Your AI agents can act on their own. Can you actually stop them?
- Rob James
- 4 hours ago
- 3 min read
There is a question I have started asking executive leaders that changes the temperature of the room every time: if one of your Artificial Intelligence (AI) agents started doing the wrong thing at nine o'clock tonight, who would stop it, how, and how long would it take? The pause that follows is usually the most honest answer in the meeting.

Setting the scene
The agents have arrived faster than the controls around them. In WitnessAI's July 2026 study of 300 enterprise decision makers, 70% said they are already using or piloting AI agents that can take autonomous actions. Only 18% said every one of those agents is inventoried and approved by their security team, and just 49% have continuous monitoring in place. Deloitte's 2026 State of AI in the Enterprise report, drawn from 3,235 leaders across 24 countries, finds only 21% have a mature governance model for agentic AI, even as 74% expect to be using agents at least moderately by 2027.
Here is why that gap matters. For thirty years, "AI governance" meant a document: a policy, a responsible use statement, a committee that met quarterly. That was adequate when software recommended and humans decided. Agents break the arrangement, because an agent does not recommend, it acts. It moves money, sends the message, updates the record. A policy has never once stopped a running process. In the agentic era, governance is no longer something you write, it is something you can do, in the moment, under pressure.
A pattern we have seen before
We do not have to imagine what happens when an automated system acts faster than anyone can stop it. On 1 August 2012, the trading firm Knight Capital pushed a faulty software update. The system began firing orders into the market on its own, ran for roughly 45 minutes before anyone could bring it under control, and lost about US$440 million, close to the entire value of the company. Knight had brilliant technologists and a serious risk function. What it lacked, on the morning that counted, was a fast, rehearsed way to hit stop.
Financial markets learned the lesson and built kill switches and circuit breakers into the core of trading. Regulators are now asking the same of AI: Article 14 of the European Union AI Act, the human oversight provision, requires high risk systems to be built so a person can monitor, intervene in, and halt them. The law is asking the question I put to leaders: can a human stop it.
The three questions that separate control from theatre
Consider Anna, a Chief Information Officer (CIO) at a mid sized insurer. Her teams have quietly put about forty agents into production: claims triage, customer correspondence, supplier onboarding. Nobody set out to build a shadow workforce, but that is what she now has. Here is the test I would give her.
First, are the kill criteria written down. The worst moment to decide when to stop an agent is while it is misbehaving. Real governance means the halt conditions are agreed in advance and specific: this error rate, this category of transaction, this anomaly, and the agent is paused, no debate required. If the answer to "when do we stop it" is "we would work that out at the time", that is improvisation with a good vocabulary.
Second, is the stop mechanism real and tested. A kill switch you have never pulled is a belief, not a control. Treat it like disaster recovery: schedule a drill, stop a production agent under controlled conditions, and time how long it takes and what breaks. Firms that do this discover uncomfortable things, such as an agent with credentials nobody can quickly revoke. Far better to learn that in a drill than tonight.
Third, does one named person hold the authority to stop. Technology is the easy part; authority is the gap. In the WitnessAI data, when leaders were asked who would be liable if an agent caused harm, 26% named the CIO and only 6% the Chief Information Security Officer. Accountability is already drifting to the technology leader. Name the owner, give them a genuine veto to pause or withdraw a deployment, and make sure the business knows they have it.
What lies ahead
None of this is an argument against agents. The value is real and the direction is set. The point is narrower: in 2026, the maturity of your AI programme is no longer measured by how many agents you have shipped, but by whether you could stop one, cleanly, tonight, and whether someone owns that call.
There is a simple tell. An organisation that genuinely governs its agents can name the last time it deliberately stopped one, in a drill or in anger, and what it learned. One that cannot has not been governing, it has been hoping. Hope is not a control, and business leaders are starting to ask for the difference.
.png)


Comments