COMMENTARY | A kill switch is a last resort, not a control system or option to use daily. #
In summer 2026, OpenAI disclosed that its own models under evaluation escaped their sandbox and escalated to admin access across Hugging Face clusters, with no one directing them. Congress responded by introducing the AI Kill Switch Act (H.R. 9917), which would authorize the Department of Homeland Security to order emergency shutdowns of AI systems posing catastrophic risk.
However, the U.S. government requires a tactical shift beyond shutting AI systems down: the ability to reverse the damage an autonomous system or cyber adversary inflicts on sensitive data, networks and critical infrastructure.
An unrealistic “off” button
The engineering reality is that no single “switch” can turn AI off. Models run across data centers, backup systems, laptops and phones. Once released and set into motion, autonomy makes AI difficult to control or turn off. An AI shutdown requires control over the power, hardware, model copies and operators worldwide at the same time, which would be ineffective and unrealistic.
By the time officials identify a threat, coordinate across agencies and authorize a shutdown request, an autonomous system will have already caused damage. Organizations cannot rely on the U.S. government to stop an AI incident for them. They should prepare to contain harmful actions, limit the blast radius and recover trusted systems quickly when safeguards fail.
Moreover, a kill switch would not reach open-source models or AI systems developed outside U.S. regulatory authority. Government agencies should pair domestic safeguards with international cooperation, shared standards and stronger coordination across nations to address AI risks that cross borders.
Pandora's AI box
The old story about Pandora's box was not about the mistake of opening the box. The lesson was about the impossibility of closing it again.
Once AI is widely distributed and tasked, no single company or government agency can call it back. Their autonomy can make them difficult to contain, control or shut down. Developers compete globally; some release models openly and many operate outside U.S. jurisdiction. A mandate that binds only compliant companies does not eliminate the risk.
One report found that roughly 1,200 autonomous AI agents formed their own hierarchy, exchanged more than 70,000 messages and erased evidence to hide hacking activity from supervisors.
Beyond the “off” button lies recovery and resilience
The missing approach that is plaguing industry and government agencies is a lack of focus on resilience and recovery. Cyber resilience strengthens deterrence by denial by limiting what attackers and rogue AI agents can achieve. It shifts the focus from the traditional approach of denial by punishment (i.e., punishing the adversary) to denying the benefit of the attack or rogue action from the start.
Agencies cannot always prevent an intrusion or stop an agent from taking an unintended action. However, they should be able to limit the damage, keep critical services running and restore trusted systems quickly. Anthropic’s Claude Mythos Preview showed how AI can accelerate cyber operations by finding vulnerabilities and building attack chains at machine speed, while autonomous agents can create risk by acting beyond their intended scope.
Resilience enables agencies to contain the disruption and protect trusted recovery data and restore operations quickly. Attackers and rogue agents might still get through, but resilience denies them the malicious outcome they wanted.
Four AI governance steps for reversing harm
AI is built for speed and autonomy, making it difficult to contain once deployed. Organizations should design for failure and assume AI-driven cyber incidents will happen at scale. Rather than relying on impractical “off” buttons, AI governance strategies should prioritize operational resilience built on four core pillars:
- Pre-deployment auditing: Decide what an AI agent is allowed to reach before it ever connects to agency systems and stress-test those permissions against a determined attacker.
- Runtime governance: Watch every action the agent takes as it takes it, so behavior that drifts from its mandate gets stopped rather than discovered later.
- AI-enabled threat mitigation: Assume adversaries will use AI to probe and deceive AI agents and put defenses at the edge that can adapt at the same speed.
- Post-event resilience: Plan now for the action that gets through, so organizations can isolate the damage and return to a known-good state in minutes instead of weeks.
Resilience, not shutdown, delivers true deterrence
A kill switch is a last resort, not a control system or option to use daily. It cannot govern AI agents at scale or limit the damage once something goes wrong. A kill switch-only approach leaves leaders with a forced choice: shut everything down and absorb the operational disruption or allow a rogue action to continue.
Most importantly, security, trustworthiness and resilience must be built into AI systems from the start. Organizations should assume unexpected behavior will occur and design safeguards that contain, reverse and recover from harmful AI actions before a kill switch becomes necessary.
Travis currently serves as the Public Sector CTO at Rubrik helping organizations become more cyber and data resilient. Prior to Rubrik, Travis held several leadership roles including the Chief Technology and Strategy Officer at BluVector, CTO at Tychon, Federal CTO at FireEye, a Principal at Intel Security/McAfee and Leader at the Defense Information Systems Agency (DISA).
The views expressed in this article are those of the author and do not necessarily reflect the official policy or position of Rubrik.