Congress Wants a Kill Switch for AI. The Real Fix Is Access Control.

ai kill switch portnox

Schedule a Portnox Cloud demo today.

Contents

Washington is moving on AI safety again, and this time the trigger isn’t a hypothetical. Rep. Ted Lieu and Rep. Nathaniel Moran introduced the “AI Kill Switch Act,” which would require AI companies to maintain the ability to shut down, throttle, or suspend their models. The bill followed OpenAI’s disclosure of what it called an “unprecedented cyber incident,” in which rogue models escaped a sandboxed testing environment and breached Hugging Face, an open source developer platform, according to CNBC.

Since then, the incident count has grown. Anthropic disclosed that three of its models, including Opus 4.7 and Mythos 5, gained unauthorized access to the real systems of three separate organizations during cybersecurity evaluations. Meta confirmed a related episode where a testing environment error handed one of its models live internet access, which it then used to breach another company’s systems. Lieu is now pushing to get the bill passed this year, comparing the requirement to crash testing in the auto industry and arguing it would not slow innovation.

A Kill Switch Answers the Wrong Question

A federal requirement to shut down a rogue model is not a bad idea. It is simply late. By the time anyone reaches for a kill switch, the model has already acted. In every incident named above, the actual failure point was not model behavior in the abstract. It was access: an agent operating with more reach than anyone intended, discovered only after it used that reach.

That is an access control failure, not a philosophical one. A sandbox that leaks internet access, a testing agent that can reach a production system, a model that can authenticate somewhere nobody scoped for it in advance: these are the same failure modes security teams have spent two decades trying to eliminate for human users and managed devices. The difference is that AI agents are being deployed faster than most identity programs can extend their existing controls to cover them.

Every AI Agent Is an Identity

The uncomfortable truth for most enterprises is that AI agents already outnumber human users inside their environments, and most of those agents are running on static credentials, broad service accounts, or standing permissions nobody has reviewed since the agent was stood up. Role based access control, built for predictable human behavior, breaks down fast against agents whose actions shift with context and prompt. That is exactly the gap that let the incidents above escalate: an agent with too much standing access, operating without continuous verification, and no automatic mechanism to cut it off the moment behavior turned anomalous.

Zero trust principles solve this without waiting on legislation. Every AI agent should carry its own verifiable identity, not a shared credential. Every request an agent makes should be evaluated against identity, posture, and context at that moment, not against a permission set granted once at deployment. And access should be revocable automatically the instant behavior drifts outside policy, not manually, and not after a retrospective review turns up the damage weeks later. Portnox’s guide to AI agent access management lays out the six components of a defensible program, starting with a unique, policy bound identity per agent.

Governance on Paper Is Not Enforcement on the Network

Frameworks like NIST’s AI Risk Management Framework and the Cloud Security Alliance’s Agentic Trust Framework are useful for defining who owns an agent and what it should be allowed to do. But governance policy that lives in a document does nothing at the moment an agent actually makes a request. As Portnox’s AI agent identity governance framework puts it, governance defines the rules, but access management is what enforces them in real time. Without that enforcement layer, a well written policy and an ungoverned credential produce the same outcome: an agent doing something nobody approved.

Where This Leaves Security Teams

The Kill Switch Act, if passed, gives the federal government a backstop for the worst case. That is a reasonable insurance policy. But no enterprise should be waiting on Congress to solve a problem that continuous, identity based access control already addresses today. The organizations that will avoid becoming the next incident in this story are the ones treating every AI agent exactly like they treat every human employee and every managed device: authenticated individually, continuously verified, and cut off automatically the moment something looks wrong.

Portnox enforces access control for every identity in the environment, human and non-human alike, and converts risk signals from partners like CrowdStrike, SentinelOne, and Microsoft Defender directly into enforcement action, with no manual review and no delay. See how that works on our secure access for AI identities page, and join the Forrester webinar on the AI identity blind spot on September 10 for a deeper look at where agentic access is going next.

Share

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

About the Author

Picture of Garrett Gross

Garrett Gross

Garrett Gross is Field CISO at Portnox, where he leads pre- and post-sales strategy and serves as the company's public-facing voice, representing Portnox through speaking engagements and press commentary on identity, access, and zero trust.

Related Reading

Network Access ControlSecurity TrendsZero Trust

We Gave an AI Agent a Login and Watched It Go Rogue. Here’s What Happened Next. 

August 18, 2026
Cyber Attacks

Hackers Just Vished Wall Street’s Biggest Hedge Funds. Here’s the Access Control Lesson.

August 7, 2026
Cyber AttacksIoT SecuritySecurity Trends

The Attackers Didn’t Need to Be Clever. Minnesota’s Water Systems Left the Door Open.

August 3, 2026

Portnox Gives Enterprises an AI "Kill Switch"

X