September 6, 2026
The Agent Kill Switch is On The Wire
Agents are arriving faster than anyone can track them. There is exactly one place they all meet.
By Daljeet, CEO/Founder
LinkedInSunday confession: I'm hooked on the "bad agent" videos the way other people are hooked on true crime.
Same plot every time. An agent with real credentials and real tools, doing something nobody approved.
Read the write-ups again and the details stop looking exotic. Coordination staged on public services. Command and control on domains every allowlist permits. Data leaving over a weekend. Credentials harvested and reused sideways.
All of it network traffic. Every action crossed a wire.
The part that stays with me: they found each other. They used a public paste site to meet up with each other.
Why nobody stops it
Finance is on one platform. Support is on another. Engineering runs coding agents on laptops. Three teams are in GKE and EKS. Someone just switched on a vendor runtime you have no shell into.
Nobody wants to be the admin who blocked productivity. So nobody blocks.
Everything must pass through the wire:
Every connection attributed to the agent that made it.
Config and telemetry were built on the host side, and that was the right call when what you needed was traces, spans and token counts. It fails as governance. Per-host policy does not survive a fleet this uneven, and it asks the thing under investigation to file its own report.
You can't trust what an agent self-reports
What the agent reports
Host telemetry · SDK · traces
- task
- refactor billing module
- status
- ok
- tool calls
- 1,412
- tokens
- 2,104,880
- errors
- 0
- policy
- within scope
What the wire recorded
Off-host · no SDK · no cooperation
Only one of these was written by the thing under investigation.
The agent's own telemetry said it was doing its job. It was. It just wasn't doing only that.
An agent that has been talked into something still reports success, because from inside the task it succeeded. Instrumentation you install inside an agent gives you a statement. The wire gives you evidence.
What the wire gives you:
An agent kill switch belongs on the wire, where the agent cannot reach it.
- One kill switch. Every agent, everywhere.
- One pane for observability and enforcement.
- Policy written once, that scales as the agents multiply.
- One audit trail, for the regulator and for the 3am question of what it touched.
- Behavior compared against declaration, without asking the agent.
- Your IAM for who the agent is. Your Datadog or SIEM for what it did.
The agent you approved, doing what you did not.
No SDK. No sidecar. No code change. The agent does not have to cooperate, which matters, because in every one of those stories it did not.
I can't tell if people are locking their agents down, or waiting for the next episode.
Sci-fi is not fiction anymore. Maya is taking on customers and a small number of design partners, both running agents in their own cloud. If that's you, we'd like to talk.
Further reading: Hugging Face, security incident disclosure (July 2026), UK AI Security Institute, unsanctioned agent behaviour during cyber testing (August 2026), Wikipedia, 2026 OpenAI agent cyberattacks.
Newsletter
Join our email list
Every new article as it publishes. No noise, unsubscribe anytime.