AIToday
Large Language ModelsAI Safety & AlignmentAI Business & IndustrySiliconANGLE AIPublished: Sep 29, 2026, 06:00 JST

ServiceNow's Bhakti Pitre: rogue AI agents need risk-based kill switch

ServiceNow's Bhakti Pitre: rogue AI agents need risk-based kill switch

3 Key Points

  1. What happened

    Bhakti Pitre, ServiceNow's VP of AI platform security product, said at Okta's Oktane event that agent "kill switch" is not just on and off. She cited an agent authorized to discount 10% that got prompt injected and began discounting 100%.

  2. Why it matters

    ServiceNow is framing AI governance as five steps — discover, observe, govern, secure and measure — and says containment should scale with risk, so companies are pushed to weigh business impact before cutting an agent off.

  3. What to watch

    Pitre says no single provider sees every layer an agent touches, so ServiceNow is working with Okta on agent session tokens and identities. The test is whether vendors cooperate, which Pitre said requires being "each other's friends or frenemies."

WHO IT HITSThis lands on security and IT governance teams at enterprises that have already moved AI agents into production, plus the identity and endpoint vendors they rely on. It suggests those teams may need to define agent permissions and containment thresholds before granting agents authority over pricing or other business actions, based on the discount scenario Pitre described.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

ServiceNow has spent the year pitching itself as the control tower for enterprise AI, and agent containment is the latest piece of that pitch. The company's argument, as laid out by vice president of AI platform security product Bhakti Pitre at Okta's Oktane event, is that governance does not end at deployment. ServiceNow frames the work as five steps — discover, observe, govern, secure and measure — and says containment should scale with risk. Pitre's contrast between an agent that simply stops producing results and one that was authorized to discount only 10% but, after prompt injection, began discounting 100%, is the concrete illustration of that scale: one case calls for a pause and investigation, the other for pulling the plug.

The harder half, in Pitre's telling, is knowing why to act, not just how. ServiceNow maps an agent to the business processes that depend on it and uses Veza's identity security technology to adjust excessive permissions, which is meant to supply the business context for that decision. Pitre also said no single provider sees every layer an agent touches, from the endpoint to the network and the gateway, and that ServiceNow is working with Okta on agent session tokens and identities.

What the outcome hinges on may be that cross-vendor cooperation. Pitre's remark that the industry needs to be "each other's friends or frenemies" suggests the containment question is likely to be settled less by any one product than by whether platforms and identity providers can cover the layers between them. For enterprises already running agents in production, the practical stake is whether they can define risk thresholds and permission limits before an agent goes beyond what it was authorized to do.

FAQ
What does ServiceNow mean by a kill switch for AI agents?
Bhakti Pitre said the term shouldn't imply an on/off button. She said the response should scale with risk, so an agent that only stops producing results may need a pause and investigation, while an agent acting well outside its authority needs to be shut down.
What is ServiceNow's five-step approach to AI governance?
Pitre described the steps as discover, observe, govern, secure and measure. She said those steps underpin ServiceNow's expanded AI Control Tower.
How is ServiceNow handling agent permissions?
Pitre said ServiceNow can map an agent to the business processes that depend on it and use Veza's identity security technology to adjust excessive permissions. ServiceNow is also working with Okta to secure agent session tokens and agent identities.
SiliconANGLE AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • Meta taps CJ Desai to lead new enterprise AI unitSiliconANGLE AI · 21m ago
  • 1Password ties AI agent access to individual tasksSiliconANGLE AI · 21m ago
  • Agentic AI uses 10 to 100 times more tokens per task: FuturumSiliconANGLE AI · 21m ago

AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleClaude Code's Boris Cherny: Black-box AI code OK only for prototypes