---
sourceDocument: Australia Enable AI
sourceDocumentLink: https://www.servicenow.com/docs/r/intelligent-experiences

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Enable AI

ft:clusterId :

    - platai

bundleId :

    - platai

workflow :

    - Platform


---

# AI agent containment using kill switch protocol

# AI agent containment using kill switch protocol {#ariaid-title1}

Release version: Australia  
Updated July 21, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read  
Explore how detecting malicious activity and deactivating AI agents works to enforce guardrails and help improve your security posture.

AI agents operate as autonomous actors across the enterprise, frequently with elevated or administrative privileges. AI agent containment using kill switch protocol gives you the ability to immediately contain an AI agent and revoke
all of its active credentials across connected systems.

Policy enforcement points (PEPs) are part of AI agent containment. PEPs can be identity providers, AI agent runtimes, or infrastructure platforms. When you contain an AI agent, AI Control Tower doesn't just issue revocation requests;
it confirms enforcement completion from each individual PEP before declaring the agent contained.  

## Example: Malicious activity by an AI agent {#gov-sec-exploring-ai-agent-containment__example_p23_jtj_zjc}

An AI steward receives a tip from a vendor that an AI agent integrated with their platform is generating suspicious API calls. The steward opens the Security page of AI Control Tower and notices a critical security event involving the AI agent. Upon viewing the AI asset, AI Control Tower alerts the steward that malicious activity was detected. Traceloop data and policy enforcement points (PEPs) provide a summary of the agent behavior.   

The system suggests that the next best action is to deactivate the AI agent. The analyst deactivates the AI agent and receives confirmation that the AI agent was deactivated in Okta as well as AWS Bedrock.

## Audit and compliance {#gov-sec-exploring-ai-agent-containment__section_szt_4sj_zjc}

Every containment action including the PEP-by-PEP confirmation, produces a complete, immutable audit trail shown in the kill switch protocol log. This audit record can help satisfy compliance documentation requirements.

## Next steps {#gov-sec-exploring-ai-agent-containment__moreinfo}

To configure and use AI agent containment with kill switch protocol, see [Configure AI agent containment](https://www.servicenow.com/docs/bJYcPJAIaNS_pF5qrrU7ww "Connect identity providers and hyperscalers to ServiceNow to let you contain and enforce guardrails for AI assets at runtime using kill switch protocol.") and [Manage AI agents using kill switch protocol](https://www.servicenow.com/docs/ydFgncmKX~gV64E4iWARPQ "Deactivate or reinstate AI agents using kill switch protocol to eliminate malicious activity and improve your security posture.").

