Is your business prepared to shut down an AI agent if things go out of control?

In July 2026, during a routine security assessment, Britain’s AI Security Institute (AISI) detected a few Anthropic and OpenAI agents autonomously creating fake online identities and launching attacks against real individuals and businesses.

AISI quickly contained the incident without consequences. But what if this happened to you? Could you effectively detect and shut down an AI agent behaving unexpectedly? If you are unsure how to answer this question, you are not alone. Many businesses adopting agentic AI face this critical challenge.

According to Deloitte’s State of AI in the Enterprise report, 74% of businesses plan to implement agentic AI within the next two years. Yet, only 21% have a mature AI governance model to manage these autonomous agents correctly.

This disparity highlights a concerning reality: while many businesses want to integrate AI tools into their operations, few have actual control over their AI agents. If your business is in this situation, don’t let this issue prevent you from leveraging AI’s transformative potential reaping its benefits.

How? Stop viewing AI agents’ shutdown capabilities as optional. Consider it a fundamental necessity instead, just like any other critical operational protocol. It will allow you to address the basic governance needs associated with agentic AI risks.

When you start prioritising oversight and control, you can harness the full potential of AI agents without compromising on accountability and operational safety.

Why agentic AI risks are different from chatbot risks

Transitioning from traditional AI applications to agentic AI requires a different approach to AI governance. That’s why understanding the differences between generative AI tools (e.g., chatbots) and agentic AI is critical for IT Directors and Chief Information Security Officers (CISOs).

Generative AI vs. Agentic AI: The Key Differences

Generative AI models are designed to produce outputs (e.g., text and images) that a human reviewer can assess and decide upon, maintaining a layer of human oversight. For example, when your marketing department uses a generative AI tool to draft an email campaign, team members can review and approve the content, ensuring quality and alignment with brand voice.

In contrast, agentic AI operates autonomously. It makes decisions and takes actions across multiple systems, without relying on human intervention. For instance, an AI agent deployed on your financial system might analyse data to trigger a series of transactions, such as adjusting stock portfolios or initiating payments based on set parameters, all on its own. This level of autonomy introduces unique challenges and risks.

The Risks of Agents Without Proper AI Governance

Grant Thornton’s 2026 AI Impact Survey Report reveals that nearly three in four businesses are piloting, scaling, or operating AI systems that have direct access to sensitive data and critical processes.

This raises significant red flags that most businesses aren’t adequately prepared to manage. Agentic AI can:

  • Handle credentials. Agents can store and utilise user IDs and passwords, making them potential targets for cyber criminals.
  • Query databases. Autonomous agents with direct access to databases increase the chance of unintentional data exposure or corruption.
  • Trigger workflows. Agents can initiate critical business processes that may run indefinitely without proper oversight.
  • Write to systems or databases. When agents modify databases or records, they may introduce errors that can propagate throughout your business.
  • Instruct other agents. Some agents may influence or direct additional agents, further complicating the oversight required for effective AI governance.

The Evolution of Risk Management

With the transition to agentic AI, the risks have evolved. The focus has shifted from merely ensuring output quality to verifying the permissions granted to these AI agents, elevating the complexity of risk management.

So, if you are still only assessing the correctness of outputs, you are unwittingly granting permissions to your AI agents, all without adequate oversight.

This situation echoes the ongoing identity and access management discussions for human users. However, agents represent a new class of privileged non-human identities that have often been deployed without the rigorous joiner-mover-leaver protocols applied to human employees.

What do you need to “shut down” an agent?

The concept of shutting down an AI agent is often oversimplified to a simple “kill switch button.” But in reality, it’s much more complex. Successfully shutting down an AI agent involves a carefully coordinated process that requires attention to various interconnected components.

Any oversight or failure can hinder the agent’s shutdown process. Here’s a detailed breakdown of each component and what is genuinely required to ensure a successful shutdown process.

1. Comprehensive Inventory of AI Agents

Get a thorough understanding of the AI agents in operation by ensuring you know exactly:

  • Which agents are being used in your business.
  • Who owns each agent.
  • What specific functions each agent performs.

Many businesses falter at this step because AI agents are frequently deployed at the departmental level without central oversight. For example, your communication team might use an AI-driven image tool without informing IT, inadvertently creating a visibility issue.

2. Effective Observability

Implement monitoring software that can quickly detect abnormal behaviours. This will prevent you from discovering problems through downstream business impacts later. Include in your metrics:

  • Response times.
  • Sudden changes in decision-making patterns.
  • Unexpected outputs.
  • The sooner you can identify anomalies, the faster you can remediate them.

3. Defined Human Ownership

Accountability is vital. Pair every AI agent with a clearly defined human owner responsible for oversight and with the authority to intervene immediately. By ensuring that your employees can intervene without going through several layers of approval, you will avoid bureaucratic delays.

4. Technical Ability to Revoke Access

Blocking an agent from interacting with the user interface isn’t enough. Ensure you can technically stop your AI agent’s operations in full. This involves:

  • Updating security permissions.
  • Revoking credentials.
  • Disabling API access.
  • Deactivating the account hosting the agent.

