Stay ahead of the curve with the latest news, ideas and resources on all things Identity Assurance and Passwordless.
Bill Gates Says Monitor AI. Here's What Controls Must Come Next.
Bojan Simic, CEO, HYPR
8 Min. Read | October 2, 2026
Bill Gates was interviewed on Meet the Press talking about AI kill switches. He said "it's not enough to have a kill switch," and that companies should monitor powerful AI systems and keep records of "exactly what's being done." He also drew a clear line: "The thing that's urgent has to do with bad people using AI, not the AI going off on its own."
I agree with Gates on one thing. You need visibility, and you need to be able to audit it. Every enterprise should know what agents it has, what they're doing, and exactly what they did. That's step one.
But a record of "exactly what's being done" is simply… a very detailed autopsy.
Visibility should be free. Every security team deserves to know which AI agents are running in its environment, what they connect to, and what they're doing, without paying a premium for it. Visibility is the starting line… it is not what takes enterprises to unlocking real business value.
Is the bigger AI risk bad actors or good intentions?
Gates names two risks: bad people using AI, and AI going off on its own. There’s a third, and inside the enterprise it’s the most common one: good people leveraging AI in their jobs, and getting unintended consequences that are difficult to roll back.
Here's what I hear from CISOs every week. The AI agent your best analyst uses to clear her inbox is the same agent an attacker wants to get their hands on. Same tool. Same permissions. Same tokens.
When an attacker steals an agent's token, they become that agent. Hugging Face has dealt with exposed secrets on its Spaces platform, and researchers have found more than 1,500 of its API tokens sitting in public code, some with write access to major tech companies' repositories.
When a great employee's agent goes sideways, it acts with that employee's full access. Earlier this year, Summer Yue, director of alignment at Meta's superintelligence lab, pointed an open-source agent at her email and told it to confirm before doing anything. It started deleting her inbox anyway. She told it to stop from her phone. It kept going. She had to physically get to the machine and shut it down.
Last year, SaaStr founder Jason Lemkin watched a coding agent wipe a production database in the middle of a code freeze.
To your systems, all of these look identical: a trusted identity doing something it shouldn't. You can't read intent from a log. You don't need to. The response is the same either way. Stop it.
What should AI agent visibility and auditability look like?
Gates is right to put records at the center of this. When something goes wrong, the audit trail is how you prove what happened, who authorized it, and what to fix. Your regulators will ask for it. So will your board.
The bar is higher than most teams expect. Real visibility into AI agents takes four things.
Discovery. Know every AI agent running in your environment, including the ones employees installed on their own. That means detecting agent harnesses like Claude Code, Codex, and Cursor on the endpoint and routing their traffic through a central gateway.
Identity. Bind every agent to a verified human supervisor, so every entry in the log has a name attached.
Full session detail. One agent session can spawn several subagents and run hundreds of commands. In one session from our own environment, an agent and its subagents made 121 calls, including 101 shell commands and three MCP tool calls into Jira. You need every branch, every command, and everything it touched.
Tool and MCP traffic. Agents act through tools. In a single day, our gateway evaluated more than 6,600 MCP tool calls across our own agents, each one logged against the agent, the connector, the policy, the supervisor, and the outcome.


That's the foundation. Everything else gets built on top of it.
Why isn't visibility enough to secure AI agents?
Visibility answers the question "what happened?" Security teams need to dynamically action "what happens next?"
Think about it in terms of planes. The data plane is where AI agents do their work: the tool calls, API requests, and actions they take against real systems. The control plane is where you decide what's allowed to happen there. Monitoring watches the data plane. An AI control plane governs it.
Yue's agent would have produced a perfect record of every email it deleted. Lemkin's would have logged the exact moment the database disappeared. Neither log would have saved a single file.
Agents move at machine speed. By the time someone reads the alert, the work is done. Most of the enterprises I talk to are stuck right here. They can see their agents. They can't stop them.
What does an AI control plane need?
An AI control plane sits above every AI agent and AI system in your environment. It needs three things, working together.
Policies. Every agent needs an identity tied to a named human and a defined scope: what it can touch, on whose behalf, and for how long. If you can't say which agent acted and who authorized it, your AI policy is a PDF.
