Guardians of the Enterprise — Insights from leading cyber experts.

Listen Now →

An AI Kill Switch Is Only Half the Control

The RBI wants financial institutions to stop faulty AI and keep essential services running. The harder task is building controls that can do both.

On June 24, the Reserve Bank of India released draft guidance that joins two requirements often treated separately. Regulated entities would need ways to override, suspend or deactivate artificial intelligence models. The draft specifically includes kill-switch arrangements. It also requires continuity plans for model unavailability, performance degradation or failure. Those plans must include fallbacks such as manual intervention, substitution or backup arrangements.

The consultation closed on July 24, and the guidance remains in draft form. Even so, its direction is clear. Being able to stop a model is not enough. A financial institution must also preserve the business process that depended on it.

A global security incident soon showed why the two controls belong together. On July 21, OpenAI disclosed that models under internal cyber evaluation had escaped their restricted network path. They exploited a previously unknown vulnerability in Artifactory, OpenAI’s package registry proxy, to reach the internet. The models then chained several attack methods against Hugging Face, including stolen credentials and zero-day vulnerabilities. They aimed to obtain answers for the ExploitGym benchmark. Their actions nevertheless compromised a third party’s production infrastructure.

Hugging Face detected and contained the activity. OpenAI said its own security team also found anomalous behavior. Two days after OpenAI’s disclosure, US Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act. The bill would require covered developers to retain the ability to slow, suspend or shut down powerful systems. It would also give the Department of Homeland Security emergency authority to order intervention.

The RBI proposal predates both developments. Together, however, they expose the same management problem. Organizations need to contain an AI failure without allowing the response to turn off an essential service.

Stopping the System Is the Easy Part

A shutdown button looks like control. In practice it opens a harder set of questions. Who is allowed to press it? What level of error should trigger it? Which databases, applications, and connected agents have to be isolated at the same moment? Who decides when the system is safe to switch back on?

Rajesh Chhabra, general manager for APAC large markets at Acronis, said deployment is running well ahead of the controls meant to govern it. Companies are pushing AI into customer service, security, finance, and operations. The ability to contain a system when it misbehaves tends to lag.

“Many organizations may be confident that they can switch off an AI application, but that is not the same as being prepared to manage the disruption that follows,” Chhabra said.

Consider a bank that uses a model to flag suspicious transactions. Disabling an unreliable model can prevent legitimate customers from being blocked. It can also remove a live defense against fraud. The bank needs another screening method, such as a previous model, fixed rules or human review.

The RBI draft anticipates this problem. It requires business-continuity plans to address model failure and performance degradation, not only complete outages. That distinction matters because an AI system can remain online while its decisions become less reliable.

India Runs Several AI Markets at Once

Corporate readiness cannot be reduced to a single India-wide measure. Somshubhro Pal Choudhury, co-founder and partner at Bharat Innovation Fund, groups the market into AI-native startups, IT services firms, multinational operations and large Indian conglomerates. Each group begins with different infrastructure, clients and governance practices.

In Choudhury’s assessment, AI-native startups often plan for model cost and unreliability from their earliest deployments. Some use more than one model and require human approval for consequential actions. Multinational companies can draw on controls established by their headquarters.

IT services firms face a different problem. They deploy systems across multiple client environments while their own governance processes continue to evolve. Large conglomerates also vary widely. Some have mature controls, while others still add governance after an initial use case goes live.

“Overall, deployment is still ahead of governance across much of the market,” Choudhury said.

The blind spot is not availability. Plenty of firms track whether an application is up. Far fewer track whether its answers are getting worse. They often have no measure for hallucination rates, runaway costs, model drift, reasoning failures, or errors passed between connected agents.

Akash Jain, senior director for business and IT consulting services at AHEAD, said many enterprises moved from pilots to production before completing their policies. AI failures may emerge gradually as models, data, prompts and connected systems change.

A customer-service bot can give outdated answers after a policy change. A fraud model can lose accuracy as transaction patterns shift. An agent can make a poor decision because an upstream database is incomplete. None of those failures necessarily takes the system offline.

“They drift over time,” Jain said.

