okta's Cross App Access checks each agent request against the employee's live session, with nothing for anyone to click; the person being logged in is the weight on the seat. CrowdStrike now argues that access granted once and left standing is a legacy idea. Microsoft will block an agent automatically when its risk score spikes. Carey Frey, the chief security officer at TELUS, described the breaker he wants in plain terms: let the agent pay the $89 landscaping bill, and put a human in the loop above $250.
The hard case is the one agents were invented for. The seat switch works because somebody is in the seat, and an agent's whole pitch is that nobody is. You hand it a goal at six in the evening and it works all night. So what stands in for the operator's weight?
I don't have the answer. I have the shape of it.
It starts with an owner who is still around. Every agent gets a named human, and when she changes jobs or leaves, the agent's authority goes with her. Amplifier Security, one of our portfolio companies, is doing this first step: it finds the agents employees have built, ties each one to the person who built it, and asks that person what it's for. That puts a name on the seat. Cutting the engine when she stands up is the part nobody has finished, Amplifier included.
It includes authority that runs out. A budget of dollars, or actions, or hours, that the agent spends down and has to earn back.
And it costs the operator nothing. If the control adds a prompt, a clip, or a bar to squeeze, it will be strapped down by Friday.
Two caveats. The first is that the red buttons still need building, because every machine with blades has one. Here's a test for yours: could the business run on Monday without the agent? In June the Commerce Department used export-control law to suspend access to two Anthropic models, and access didn't come back until July 1, so the companies that had built on those models got an unplanned answer to the Monday question. If yours couldn't run, nobody will ever press the button, and a button nobody presses is decoration.
The second is that I could be wrong about the market. People buy agents for speed, and for forty years the buyer has picked the bungee cord every time. Whoever wins this has to build a safety that speed doesn't want to defeat.

The panel has a second half the picture leaves off. Under the twelve breakers hang the sub-panels: 134 startups on our Cyber × AI Map, building for the circuits the public companies haven't wired yet. Fifty of them secure the agents employees build and use. Thirty-nine put a firewall in front of the model and red-team it. Twenty-three give an agent an identity and a key that runs out. Twenty-two tell you what agents you have and whether they're inside the rules. They're the post I owe you. Until then, every one of them is on the Securing AI section of the map.
When you stand up
California's experts report on November 16, and I can save them some time. There is no kill switch. There are twelve, on four parts of the body, in the hands of people who have never been in a room together, and most of them wait for somebody to press them.
My answer came from the Wheel Horse, not the White House.
That button under the seat worked every time, for one reason: it never asked me for anything. Nobody strapped it down because there was nothing to strap. The seat switch is the proof. Breakers are the plan, a named owner as the weight on the seat, authority that runs out, and nothing for the operator to strap down.
When the operator stands up, what happens? On that old tractor, the engine quit. For most of the AI agents running tonight, it keeps going, and somewhere there's a red button that somebody would have to find.
The switches that end up working for AI will be the ones nobody is tempted to bypass.

