On this page

Pattern: Kill Switch / Circuit Breaker

A tested mechanism that stops one agent or class of agents at the point of action, revoking its access without breaking the rest of the fleet.

Layer 04 · Runtime Controls & Observability In the chapter 05 catalogue

Summary: Provide a tested mechanism to stop an agent or class of agents at the point of action, revoking access and halting tool calls, without breaking the rest of the fleet. Autonomy is granted only where it can be withdrawn.

Kill Switch / Circuit Breaker An architecture diagram generated by Archify. Guardrail events · flagged calls · Layer 04 Runtime Controls & Observability Guardrail events flagged calls Telemetry · anomaly, threshold · Layer 04 Runtime Controls & Observability Telemetry anomaly, threshold Circuit breaker · tool-call boundary · Layer 04 Runtime Controls & Observability · auto or manual Circuit breaker tool-call boundary auto or manual Agent A · scope revoked · Layer 04 Runtime Controls & Observability Agent A scope revoked Agent B · runs on · Layer 04 Runtime Controls & Observability Agent B runs on Agent C · runs on · Layer 04 Runtime Controls & Observability Agent C runs on Incident record · trip logged · Layer 05 Assurance & Continuous Compliance Incident record trip logged signal revoke scope trip = evidence Layer 04 Runtime Controls & Observability Layer 05 Assurance & Continuous Compliance Legend Backend Database Security External
Kill Switch and Circuit BreakerA breaker trips on a signal and revokes one agent’s scope while the rest of the fleet keeps running, and the trip itself becomes an incident record. Design the breaker per agent scope before you need it and test the trip in staging. Generated from the Body of Knowledge.Open interactive diagram (opens in a new tab)

Objectives

Bound the blast radius of a misbehaving or compromised agent, and make “stop it” a control that has been exercised, not a claim.

Target users

AI governance engineer, security engineer, SRE.

Impacted stakeholders

Model owners, users, incident responders, affected third parties.

Relevant principles

Register and bound every actor before it acts; start from a named failure mode or harm.

Context

Agents that act autonomously (calling tools, moving data or money), where a single failure can cascade. Gartner expects that by 2029 more than half of successful attacks on AI agents will exploit access-control weaknesses and prompt injection1.

Problem

An agent that cannot be stopped precisely can only be stopped by breaking everything. A fleet on shared credentials means an incident forces a choice between leaving the agent running and rotating a secret that halts the whole fleet.

Solution

Bind each agent to its own identity (see Agent Identity & Scoped Credentials) so access can be revoked per agent. Implement a circuit breaker at the tool-call boundary that trips on a defined signal: a threshold breach, an anomaly, a manual pull. Test the kill switch on a schedule; an untested kill switch is not a control.

Consequences

Incidents are contained to one agent and recovery is fast. The cost is per-agent identity plumbing and the engineering to make revocation instant and safe.

Agent Identity & Scoped Credentials; Agent Registry; Human-in-the-loop Gate; Incident Pipeline.

Maps to: EU AI Act Art. 14, Art. 15 · ISO/IEC 42001 · NIST AI RMF (Manage) · CSA AICM · OWASP Agentic ASI02/ASI10 · Layer 04 Runtime Controls & Observability.

Threat IDs follow the OWASP Top 10 for Agentic Applications 2026 2 and function labels the NIST AI RMF3. Mappings are illustrative, not a claim of conformity.

Sources

  1. [1] “Gartner Forecasts the Market for Securing AI Will Reach Almost $5 Billion in 2027” (>50% of agent attacks exploit access-control and prompt injection by 2029). Gartner. 2026-08-26. https://www.gartner.com/en/newsroom/press-releases/2026-08-26-gartner-forecasts-the-market-for-securing-ai-will-reach-almost-5-billion-in-2027 (verified: primary)
  2. [2] Top 10 for Agentic Applications 2026 (ASI IDs). OWASP GenAI Security Project. 2025-12-09. https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/ (verified: primary)
  3. [3] AI Risk Management Framework (AI RMF 1.0; Govern, Map, Measure, Manage). NIST. 2023-01-26. https://www.nist.gov/itl/ai-risk-management-framework (verified: primary)
Edit this page on GitHub
Cite this pattern

García Aibar, J. (2026). Pattern: Kill Switch / Circuit Breaker. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), chapter 05, Patterns. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker. CC BY 4.0

BibTeX

@misc{aige2026bok,
  author  = {Jorge García Aibar},
  title   = {{AI Governance Engineering: The Thesis \& Body of Knowledge}},
  chapter = {05. Patterns: Kill Switch / Circuit Breaker},
  year    = {2026},
  version = {0.5.0},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/patterns/kill-switch-circuit-breaker},
  note    = {Version 0.5.0}
}
Share on LinkedIn