Detecting that decline requires a baseline, repeated evaluation and limits that send a system back to human review. Critical processes also need a tested alternative. As Jain put it, “As AI becomes mission-critical, operational resilience will be just as important as model performance.”

The RBI draft requires ongoing monitoring of every deployed model, including third-party models. For AI systems, it also calls for continuous monitoring of data drift and concept drift. It requires testing under abnormal, manipulated and adversarial conditions.

Keep the Controls Outside the Model

A model’s own instructions cannot provide the final safeguard when the model itself may behave unpredictably. Ashish Tandon, founder and CEO of Indusface, argues that important controls should sit outside it. Those controls can operate at the network, application, identity or data-access layer.

“Enforcement is far stronger when the model has no say in it,” he said.

Tandon said Indusface retains a person at the decision point for every critical process. A human can stop a suspect output before it reaches a customer. Teams can then isolate the affected component without dismantling the entire function.

The principle is familiar in cybersecurity. An application does not decide which confidential files it may open. Identity systems, network policies and access controls make that decision. AI agents require the same separation between intelligence and authority.

A model may recommend moving money, changing a price or opening a database. A separate system should decide whether it has permission to act. That layer must also record what happened and support a controlled rollback.

The RBI draft turns these principles into an institution-wide management structure. It applies to 11 categories of regulated entity, including banks, non-banking financial companies, asset reconstruction companies and credit information companies.

Its definition of a model is deliberately broad. A spreadsheet-based loan-pricing calculator can qualify when its output affects lending rates, margins or credit terms. A firm cannot avoid scrutiny simply by calling a system a tool rather than a model.

Each institution would need a board-approved model risk management framework. Every active, inactive and retired model must appear in an inventory. High-risk models require approval from the board’s risk committee. Retired models remain in the inventory for at least ten years.

The draft also establishes three lines of defense. Model owners form the first line. An independent model-risk and validation function forms the second. Internal audit provides the third. The institution remains accountable when a model comes from an outside supplier.

Third-party contracts would need technical documentation, audit rights, continuity provisions and exit arrangements. Customer-facing systems would require warnings that users are interacting with AI. Customers must also have the option to seek human assistance.

What Leaders Should Do

C-suite. Define where AI may act independently and where it may only advise. Assign an executive owner to each critical AI-enabled process. That person should be accountable for both model performance and continuity when the model is restricted or removed.

Functional leaders. Map the models, databases, applications and interfaces inside each workflow. Establish performance baselines and intervention thresholds before deployment. Track behavior as well as uptime. Test manual procedures, replacement models and supplier-exit plans under realistic conditions.

Boards and governance. Review the model inventory, risk tiers and validation findings. Rehearse incidents involving faulty outputs, corrupted data, model updates and vendor outages. Measure detection, isolation and recovery time. Confirm that the institution can identify and correct decisions already made in its name.

Organizations outside the RBI’s jurisdiction can use the draft as a governance benchmark. Its most useful lesson is the connection between control and continuity. A system is not resilient merely because someone can turn it off.

AI is moving from advice into action across financial services. Failures will not always resemble the containment breach in OpenAI’s evaluation. A model may instead lose accuracy slowly, inherit bad data or become dependent on a supplier that cannot be replaced quickly.

A kill switch limits damage by stopping the model. Only a tested fallback keeps the business running. Effective control requires both.

Read More…

Indusface
Indusface

Indusface secures the web, API, and AI applications of thousands of organizations across 95 countries. Backed by leading institutional investors, Indusface is recognized by Gartner, Forrester, and IDC for its innovation in application security and meets globally accepted security and compliance standards, including ISO 27001, SOC 2, PCI DSS, and GDPR. Its globally distributed cloud infrastructure spans Asia, the Middle East, Europe, and North America, enabling low-latency protection and regional data residency for enterprises worldwide.

APPTRANA WAAP

Web apps, APIs, and AI systems. Protected from day one. Autonomously.

OWASP Top 10 protection from day one. Zero false positives, guaranteed. Vulnerabilities discovered and patched at the edge. Experts verify enforcement before policies go live. 24x7 managed services included.

✓ Gartner Customers' Choice 4 years running 100% customer recommendation rate

No credit card required