As a CISO, I’ve sat through enough tabletop exercises to know the difference between a control that exists on paper and one that actually works under pressure. Right now, most organizations have an AI kill switch that exists only on paper, and the Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report backs that up with numbers that should alarm every security team running AI in production.
Seventy-nine percent of organizations surveyed lack a tested kill switch for their AI systems. A year ago, the Kiteworks 2026 Forecast Report projected that figure to be closer to 60% by now. Instead of closing, the gap widened – which tells me security teams are approving AI deployments faster than they’re building the controls to contain them.
The distinction that matters: documented versus tested
Here’s what I’ve seen repeatedly in incident response: a team says, “we have a kill switch,” and what they actually have is a Confluence page describing an escalation path and a named owner. That’s not a control. A control is something you’ve triggered, watched fail in some unexpected way, fixed, and triggered again until it works reliably under time pressure.
The report found that 23% of organizations with AI already in production had never tested their termination process end to end. That number is almost certainly optimistic, because “tested” in a survey response often means “reviewed in a meeting,” not “executed against a live system during a simulated incident.”
Why 27 seconds changes the math
The CrowdStrike 2026 Global Threat Report documented AI-enabled lateral movement in as little as 27 seconds in its fastest observed intrusions. Mandiant’s M-Trends 2026 report found the median time from initial access to a secondary threat group handoff fell to 22 seconds in 2025. If your kill switch depends on a SOC analyst seeing an alert, opening a ticket, and paging someone with revocation privileges, you are operating on a timeline measured in minutes against an adversary operating on a timeline measured in seconds.
This is the part that gets lost in governance conversations that stay at the policy level. An AI agent with standing access to a data store doesn’t wait for a human to notice something is wrong. It keeps executing whatever it was doing – including whatever an attacker redirected it to do – at machine speed, continuously, until something actually cuts its access.
Why the control architecture keeps failing
Most kill switches I’ve reviewed were bolted onto identity and access management systems built for human logins: rate-limited, predictable, easy to flag when something looks anomalous. AI agents don’t behave like human users. They authenticate at machine speed, they often run under service accounts provisioned once and rarely re-reviewed, and their normal behavior pattern – rapid, repeated API calls – looks identical to their anomalous behavior pattern. A detection rule tuned for human anomalies won’t catch an agent quietly expanding its own scope.
The Data Security Maturity Score in the 2026 Annual Survey Report averaged 39 out of 100 across respondents, with a companion AI Governance Maturity Score at 35 out of 100. Sixty-four percent of AI-deploying organizations had at least one AI-specific security incident in the past year. Those numbers are consistent with what I’d expect from control architectures designed for the wrong threat model.
What a real kill switch looks like
A tested kill switch means the security team has scheduled, executed, and measured a termination drill – not reviewed a document about one. It means access is scoped narrowly enough that revoking it doesn’t require untangling a web of inherited permissions. It means the revocation path doesn’t depend on a human being awake, available, and fast enough to beat a 27-second breakout window. And it means the audit log captures the drill results, because half of surveyed organizations couldn’t produce a complete AI access record within one business day of a request – a gap that turns into a regulatory problem the moment a real incident triggers one.
Sixty-three percent of organizations reported at least one compliance consequence tied to an AI governance gap in the past year. I’d rather find the gap in a drill than have a regulator find it for me.
What I’d tell any security team right now
Stop asking whether you have a kill switch. Ask when you last tested it, how long it took, and what broke. If you can’t answer those three questions with specifics, you don’t have a kill switch. You have a plan to build one, and the 79% of organizations in this report who are in that position are one incident away from finding out the hard way.

Frank Balonis is Chief Information Security Officer at Kiteworks, where he leads security operations, incident response, and compliance programs protecting sensitive data across regulated industries.


