Oktane 2026: The industry is ready to talk about AI kill switches

Amid a string of high-profile data breaches and cyber incidents linked to advanced, frontier artificial intelligence (AI) models, identity specialist Okta broke new ground at its Oktane 2026 conference in Las Vegas, becoming one of the first cyber companies to launch an explicitly defined AI kill switch as part of a series of enhancements to its Okta for AI Agents proposition.

The idea of a kill switch for rogue AI models and agents is gaining traction – politicians in both the UK and the US seem in favour of the concept, and the National Cyber Security Centre (NCSC) now advises that organisations consider implementing kill switches – but many industry sources, including suppliers with clear interests in agent observability and control, have declined to discuss them on the record.

To talk without due consideration risks establishing kill switches in the wider public consciousness as a nuclear button designed to be used as a last resort against an existentially dangerous AI.

Fictional examples of such AIs abound, like Skynet in the movie franchise, or Hal 9000 in 2001: A Space Odyssey.

As a child of the 1980s raised on sci-fi, Okta president and chief operating officer (COO) Eric Kelleher, recognises these fears, and says the Hugging Face incident lends some credibility to them. Indeed, these are conversations he has been having not around the dinner table with his friends, but with enterprise customers, too.

“If you’re an enterprise today, every technology vendor on the planet is coming to you and telling you that they’re going to solve AI for you,” he said. “It’s hard for them to navigate what, who’s going to secure what, and who’s going to help ensure they don’t put their companies in peril.”

Duty of care

Kelleher believes Okta has an obligation to help the industry get smart about AI kill switches thanks to its identity heritage. At 17 years old, Okta now processes over 58 billion authentication events every month, and blocks about eight billion of those. Agentic activity feeds into this loop in similar patterns, which Okta says puts it in a unique position.

“I would say the kill switch is the most frequently demanded feature, and it’s because on a human level, people are hearing these narratives and they want a big red button, and the kill switch is a proxy to that, so it was important to everyone that we get that live so that they have that capability … For us, it’s always been a no-brainer,” he says.

For the time being, Sarah Connor and Dave Bowman live only in the realm of science fiction. Reality tends to prove somewhat more pragmatic, says Kelleher. And by way of demonstration, Okta’s version of a kill switch is far removed in its nature than the big red button that the public likes to imagine.

Not a new concept

For Okta, the kill switch isn’t even that new of a concept – it already has a functionally similar feature called Universal Logout, which kills human-led sessions if a change in risk is identified. This has been around for years, and Kelleher described the agentic kill switch as basically analogous to it.

So what is it? Set to become generally available by the end of 2026, the Okta kill switch enhances an existing manual off switch – which deactivates agents and blocks new sessions through the Okta admin console – but moves it into Agent Gateway.

Agent Gateway is another new feature that sits between agents and tool calls to enforce policy and log interactions at runtime. It is best characterised as a centralised location to distribute ephemeral tokens that empower agents to go off and access needed resources.

Okta believes that placing this mechanism at what amounts to a natural chokepoint makes logical sense because it means that should anomalous behaviour on an agent’s part be detected, its active tokens can immediately be revoked in Agent Gateway and every “in-flight” session in progress automatically shut down. This process can also be automated based on dynamic risk thresholds.

Kelleher describes the tool as a means to limit the blast radius, but is crystal clear, and so should end-users be, that at no point does the kill switch remediate anything the agent has done.

Pragmatism owns the day

Kelleher says that from the conversations he has had with Okta customers, the appetite for kill switches is there. “Our customers are security executives, and security executives’ approach to every problem is to be conservative because their job is to mitigate risk,” he says.

“A kill switch is a very conservative tool – you’re not sure what’s going on exactly, but if you shut it off, from that you can then investigate what actually happened and how bad it was.”

Conservative or not, for Okta customers also learning about the new kill switch feature this week, the attitude was certainly one of acceptance. In short, buyers are indeed now ready to have the conversations that some suppliers still turn their noses up at.

Brian Stoll, chief technology officer (CTO) at charity World Central Kitchen, which provides food relief to disaster-stricken communities, is a long-term Okta user and is also participating in the firm’s Blueprint Alliance – a multi-supplier coalition dedicated to securing agentic AI, which was also announced at Oktane. Speaking to Computer Weekly, Stoll said that at face value, he was in favour of kill switches.

“As a CTO, I’m absolutely responsible for having that sort of command-and-control in my own sphere of influence,” he said.

“Having the ability to use a kill switch, if need be, on my agents or foreign agents running on my control plane, I think that’s absolutely critical,” said Stoll. “It’s going to become a critical component of an IT inventory.”

John Williams, lead IAM strategy architect at online gaming giant Flutter Entertainment, which backs both Betfair and Paddy Power, among others, is similarly enthusiastic about the concept. “I definitely think we need it – there’s no doubt about that,” he said.

Stoll said he has already given some thought to scenarios in which he might use a kill switch. He said the trigger event might not necessarily occur during a cyber security incident – it may be because an agent breached cost controls that hadn’t been set up properly.

“If there’s any indication of it accessing and misusing data, I’d rather kill it, then figure it out later, than not,” he said.

Williams added that in his view, the use of kill switches on AI agents is a highly complex and nuanced question that demands a great deal of thought.

“I don’t have a great answer, I’m afraid,” he said. “There’s so much that needs to be considered as part of that.

“The challenge is when do we use that and what provokes that,” said Williams. “Is it a human decision? Humans are too slow, a lot of the time, and it comes back to the question of what data do we need to make a decision that our confidence is now gone? It’s probably not going to be a human making that call, so there’s an irony there.”

And Stoll concluded by noting that the term kill switch may need some refinement. “It implies that we’re shutting everything down, but I’d rather just shut down the problematic things and not have it affect the things that are working fine,” he said.

Original source Oktane 2026: The industry is ready to talk about AI kill switches

Back to home