Guardrails. Policy enforcement has to happen inline on the data plane, at the moment of action, outside the agent. A bulk delete, a $10,000 payment, or a production change should pause until a human approves it, with a signature that can't be faked. Yue gave her agent a guardrail when she told it to confirm first. It ignored her. A guardrail the agent can ignore is a suggestion.
A kill switch. When an agent stops acting the way it should, someone has to be able to shut it down instantly, from anywhere. Revoke its access, end its sessions, stop the action in progress. No sprint to the server room.
Visibility is also what makes control safe to roll out. A good control plane lets teams run a new policy in observe mode against live agent traffic, replay past events to test it, and see exactly what it would have blocked before switching it to enforce. That's where visibility and control meet.
Run Yue's inbox through that and the agent stops at the first batch. Lemkin's database never gets touched.
Why does agentic AI need a control plane to scale?
Every CEO I talk to wants more agents. Every CISO I talk to wants to say yes. Between them sits one question: if this agent goes sideways at 10 PM, can we stop it?
You can't put a human in front of every agent action. Five agents, maybe. Five thousand, no chance. The model that scales is what we call human above the loop. People set the rules and step in when something crosses a line. That only works if stepping in actually works.
Think about handing a teenager the car keys. You don't ride along on every trip. You set a curfew, you know where the car is, and you can take the keys back. Remove that last part and nobody hands over the keys.
That's the kill switch. It's what lets you let go.
Where we're putting our effort
This is why we built HYPR AgentPass, an AI control plane for agentic AI. Every agent is discovered, bound to a verified human supervisor, and logged down to the individual tool call. Policy enforcement happens inline. High-risk actions wait for a passkey-signed approval. And any agent can be shut down the moment it stops acting the way it should. We run our own agents on it, and the need for control showed up fast.
If you're working through this now, apply for our Private Access Program. I'd like to hear what you're running into.
Gates is right that records matter, and right that a kill switch alone isn't enough. Neither is visibility alone. Visibility should be free, because seeing what your AI agents do is step one. Being able to do something about it is the whole point.
Quick answers
What is an AI kill switch?
The ability to revoke an AI agent's access and stop its actions instantly, across every system it touches. It depends on each agent having a verifiable identity, so you know exactly what to shut off.
Is monitoring enough to secure AI agents?
No. Monitoring records what an agent did. Enterprises also need policies that define what each agent can do, guardrails that enforce them at the moment of action, and a kill switch for when an agent breaks them.
Why do bad actors and legitimate users create the same AI risk?
They use the same agents, credentials, and permissions. A stolen agent token and a misbehaving agent both look like a trusted identity doing something it shouldn't, so the same controls stop both.
What is an AI control plane?
An AI control plane is the layer that governs AI agents across an enterprise. It holds each agent's identity, defines what it can do through policy, enforces that policy at the moment of action, routes high-risk actions for human approval, and can shut any agent down instantly.
What is the difference between the control plane and the data plane for AI agents?
The data plane is where AI agents act: tool calls, API requests, and changes to real systems. The control plane decides what is allowed to happen on the data plane and enforces it. Monitoring observes the data plane. A control plane governs it.
What should an AI agent audit trail include?
Every action should record which agent acted, which human it acted for, which tool or system it touched, which policy evaluated it, and the outcome, whether that was allowed, blocked, approved, or expired.
Related Reading
- Why Enterprise AI Adoption Programs Fail Before They Begin
- You May Be Able To See Your AI Agents. Can You Stop Them?
Bojan Simic
CEO, HYPR
Bojan Simic is the Chief Executive Officer & Co-Founder of HYPR. Bojan's vision for the elimination of shared secrets and his experience in authentication & cryptography serves as the underlying foundation for HYPR technology and company strategy. Previously, he served as an information security consultant for Fortune 500 enterprises in the financial and insurance verticals conducting security architecture reviews, threat modeling, and penetration testing. Bojan has a passion for deploying applied cryptography implementations across security-critical software in both the public and private sectors. Bojan also serves as HYPR’s delegate to the FIDO Alliance board of directors, empowering the alliance’s mission to rid the world of passwords.
Related Content