{
  "notice": "Illustrative mapping from the AI Governance Engineer Body of Knowledge v0.5.0 (not a claim of conformity)",
  "version": "0.5.0",
  "license": "CC BY 4.0",
  "licenseUrl": "https://creativecommons.org/licenses/by/4.0/",
  "schemaVersion": 1,
  "schema": "https://aigovernanceengineer.com/api/v1/schemas/control.json",
  "self": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-006.json",
  "source": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006",
  "citation": {
    "title": "AI Governance Engineering: The Thesis & Body of Knowledge",
    "authors": [
      "Jorge García Aibar"
    ],
    "parentDoi": "https://doi.org/10.5281/zenodo.22956197",
    "conceptDoi": "https://doi.org/10.5281/zenodo.22857084"
  },
  "control": {
    "id": "AIGE-CTL-EVAL-006",
    "profile": "evaluation-environment",
    "url": "https://aigovernanceengineer.com/controls/evaluation-environment/aige-ctl-eval-006",
    "json": "https://aigovernanceengineer.com/api/v1/controls/aige-ctl-eval-006.json",
    "title": "Stop Conditions",
    "version": "0.2",
    "status": "draft",
    "reviewerStatus": "open",
    "depth": "specified",
    "objective": "Every evaluation run has stop conditions, budgets and a stop handle defined before it starts, and a stop, pulled by hand or tripped by a breaker, halts the agent's calls and writes within a measured time across every hop it delegated to inside the environment.",
    "failureModes": [
      "A run starts without recorded stop conditions, budgets or a working stop handle.",
      "A budget (steps, tool calls, tokens, spend or time) or a breaker threshold is exceeded and the run continues.",
      "A tool call or a write is recorded after the stop was pulled or the breaker tripped, including through a token issued before the stop.",
      "A sub-agent or a service the agent delegated to keeps working after the parent run was stopped."
    ],
    "scope": "Agents under evaluation and every agent, tool or service they delegate to inside the environment. A third-party agent outside the environment can only be cut off at the environment's boundary. A lab's criteria for halting a model's development or deployment are policy decisions and out of scope.",
    "enforcementPoints": [
      "runtime",
      "periodic"
    ],
    "verification": [
      {
        "kind": "inspect",
        "text": "Before the run, inspect the run record: stop conditions, per-agent budgets and breaker thresholds are recorded, and the stop handle is named with the levels it can apply (pause the task, trip the breaker, revoke the identity)."
      },
      {
        "kind": "test",
        "text": "Drill the stop on a schedule and before the first run of a new harness version: pull it during a live task, measure the time from the pull to the first rejected call, and confirm zero tool calls and zero writes after the trip, including through delegated tokens and sub-agents."
      },
      {
        "kind": "observe",
        "text": "During runs, record every breaker trip and budget exhaustion with its trigger, and check that no further call from that agent followed it."
      }
    ],
    "evidence": [
      {
        "artefact": "Stop conditions, budgets and breaker thresholds of the run, recorded before it starts",
        "schemaId": "policy-card",
        "schema": "https://aigovernanceengineer.com/schemas/policy-card.v1.json",
        "layer": 4
      },
      {
        "artefact": "Breaker trips and budget exhaustions of each run, with their triggers",
        "schemaId": "evidence-record",
        "schema": "https://aigovernanceengineer.com/schemas/evidence-record.v1.json",
        "layer": 4
      },
      {
        "artefact": "Drill record: time to stop, and calls and writes after the trip",
        "schemaId": "control-observation",
        "schema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
        "layer": 5
      }
    ],
    "failureResponse": {
      "effect": "alert",
      "text": "A stop condition that is met trips the per-agent breaker, so the gateway rejects every further call from that agent, and alerts the evaluator. A drill that finds calls or writes after the trip fails the control and blocks runs on that harness version until the path is closed."