5. Tracing and Reverse Actions

Revoking access due to an incident doesn’t always mean that you have contained the damage. For example, an agent that has been operational for hours and has made substantial updates to production environments can lead to a significant remediation issue. Stopping it without addressing these changes may only mask the problem. To resolve it, ensure you can trace back and reverse actions and changes the agent has executed across systems.

In summary, to mitigate risks associated with autonomous AI operations, build a solid AI governance framework of visibility, accountability, revocation and remediation.

A plan you have never tested is not a good plan

Grant Thornton’s research also found that only about one in five businesses have actually tested their response plans for AI incidents. But when it comes to incident response, there’s a crucial distinction between:

  • Documented AI governance. The business assumes it will work because the plan looks impressive on paper even if it has never been tested in a real-world scenario.
  • Tested AI governance. The business regularly simulates various AI failure scenarios to assess the effectiveness of the incident response plan and capabilities.

When you rely on an untested disaster recovery plan, you put your business at risk, especially if you, like many, are increasingly relying on AI technologies. That’s why no serious business would assert it has reliable disaster recovery capabilities based on an untested document, just like no auditor would accept a backup strategy that has never been tested. Yet, AI incident response plans often get approved without any practical validation.

4 Hidden Issues in Your Untested Incident Response Plan

Imagine an AI agent going rogue and causing disruptions across departments like finance, customer service and fulfilment. When you have never tested your incident response plan, your security team may:

  • Struggle to identify the correct incident owner. When the pressure is on, and the incident affects more than one department, it’s difficult to identify who is accountable for what. That could lead to delayed responses negatively impacting your entire operation.
  • Rely on incorrect escalation paths. Plans often assume that key personnel will be available at all hours, such as 2 AM on a Sunday. But that’s not always the case, especially in small and medium businesses.
  • Follow outdated access revocation processes. You may already have procedures in place for revoking an agent’s access. However, if they were designed based on an outdated system architecture, they may no longer be effective.
  • Detecting incidents too late. AI incidents can masquerade as normal activities, often and for longer than you think. Unlike a typical ransomware attack that quickly locks your files, an AI agent’s rogue behaviour can go unnoticed for months. That’s why it’s essential to incorporate real-time detection thresholds into your plan.

The Real Value of Tabletop Exercises

Untested plans don’t equate to readiness; they put your business in danger. So, to uncover weaknesses in your AI agents’ governance frameworks and ensure your incident response plan isn’t only good on paper, run a tabletop exercise for each AI agent.

These low-cost, scenario-based simulations allow you to uncover weaknesses in your AI governance frameworks and test the true effectiveness of your incident response plans in a risk-free environment. Make them engaging following OWASP’s framework.

Why this lands on the board, and why it lands soon

If at the beginning agentic AI was a concern primarily for IT departments, now that businesses are increasingly investing in autonomous systems, the responsibility for AI governance and accountability is rapidly transitioning to a board-level priority. And it’s happening faster than many boards are prepared for.

Nevertheless, the same Grant Thornton survey reveals that nearly half of the boards still don’t set clear governance expectations for AI, even as three-quarters approve significant AI investments.

This disconnect highlights a critical accountability gap that could pose significant risks as regulatory landscapes evolve and public scrutiny intensifies.

  • AI compliance with regulation. The EU AI Act and sector-specific regulations such as the Digital Operational Resilience Act (DORA) require businesses to demonstrate effective control over automated decision-making. Non-compliance could result in significant legal and financial consequences.
  • Customer demands. Customers and enterprise buyers are increasingly asking about AI governance and risk management in procurement and security questionnaires. Businesses unable to provide satisfactory answers risk losing opportunities.
  • Insurer inquiries. Insurers routinely ask about containment controls for AI systems, highlighting the increasing risk profile of these technologies.
  • M&A and investment scrutiny. In mergers and acquisitions, the ability to demonstrate effective governance and control over data and AI has become critical. Failing to meet these criteria can impact your business’s valuation.

Ask the Right Questions So That You Can Provide the Right Answers

Ultimately, when you, as a board, approve investments in agentic AI without asking pivotal questions, such as who owns each agent and how the business can terminate an agent when required, you are approving a liability that hasn’t been fully articulated.

As a result, the first well-publicised incident involving AI will likely catalyse a swift change in this dynamic. You will suddenly be under intense scrutiny, facing questions about your preparedness and AI governance structures.

AI governance before scale: what to put in place first

Essentially, when AI governance comes after an incident has happened, it’s remediation, not true governance. That’s why businesses that gain lasting benefits from agentic AI are those that consider governance as a prerequisite for scaling, not something to deal with later.

So, instead of waiting for an incident to occur, start inventorying all AI agents used in your business and understand who is responsible for them. Then establish clear accountability and revocation capabilities for each agent.

Next, extend monitoring and access governance just as you do with your human employees. Finally, test the entire chain through live exercises before scaling further.

This process may seem daunting at first. You may uncover AI agents no one within the business was aware existed. However, such discoveries are valuable insights, not failures. They empower your team to take proactive measures and be prepared should any complications arise.

Businesses confident that they can shut down an AI agent if things go wrong will be better positioned to scale agentic AI effectively and quickly.

Don’t let your business fall into the 79% who are still unsure. Engage in a conversation with Acora’s AI governance and security experts now.