A kill switch for AI agents is the ability to stop agent activity on demand, without relying on the agent's cooperation: revoke one agent's credentials, pause a workflow, or freeze agent traffic across an organization. In practice it is a set of coordinated actions with different reach rather than one button, and it is only trustworthy if it has been rehearsed before it is needed.
What a kill switch has to cover
Agents act through several paths at once: model calls, MCP tool calls, calls to other agents and outbound requests. A stop that closes one path and leaves the others open is not a stop. Three properties separate a usable kill switch from a decorative one:
- Reach. It cuts the credentials and paths the agent actually uses, not only its user-interface session.
- Graduated scope. One misbehaving agent should not force a freeze of everything; a compromised shared tool might.
- Preview and evidence. Before stopping production systems you want to know which ones stop, and afterwards you need the record of what was running when you pulled it.
The kill switch is the main control against rogue agents, ASI10 in the OWASP Top 10 for Agentic Applications, and one of the core controls of agentic AI security. The threat model is set out in rogue AI agents and kill switches.
How it differs from human-in-the-loop approval
A human-in-the-loop approval stops one call before it runs and waits for a person. A kill switch stops agents that are already running, across many calls. Approval is a routine control for consequential actions; the kill switch is for incidents, and how much it should stop depends on the blast radius of what went wrong.
In Praesidia
Organization owners can freeze their organization's agent traffic in one step, after a preview lists every AI system that will stop. They choose what to stop, such as agent-to-agent calls, MCP tool calls, model access or outbound traffic; by default the evidence is preserved, and the freeze stays in place until an owner lifts it, which can be done item by item. A single agent can also be revoked, which ends its credentials without touching other agents. Both act on traffic that passes through Praesidia; an agent using credentials Praesidia never issued is outside their reach. Where containment fits in a response is described on AI incident response.
Common questions
Is a kill switch the same as turning off the model?
No. Revoking a model provider key stops model calls but can leave tool calls, agent-to-agent calls and scheduled work running. A kill switch has to cover the paths an agent acts through, not only the model it reasons with.
Should a kill switch stop every agent?
Only when the incident calls for it. Revoking one agent contains a single compromised identity; freezing the whole organization fits a compromised shared dependency, or an incident whose scope is not yet known.
How do you know a kill switch works?
Drill it like any break-glass procedure, on a schedule and after major changes to how agents are deployed, and check that the drill left a complete record of what was stopped and by whom.