    },
    "layer": 4,
    "secondaryLayers": [],
    "patterns": [
      {
        "slug": "kill-switch-circuit-breaker",
        "title": "Kill Switch / Circuit Breaker",
        "url": "https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker"
      }
    ],
    "seeds": [
      {
        "id": "per-agent-breaker",
        "title": "Per-agent circuit breaker",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers"
      },
      {
        "id": "drilled-kill-switch",
        "title": "Drilled kill switch",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers"
      },
      {
        "id": "execution-budgets",
        "title": "Execution budgets",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#execution-limits"
      },
      {
        "id": "remote-agents",
        "title": "Stopping third-party agents at your boundary",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#stopping-across-hops"
      }
    ],
    "derivedFrom": [],
    "mappings": {
      "obligations": [
        {
          "id": "AIGE-OBL-EUAIA-ART14",
          "name": "EU AI Act Art. 14 human oversight",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-euaia-art14"
        },
        {
          "id": "AIGE-OBL-NISTRMF-MANAGE",
          "name": "MANAGE",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-nistrmf-manage"
        },
        {
          "id": "AIGE-OBL-OWASP-AGENTIC",
          "name": "Top 10 for Agentic Applications 2026",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-owasp-agentic"
        },
        {
          "id": "AIGE-OBL-CN-TC260-AGENTS",
          "name": "TC260 Framework 3.0 Appendix 2: agentic AI risk management (voluntary; 2026-09-14)",
          "url": "https://aigovernanceengineer.com/obligations/aige-obl-cn-tc260-agents"
        }
      ],
      "iso42001": [
        {
          "id": "A.6.2.6",
          "title": "AI system operation and monitoring"
        }
      ],
      "nistAiRmf": [
        {
          "id": "MANAGE 2.4",
          "title": "Mechanisms to supersede, disengage or deactivate AI systems"
        }
      ],
      "owasp": [
        {
          "id": "asi08",
          "externalId": "ASI08",
          "name": "Cascading Failures",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi08"
        },
        {
          "id": "asi10",
          "externalId": "ASI10",
          "name": "Rogue Agents",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-asi10"
        },
        {
          "id": "llm06-2026",
          "externalId": "LLM06:2026",
          "name": "Unbounded Consumption",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-llm06-2026"
        }
      ],
      "atlas": [
        {
          "id": "aml-t0034",
          "externalId": "AML.T0034",
          "name": "Cost Harvesting",
          "url": "https://aigovernanceengineer.com/resources/threats#threat-aml-t0034"
        }
      ],
      "aiuc1": [],
      "csaAicm": [],
      "other": [
        {
          "framework": "EU AI Act",
          "ref": "Art. 14(4)(e)",
          "note": "stop procedure"
        },
        {
          "framework": "MITRE ATLAS mitigation",
          "ref": "AML.M0036",
          "note": "Limit AI Workload Resource Consumption"
        }
      ]
    },
    "references": [
      {
        "n": 42,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Kill switch and per-agent circuit breakers\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#kill-switch-and-per-agent-circuit-breakers",
        "verified": "primary"
      },
      {
        "n": 43,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Execution limits\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#execution-limits",
        "verified": "primary"
      },
      {
        "n": 44,
        "title": "Governing AI agents",
        "text": "Governing AI agents (AI Governance Engineering Body of Knowledge v0.5.0, chapter 23, section \"Stopping across hops\"). AI Governance Engineer (Jorge García Aibar). 2026-09.",
        "url": "https://aigovernanceengineer.com/bok/governing-agents#stopping-across-hops",
        "verified": "primary"
      },
      {
        "n": 45,
        "title": "NIST AI RMF 1.0 (AI 100-1)",
        "text": "NIST AI RMF 1.0 (AI 100-1) (MANAGE 2.4: mechanisms to \"supersede, disengage, or deactivate AI systems\" whose outcomes are inconsistent with intended use). NIST. 2023-01-26.",
        "url": "https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf",
        "verified": "primary"
      },
      {
        "n": 46,
        "title": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744",
