Deactivate or reinstate AI agents using kill switch protocol to eliminate malicious activity and improve your security posture.
Before you begin
Role required: AI steward [sn_ai_governance_ai_steward]
Make sure that you have configured connectors and optional identity providers for AI agent containment. For more information, see Configure AI agent containment.
Procedure
-
In AI Control Tower, navigate to .
Alternatively, you can navigate to .
-
Open Critical AI asset events.
-
Select and view the AI asset associated with the critical event.
A banner appears informing you that there is malicious activity detected for this AI asset.
-
On the banner, select View details.
A pane appears with information about the activity detected for this AI asset, and the next best action to take.
-
Select Deactivate.
-
Provide the reason for the deactivation and select Deactivate.
The banner on the AI asset changes to reflect the progress of deactivation.
-
Select View kill switch protocol log to track the progress of the deactivation.
-
After deactivation is complete, you can reinstate the AI agent by resolving the critical security task for the AI agent first.
-
Navigate to .
-
In the AI agent row, under More actions, select Reinstate.
-
Enter a reason for reinstating the AI agent and select Reinstate.