The ‘kill switch’ has become the default answer to agentic AI governance: an agent operates outside policy, someone hits the emergency stop. It’s intuitive. It’s also built on a mistaken premise — that your hardest problem is stopping an agent after you’ve already given it the privileges to act.

The real challenge isn’t how quickly an organization can stop an AI agent. It is ensuring that an agent is never able to operate outside of policy in the first place. If you’re relying on a ‘kill switch’ to stop an AI agent, you’ve already made a fundamental mistake. A properly governed agent is simply never handed the task, so there is nothing to kill.

Why the ‘kill switch’ model breaks down

I don’t blame organizations for being drawn to the AI ‘kill switch’. It’s intuitive –  mirroring a familiar safety concept. Yet, this idea fails to account for the reality of agentic systems. Three problems come to mind.

First, AI agents are non-deterministic and operate at machine speed. Once a task begins execution, the window for human intervention essentially disappears. An agent with privileges on a production database can delete or exfiltrate data before an alert ever fires.

PocketOS was a recent victim of this when an agent wiped out a company’s entire production database (and its backups) in just nine seconds. So the assumption that humans can simply intervene in real-time doesn’t hold.

Second, AI failures are often not caused by malicious behaviour. They are caused by excessive privileges. The issue isn’t necessarily that the agent acted maliciously; it is that the system allowed that action to happen. This means the ‘kill switch’ approach misdiagnoses the problem. It treats AI risk as a behavioral issue when the underlying challenge is a policy and privileges issue.

Third, most organizations still lack a clear identity model for AI agents. Companies are mostly able to track human users and system logins, but not which agent initiated an action, what identity it used or what privileges were active at the time.  A ‘kill switch’ assumes everything is identifiable and controllable. But without a unified identity control plane across humans, machines, workloads, and AI agents, revoking privileges or stopping an agent becomes near impossible.

Policy is paramount

The answer is not a faster shutdown mechanism. It is better policy enforcement.

The fundamental flaw in today’s security models is that privileges have historically been attached to identities or groups of identities. That approach worked when organizations had a manageable number of users, applications and service accounts.

In the agentic era, the number of machine identities tends to grow exponentially. Some organizations are already considering environments where employees are supported by dozens or even hundreds of AI agents. Trying to govern these environments by creating more identities, roles and privileges will result in identity fragmentation and credential sprawl.

Security can’t scale by continuously adding more identity-based policies, so the solution is to rethink how policy is embedded through architecture.

What policy looks like in practice

Instead of asking only “who are you?”, organizations need to ask “what action is being requested, and should it be allowed?” Every action an AI agent attempts should be bounded by a trusted runtime, considering the intent of the task, the resource being accessed, the context of the request and the policies governing that action.

The trusted runtime bounds what the agent can do. If a request exceeds those boundaries, the action does not execute. Full stop.

There’s a name for this. We call it Enforce Continuously — the first of three principles that extend zero trust into the agentic era. Zero trust told us to verify every actor explicitly; non-deterministic agents require that same verification to hold throughout every action, enforced by the runtime rather than requested of the model. You can’t ask a non-deterministic actor to comply. So you don’t ask.

A trusted runtime grounds both the agent AND its environment in a strong identity. Every AI agent is anchored to a hardware root of trust, providing cryptographic proof that an agent is what it claims to be, running in an approved environment, with identity that can’t be impersonated.

A unified identity layer further allows agents to interact with humans and machines together as first-class identities, with each identity being uniquely identifiable, cryptographically verifiable, bound to specific privileges and auditable at the action level. Without that foundation, organizations can’t consistently enforce policy because they can’t reliably determine who, or what, is taking action.

These two concepts are foundational to continuous enforcement.

The AI ‘kill switch’ is satisfying because it’s familiar. But architecturally weak if you are relying on it for policy enforcement: it assumes you’ll catch failure in time to act, and in agentic environments, you won’t. Identity isn’t a supporting control. It’s part of the infrastructure that makes agentic AI viable. Successful AI governance won’t be defined by faster shutdown mechanisms, but rather designs that build in trusted identities, trusted runtimes, and continuous enforcement.

Ev Kontsevoy

Ev Kontsevoy

Ev Kontsevoy is CEO at Teleport

Personalized Feed
Personalized Feed