
Every agent vendor says there is a kill switch. Ask what it stops. Usually the answer is "new runs". The run that is halfway through paying invoices keeps going. The batch queued behind it keeps going. The job scheduled for 2am starts on time. The agent still holds a live token to your ERP. That is not a kill switch. It is a sign on the door.
In one sentence: stop has to reach the action in flight, the queue, the schedule and the credentials, and resuming needs as much care as stopping.
Where it comes from
Industrial machines have emergency stops. The AI Act borrows the idea. People overseeing a high-risk system must be able "to intervene in the operation of the high-risk AI system or interrupt the system through a 'stop' button or a similar procedure"1. The Act adds a condition that is easy to skip. The procedure "allows the system to come to a halt in a safe state"1.
NIST's AI Risk Management Framework asks for the organisational side. Manage 2.4 asks that responsibilities are "assigned and understood, to supersede, disengage, or deactivate AI systems" that behave outside their intended use2. Mechanism and responsibility. A button nobody is allowed to press fails the second half.
Deployers of high-risk systems have a matching duty. If they have reason to think the system presents a risk, they inform the provider and the authority "and shall suspend the use of that system"4. You cannot suspend what you cannot stop.
What it actually is
Four targets. A real switch covers all of them.
1. The action in flight. The agent has sent "schedule payment" and is waiting for the ERP. Stopping the agent now does not recall the request. What you can control is the next action. The switch must stop the agent before it sends another. It must also record that the last one's outcome is unknown.
2. The queue. Agents often plan a batch: forty invoices, one after another. Stop has to empty or freeze the queue. Otherwise a stopped run leaves thirty-nine actions for the next worker to pick up.
3. The schedule. Many agents run on a timer. Kubernetes shows the trap. You can suspend a CronJob, but that "does not affect Jobs that the CronJob has already started"3. And the resume has its own warning: when suspend is lifted on a CronJob with no starting deadline, "the missed Jobs are scheduled immediately"3. Pause an agent for a week, resume it, and a week of runs may fire at once.
4. The credentials. An agent that is stopped but still holds a valid token can be restarted by anyone with access to it. For a serious incident, revoke the agent's credentials in the target systems. It is the only stop that holds even if the rest of the stack misbehaves.
Here is how the controls line up. It is illustrative.
| Control | Stops new runs | Stops in-flight step | Clears queue | Stops schedule | Survives a restart |
|---|---|---|---|---|---|
| Disable the agent in its UI | Yes | Often not | Often not | Varies | Varies |
| Pause at the control layer | Yes | Before its next action | Holds it | Yes | Yes, if stored |
| Revoke credentials | Yes | Next call fails | Next call fails | Yes | Yes |
Pause, stop and rollback are different
Pause freezes the work and keeps it. Use it when something looks wrong and you need an hour. The queue waits. Resume carries on.
Stop ends the work. Queued actions are cancelled and recorded as cancelled. Use it when the agent is doing something it should not.
Rollback undoes what happened. For money it usually does not exist. A payment that reached the bank cannot be un-sent by the agent. It can only be reversed by a person, through a recall or a credit. So plan reversal, not rollback. Know who in finance does it and how long it takes. Make sure the record tells them exactly which actions to reverse.
What it is good at, and what it is not
Good at. Limiting damage once you know something is wrong. Buying time for a person to look. Proving to an auditor that oversight is more than a policy line.
Not good at. Noticing. A switch only helps once someone decides to press it. That is a monitoring question: which signals tell you to stop, and who watches them. A spend cap is a switch that presses itself.
Where it goes wrong. The switch lives in the vendor's console and your team has no login. Or it sits with an engineer who is asleep. The AI Act says the oversight people must be able to use it1. Put it in their hands.
What to check
- /01
What exactly does your stop button stop? New runs, the in-flight step, the queue, the schedule?
- /02
Who can press it, and do they have access today?
- /03
After a stop, what does the record say about the last action? Done, failed, or unknown?
- /04
What happens on resume? Do missed scheduled runs all fire at once?
- /05
How fast can you revoke the agent's credentials in each target system?
- /06
Who reverses a payment the agent made, and from what list?
Run the drill before go-live. Start a real batch in test, press stop halfway, and time it. Then read the record.
Where it is going
Our view: pause and stop become first-class, audited actions, the way approvals already are. Regulators will ask who pressed stop, when and why, and what happened to the queue. Tools that treat stop as "disable the bot" will look thin next to ones that stop cleanly and say so in the record.
Gatehouse fit
Gatehouse checks each action before it runs and stops it if the rules say no, so the stop sits in the path rather than in the agent. Every action that did land is in the record, chained by SHA-256, which gives your finance team the exact list to reverse. A global pause across all runs is a question to ask us directly, with a drill on a simulated batch. See the Gatehouse page for where the check sits.
At a glance
| Category | Controls |
|---|---|
| Also called | Emergency stop, circuit breaker, suspend, disengage |
| Borrowed from | Industrial emergency stops. Job schedulers |
| Key standards or docs | AI Act Art. 14(4)(e) and 26(5). NIST AI RMF Manage 2.4 |
| Typical owner | The process owner presses it. IT revokes credentials. Finance reverses |
| The one test | Press stop halfway through a batch. What is still running a minute later? |
Sources
- [1]Regulation (EU) 2024/1689 (AI Act), Article 14: Human oversightartificialintelligenceact.eu In text
- [2]NIST AI 100-1, AI Risk Management Framework 1.0, January 2023 (PDF)nvlpubs.nist.gov In text
- [3]CronJob, Kubernetes documentationkubernetes.io In text
- [4]Regulation (EU) 2024/1689 (AI Act), Article 26: Obligations of deployers of high-risk AI systemsartificialintelligenceact.eu In text
Read next

What is an agent control plane?
An agent control plane checks every action an AI agent wants to take against your rules before it runs, holds the hard ones for a named person, and records the result.

How to set a spend limit on an AI agent
Set it in money, not tokens. Three levels, enforced inside the system. And how to get the number from the process you're replacing.
How to monitor AI agents in production
Uptime tells you it's running. Not that it's right. Four signals to watch: quality drift, hold rate, spend per run, latency.