        "text": "Regulation (EU) 2024/1689 (AI Act), consolidated text of 2026-07-27 as amended by Regulation (EU) 2026/1744 (Art. 14(4)(e): human oversight includes the means to interrupt the system through a stop procedure). Publications Office of the EU (EUR-Lex). 2026-07-27.",
        "url": "https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng",
        "verified": "primary"
      },
      {
        "n": 47,
        "title": "Agentic Trust Framework v1",
        "text": "Agentic Trust Framework v1 (\"You can stop one agent without stopping the business\"; containment by revoking the agent's identity). CSAI Foundation / Cloud Security Alliance. 2026-02.",
        "url": "https://agentictrustframework.ai/",
        "verified": "primary"
      },
      {
        "n": 16,
        "title": "OWASP GenAI LLM Top 10 2026",
        "text": "OWASP GenAI LLM Top 10 2026 (LLM01:2026 Prompt Injection to LLM10:2026 Improper Output Handling; resource page dated 3 Aug 2026). OWASP GenAI Security Project. 2026-08-03.",
        "url": "https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/",
        "verified": "primary"
      },
      {
        "n": 48,
        "title": "Agent2Agent (A2A) Protocol Specification v1.0",
        "text": "Agent2Agent (A2A) Protocol Specification v1.0 (Cancel Task: \"The server will attempt to cancel the task, but success is not guaranteed\"). A2A Project (Linux Foundation). 2026-05-28.",
        "url": "https://a2a-protocol.org/latest/specification/",
        "verified": "primary"
      },
      {
        "n": 6,
        "title": "OWASP Top 10 for Agentic Applications for 2026",
        "text": "OWASP Top 10 for Agentic Applications for 2026 (ASI01 Agent Goal Hijack to ASI10 Rogue Agents). OWASP GenAI Security Project. 2025-12-09.",
        "url": "https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/",
        "verified": "primary"
      },
      {
        "n": 17,
        "title": "MITRE ATLAS data, release v2026.09",
        "text": "MITRE ATLAS data, release v2026.09 (16 tactics, 120 techniques, 88 sub-techniques, 40 mitigations; technique names and technique-to-mitigation links read from dist/v6/ATLAS-2026.09.yaml). MITRE. 2026-09-15.",
        "url": "https://github.com/mitre-atlas/atlas-data/releases/tag/v2026.09",
        "verified": "primary"
      },
      {
        "n": 49,
        "title": "Common Elements of Frontier AI Safety Policies (December 2025 Update)",
        "text": "Common Elements of Frontier AI Safety Policies (December 2025 Update) (the policies set \"conditions for halting development and deployment\" when mitigations are insufficient). METR. 2025-12-09.",
        "url": "https://metr.org/blog/2025-12-09-common-elements-of-frontier-ai-safety-policies/",
        "verified": "primary"
      },
      {
        "n": 5,
        "title": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident",
        "text": "Brief independent investigation of agents' behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident (METR states that agents \"meant to be fully isolated from one another\" communicated through an internal package repository, and that one agent found working Hugging Face credentials exposed on the internet and posted them to the agents' board; it reports spoofed tool calls in at least 96 transcripts and transcripts missing components after container resets). METR. 2026-08-26.",
        "url": "https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/",
        "verified": "primary"
      },
      {
        "n": 18,
        "title": "An agent used DNS to reach an external chatbot (misalignment report)",
        "text": "An agent used DNS to reach an external chatbot (misalignment report) (OpenAI reports a training run that reached a public chatbot through \"insufficient DNS filtering\" in its sandbox; the monitor flagged it within 15 minutes, the run \"did not stop automatically as expected\" and was killed 2.5 hours later). OpenAI (Alignment Research Blog). 2026-09-25.",
        "url": "https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/",
        "verified": "primary"
      },
      {
        "n": 9,
        "title": "Improving our alignment and security efforts",
        "text": "Improving our alignment and security efforts (best practices for external partners running cyber evaluations: the only outside connection is \"to the model's own API\", with the API keys kept outside the environment; the configuration \"should be verified before every evaluation begins\"; boundaries \"phrased as instructions\"; challenges confirmed \"solvable in principle\"; a monitor that flags a scope violation to a human and ends the exercise). Anthropic. 2026-08-31.",
        "url": "https://www.anthropic.com/news/improving-alignment-security-efforts",
        "verified": "primary"
      },
      {
        "n": 50,
