Manage AI agents using kill switch protocol

  • Release version: Zurich
  • Updated July 21, 2026
  • 1 minute to read
  • Deactivate or reinstate AI agents using kill switch protocol to eliminate malicious activity and improve your security posture.

    Before you begin

    Role required: AI steward [sn_ai_governance_ai_steward]

    Make sure that you have configured connectors and optional identity providers for AI agent containment. For more information, see Configure AI agent containment.

    About this task

    Procedure

    1. In AI Control Tower, navigate to Govern > Security > Overview > Your top recommendations.
      Alternatively, you can navigate to Activity Center > Recommendations.
    2. Open Critical AI asset events.
    3. Select and view the AI asset associated with the critical event.
      A banner appears informing you that there is malicious activity detected for this AI asset.
    4. On the banner, select View details.

      Banner indicating that malicious activity was detected for the AI agent.
      A pane appears with information about the activity detected for this AI asset, and the next best action to take.
    5. Select Deactivate.

      Malicious activity evidence shown for an agent.

    6. Provide the reason for the deactivation and select Deactivate.

      Deactivation confirmation with a prompt to enter the reason for deactivating the AI agent.
      The banner on the AI asset changes to reflect the progress of deactivation.
    7. Select View kill switch protocol log to track the progress of the deactivation.

      In progress banner message with a View kill switch protocol log button.
      For more information, see Review the kill switch protocol log.
    8. After deactivation is complete, you can reinstate the AI agent by resolving the critical security task for the AI agent first.
    9. Navigate to Security > Overview > Contained AI agents.
    10. In the AI agent row, under More actions, select Reinstate.
    11. Enter a reason for reinstating the AI agent and select Reinstate.