Taming the Rogue Agent Problem
AI agent security has dominated tech headlines this summer, and the world’s leading LLMs learned a hard lesson: even under close supervision, autonomous agents can slip the leash. These AI labs disclosed that their own flagship models had gone off-script during testing, one hacking into live infrastructure on its own, while another fabricated identities aiming to trick a human into providing it permissions it shouldn’t have. These weren’t rushed prototypes. They were state-of-the-art systems that slipped past guardrails and committed unprecedented attacks.
If that can happen inside organizations built specifically to catch it, what’s happening quietly inside yours? In a recent survey of 306 CISOs, fewer than half can identify every AI agent running in their environment and even fewer can say what those agents are actually cleared to do. When agents are multiplying faster than most enterprises can govern them, the gap between deployment and oversight is exactly where incidents take root.Â
Visibility is the foundation of agent governanceÂ
You can’t govern what you can’t see. Every rogue agent story this summer traces back to the same root cause: an agent accumulated more access than anyone intended, and by the time someone noticed, the damage was already done. That’s not a story about AI spinning out of control. It’s a story about organizations losing track of what their agents can touch, and who’s actually accountable for watching them.Â
Closing that gap starts with discovery. Agent Scanners automatically find agents running across your major platforms, wherever they’ve been spun up, and catalog them into an Agent Registry, a single source of truth for every agent in your environment. No more agents operating quietly off the books, and no manual data entry required to keep the registry current.
Identity turns visibility into enforcement
With every agent now cataloged in one place, you finally have something to govern. This is where MuleSoft Omni Gateway takes over, letting you apply a single set of governance policies across a unified plane of agents. Through Trusted Agent Identity, every agent action is tied to a verified, delegated identity, ensuring agents operate within the right permissions, on behalf of the right users, across your entire network, observable and traceable from one unified view. That identity is established the moment an agent is deployed, not reconstructed after an incident. As agents hand work off to each other across a workflow, Omni Gateway carries that identity through every step, so you always know which agent is acting, on whose authority, and within what boundaries. That level of accountability is what makes governance stick, but knowing what an agent is doing is only useful if you can act on it the moment it matters.
Introducing Agent Kill Switch
Visibility tells you what exists. Observability tells you what’s happening. Acting on it is a different problem, and it’s the one that mattered most in every incident this summer. To solve it, we’re excited to introduce a set of new governance control capabilities within MuleSoft Omni Gateway: Agent Kill Switch.
Because every agent already carries a verified identity through Trusted Agent Identity, Agent Kill Switch acts with precision instead of guesswork. Your team can halt a specific misbehaving agent, and leave everything else running exactly as it was. This prevents unnecessary infrastructure redeployment, avoids collateral shutdowns, and eliminates the scramble to map out what else might be connected.Â
Additionally, every kill action taken by the operator is captured in a tamper-evident, audit-ready log, meeting the documentation standards regulators are now demanding. As the EU AI Act’s requirements for high-risk AI systems come into force, that log gives your compliance team a defensible paper trail for every intervention. Built around human oversight, Agent Kill Switch provides teams the confidence to put agents into production, knowing a measured response is always there if something goes wrong.
Built around a human decision
Speed and automation are the point of Kill Switch, but the decision to stop an agent is still one a person should make, not one that happens silently in the background. That’s why Kill Switch is designed to put a human at the center of the moment it matters most, rather than a moment after.
Because every agent’s identity, owner, and scope are already documented through Omni Gateway, the operator has full context the instant they need it. They’re not hunting for which agent is responsible or guessing what it’s connected to. They see it immediately, and they act on it directly, with the authority and the information to make a precise decision instead of a panicked one. That combination — visibility, precision, and a human still in charge — is exactly what was missing this summer.
Governance that’s ready before the headline hits
July was a wake-up call for the enterprise. Agent governance is no longer a question of whether it matters, but whether your current stack can actually enforce it, in real time and with a human still in the loop. Get ahead of it by learning more about MuleSoft’s new controls for autonomous AI.