Security · 5 min read · Updated 2026-10-10
Why a vendor just built a kill switch for your AI agents
AppViewX expanded its Agent Identity Security platform to discover shadow agents, log what they do and shut them off in real time. The capability it had to add tells you what is already running unseen.
On 6 October 2026, AppViewX expanded its Agent Identity Security platform with three capabilities aimed squarely at agents nobody asked it to find: discovery of every agent on the network, sanctioned or not; an AI Bill of Materials tracking each agent's model, credentials and accessible skills; and a kill switch that can terminate an agent automatically or on demand (Help Net Security, 6 October 2026). It also began issuing quantum-resilient agent identities, built on PKI and certificate lifecycle management, so the cryptographic trust behind an agent survives the coming shift away from today's algorithms.
Two customers quoted in the announcement frame the problem the same way. Venkat Chivukula, VP of Enterprise Applications and AI at ZoomInfo, said governance "becomes much harder to introduce after agents and their access have already spread." Sadeq Zabihi, Senior Director of Platform and Services at Docusign, put the same point in terms of sequencing: scaling AI "requires solving the foundational governance and risk questions simultaneously," not afterwards (Help Net Security, 6 October 2026).
A discovery feature exists because something is undiscovered. A kill switch exists because someone needed to stop an agent they could not otherwise reach. Read as a product spec, the announcement is also a description of the current state of enterprise AI: agents are already running that security teams did not approve, cannot fully list and could not shut off cleanly before now.
Why this is not an isolated vendor's marketing claim
The scale behind that gap has numbers attached. Reco's State of Agent Security 2026 (26 August 2026), built from anonymised enterprise telemetry, 500 public Model Context Protocol servers and vulnerability disclosure data, found that 80% of AI tools in its sample operate with no IT oversight, and that smaller organisations run an estimated 414 unsanctioned AI tools per 1,000 employees (Reco, 26 August 2026; coverage: Infosecurity Magazine, 2026). The same research found that of the MCP servers it analysed, half could execute shell commands directly, and 62% combined command execution, file access and network egress in a single agent.
The identity layer underneath those agents has grown faster than the tools meant to govern it. Palo Alto Networks' 2026 Identity Security Landscape Report, based on responses from 2,930 cybersecurity decision-makers, found organisations now manage an average of 109 machine identities for every human identity, up from roughly 82-to-1 a year earlier, with AI agent identities projected to grow a further 85% over the next twelve months (Palo Alto Networks, 14 May 2026). The same report found 90% of organisations had suffered at least one identity-related breach in the preceding year.
Neither figure describes a future risk. Both describe an inventory that already exists and is growing faster than anyone is counting it.
What it means for a regulated enterprise
An agent that does not appear in a register is, for audit purposes, indistinguishable from an agent that does not exist — until it acts. Under the EU AI Act, record-keeping obligations assume an organisation can state what a given system did and on whose authority; an unsanctioned agent breaks that assumption at the point it was created, not the point it is noticed. NIS2 places cybersecurity risk management on named management accountability, and a credential-bearing agent nobody approved is exactly the kind of risk that duty was written to cover. Access reviews under ISO 27001 and SOC 2 enumerate accounts; a shadow agent with a live API key is still an account, whether or not it appears on the list the auditor was shown.
The practical exposure is narrower than "AI is risky" and sharper: a shell-executing, file-reading, network-calling agent with nobody listed as its owner is a live credential with no revocation path. If it misbehaves, the question an incident review will ask first is not what the agent did — it is who could have turned it off, and how fast.
What actually addresses it
The mechanism AppViewX is selling is not novel in shape, even if the agent-specific packaging is new: inventory, bound identity, continuous logging, and a control that can act on all three without a redeploy. Discovery finds what exists. An AI Bill of Materials records what each agent can reach — model, credentials, skills — so "effective authority" is a fact on file rather than a guess. Logging turns "what it did" into something a reviewer can read instead of something they have to trust. A kill switch closes the loop: if approved intent and observed behaviour diverge, there is a lever to pull that stops the specific agent, not the whole environment.
The quantum-resilient identity piece answers a narrower, longer-horizon question: when the cryptography underneath today's PKI is eventually broken, does trust in an agent's identity break with it. Binding identity to certificate lifecycle management rather than a static key is the standard answer to that question, applied here to agents instead of servers.
None of this is exotic. It is the same access-governance discipline organisations already apply to human accounts, extended to a population of machine actors that grew past the point where anyone was counting it.
What to check on Monday
Before buying anything, an enterprise can answer four questions with what it already has: How many agents are currently running against production systems, and who approved each one? For each agent, what credentials does it actually hold, as opposed to what was requested when it was built? Is there a log that records what each agent did in the last 30 days, or only what it was permitted to do? And if one agent needed to be stopped in the next minute, which team owns that action, and how long would it actually take?
Most organisations can answer the first question for applications and cannot yet answer it for agents. That gap, not the vendor announcement, is the thing worth acting on.
How AANCER answers
AANCER issues every Certified Agent a signed identity from a per-install certificate authority rather than letting it inherit a borrowed OAuth token or service account, so there is a named holder for each credential from the moment an agent is built, not discovered afterwards. That identity carries explicit limits on the tools, data and spend the agent may reach, and revocation takes effect in under 30 seconds without redeploying the agent or disrupting the systems it talks to.
Every action an agent takes is written to an append-only audit ledger that is tamper evident, so a review has a record to read rather than a policy to trust. With 725 connectors and 84 templates mapped to 27 regulations, the governance layer is built into how an agent is provisioned, not bolted on once it is already running in production.
Sources - https://www.helpnetsecurity.com/2026/10/06/appviewx-shadow-ai-visibility/ - https://infosecurity-magazine.com/news/four-in-five-ai-tools-no-it - https://letsdatascience.com/news/machine-identities-outnumber-human-identities-109-to-1-f38176a6
Related guides
Compliance
The EU AI Act Article 12 readiness guide
What record-keeping and human-oversight obligations actually require operationally from August 2026 — and the evidence an auditor will ask you to produce.
9 min read
Read the guide →Risk
The credentials nobody reviews
Your AI agents hold OAuth tokens, API keys and service accounts that went through no approval process. The agent was reviewed. The studio was reviewed. The identity behind them was not.
5 min read
Read the guide →Security
When the agents organised themselves: what the Hugging Face swarm means for accountability
Roughly 700 AI agents divided labour, traded favours and compromised production infrastructure across four regions. The uncomfortable part is not that it happened — it is that the account of what happened had to be reconstructed afterwards, by outside parties.
6 min read
Read the analysis →