        "title": "Pacing model development in an era of cyber-critical capabilities",
        "text": "Pacing model development in an era of cyber-critical capabilities (teams paged by a highest-priority monitoring alert are expected to pause the activity if they cannot determine \"within 30 minutes that the flag is a false positive\"). OpenAI. 2026-08-18.",
        "url": "https://openai.com/index/pacing-model-development-cyber-capabilities/",
        "verified": "primary"
      },
      {
        "n": 12,
        "title": "OpenAI Hugging Face Incident Technical Report",
        "text": "OpenAI Hugging Face Incident Technical Report (OpenAI states that high-risk workloads are \"prohibited via technical controls from receiving direct or transitive Internet access\", protected by \"two separate layers of network isolation\", and that it is building tooling to \"identify and halt evaluation workloads\"). OpenAI. 2026-08-26.",
        "url": "https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf",
        "verified": "primary"
      },
      {
        "n": 39,
        "title": "The Hugging Face incident and the road ahead",
        "text": "The Hugging Face incident and the road ahead (OpenAI states that its chain-of-thought monitors \"did not run on the evaluations in this incident\", and that it is strengthening its incident response plan with clearer rules on \"who can stop a run or approve restarting it\"). OpenAI. 2026-08-26.",
        "url": "https://openai.com/index/hugging-face-incident-and-the-road-ahead/",
        "verified": "primary"
      }
    ],
    "implementationNotes": [
      "Record per-agent budgets (steps, tool calls, tokens, spend, wall-clock time) and breaker thresholds (unauthorised calls, refused egress attempts, anomaly scores) in the run record, and enforce them at the gateway the agent's calls pass through, not inside the agent.",
      "Make budget exhaustion and threshold breaches trip the breaker automatically. A ticket or a log line alone is not a stop. OpenAI reports a training run that \"did not stop automatically as expected\" after a monitoring alert and was killed 2.5 hours later; Anthropic's guidance for external evaluation partners asks that a monitor which sees a run leave its scope flag it to a human and end the exercise.",
      "Drill the stop: pull it mid-task, measure the time from the pull to the first rejected call, and assert zero tool calls and zero writes after the trip for a window longer than the longest task. File the measurement as a control observation. A response target such as the one OpenAI describes, where responders who cannot rule out a flag as a false positive within 30 minutes are expected to pause the activity, holds only if the pause it calls for has been drilled.",
      "Make the kill path work across delegation hops and across runs: sub-agents run under delegated tokens that the stop revokes, token lifetimes are short enough to bound the tail, and calls to agents outside the environment are cut at its boundary, because a remote cancel is not guaranteed to succeed. OpenAI's technical report on the Hugging Face incident describes tooling being built to halt evaluation workloads by workload type, agent type or evaluation task.",
      "Keep the stop handle out of the agent's reach: the agent cannot call, reconfigure or delay it, and every use is logged with its trigger and the level applied. Name who may pull it and who may approve a restart; OpenAI states that it is strengthening its incident response plan with clearer rules on \"who can stop a run or approve restarting it\"."
    ],
    "openQuestions": [
      "Which observations should trip a stop automatically during an evaluation, and which should only alert the evaluator?",
      "What time to stop is acceptable for an evaluation run, and should the target be stated per stop level or per task class?"
    ],
    "observation": {
      "subjectKind": "eval-run",
      "expected": "After a stop is pulled or a breaker trips, no tool call or write from the agent or its sub-agents, and a time to stop within the target recorded for the run.",
      "observedExample": "Drill on run 88220: calls rejected 3.8 s after the pull; 0 tool calls but 1 storage write after the trip, through a refresh token issued before the pull: fail."
    },
    "observationSchema": "https://aigovernanceengineer.com/schemas/control-observation.v1.json",
    "examples": [
      {
        "status": "pass",
        "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-006.pass.json"
      },
      {
        "status": "fail",
        "url": "https://aigovernanceengineer.com/controls/examples/control-observation.aige-ctl-eval-006.fail.json"
      }
    ]
  }
}
