🛑 Incident Response

AI Kill Switch

“Most platforms have one kill switch, for one kind of thing. We built five, because an incident is never just one kind of thing.”

5
Kill Switch Types
<50ms
Agent Halt
Sub-100ms*
Fleet Broadcast
100%
Reversible & Audited

Why It Matters

A real incident is never just one kind of thing. It touches an agent's identity, the MCP tools it calls, the non-human credential behind it, the cloud workload it's running on, and every other agent sharing its blast radius — all at once. A kill switch that only covers one of those is a kill switch that misses the other four. AI-agent exploits are consistently one of the largest categories in monthly breach tracking — and almost none of them stay contained to the agent layer alone.

How RuntimeAI Helps

Five purpose-built kill switches from one Kill Switch console.

Agent Kill Switch halts a single compromised agent or an entire tenant's fleet in under 50ms. MCP Kill Switch severs all MCP server/tool/gateway connections instantly, independent of the agent layer. NHI Kill Switch applies tiered control to the non-human identity itself — L1 throttles to 10% of baseline, L2 suspends API access (credential stays valid, fully reversible), L3 revokes the credential at the vault outright. Cloud Kill Switch does the same tiering for the underlying workload — L1 rate-limit, L2 block egress, L3 full network isolation with IAM/RBAC revocation — across AWS, Azure, and GCP. Catalog Kill Switch stops every agent tied to one incident together, as a group, with a signed forensic export (credential inventory, optional in-flight prompt/completion capture) ready for the investigation. A single red "Kill Switch" button in the dashboard header opens all five as tabs in one place, with a typed confirmation step and 2FA gating for the blast-radius options — so firing one is fast, but never an accident.

The Five Kill Switch Types

One console, five independent surfaces — pick exactly the blast radius the incident calls for.

Agent Kill Switch console
1. Agent Kill Switch
Halt a single agent or an entire tenant fleet, with a visible kill-switch policy (second-approver rules) and live active-blockades feed.
MCP Kill Switch console
2. MCP Kill Switch
Severs all MCP server/tool/gateway connections instantly, separate from the Agent Kill Switch, with the full 5-type nav group visible in the sidebar.
NHI Kill Switch console
3. NHI Kill Switch
Tiered L1 (throttle) / L2 (suspend) / L3 (revoke) control over every non-human identity, shown live and reversible per-identity.
Cloud Kill Switch console
4. Cloud Kill Switch
The same L1/L2/L3 tiering applied to cloud workloads across AWS, GCP, and Azure.
Catalog Kill Switch console
5. Catalog Kill Switch
Stop every agent tied to one incident together, as a group, with a signed forensic export ready for the investigation.

Confirmation & Quick-Fire

Fast to fire, never an accident.

Kill Switch typed confirmation dialog
Typed Confirmation
Target, reason, and consequences spelled out before anything fires. Nothing engages silently.
Kill Switch global quick-fire modal
Global Quick-Fire
All five kill switch types as tabs, one click away from the header, anywhere in the dashboard.

Illustrative Scenario

An agent's behavior drifts outside its normal pattern. Agent Kill Switch freezes it in under 50ms. The investigation finds it was invoked through a specific MCP tool — MCP Kill Switch severs that tool's gateway connections so nothing else can reach it while the review continues. The underlying service account gets throttled with NHI Kill Switch L1, then revoked at L3 once the credential is confirmed compromised. If three other agents touched the same catalog entry this incident came from, Catalog Kill Switch stops all of them together and exports the forensic package in one action.

Illustrative, not a specific customer engagement.

See It In Action

Real recorded demo clips — no slides, no mockups.

Process-Level Kill Switch demo
▶
A real SIGKILL, not just a blocked connection
Kill Switch reaching in-app conversational agents demo
▶
Kill Switch reaches conversational agents too
▶ More demos on YouTube →

Frequently Asked Questions

What is an AI kill switch?
An AI kill switch is a mechanism that immediately halts an AI agent's ability to act — stopping tool calls, revoking its credentials, or isolating its network access — when it drifts outside expected behavior or a human operator decides it must stop. RuntimeAI implements five separate kill switches (Agent, MCP, NHI, Cloud, Catalog) because a real incident rarely stays contained to just the agent layer.
How fast does RuntimeAI's kill switch work?
Agent Kill Switch halts a single compromised agent or an entire tenant's fleet in under 50ms. Tenant-wide broadcast across Envoy/Wasm sidecars runs at sub-100ms p50 in production, intra-region traffic — cross-region/WAN paths will be higher.
Can a kill switch action be reversed?
Yes. Every kill switch action is reversible from the same console with one click to restore traffic, and every activation and reversal is signed and written to an immutable audit log.
What's the difference between Agent, MCP, NHI, and Cloud kill switches?
Agent Kill Switch stops the agent itself. MCP Kill Switch severs MCP server/tool/gateway connections independent of the agent layer. NHI Kill Switch applies tiered control (throttle, suspend, revoke) to the non-human identity/credential behind the agent. Cloud Kill Switch applies the same tiering to the underlying cloud workload across AWS, Azure, and GCP. Catalog Kill Switch stops every agent tied to one incident together, as a group, with a signed forensic export.

Stop a Rogue AI Agent in Milliseconds.

Five kill switches, one console, fully reversible and audited. See it fire live.