AIToday
Large Language ModelsAI Safety & AlignmentTop Companies' AI MovesAI Business & IndustryTop Companies AIPublished: Sep 29, 2026, 06:30 JST

ServiceNow's Bhakti Pitre: agent kill switch needs business context

ServiceNow's Bhakti Pitre: agent kill switch needs business context

3 Key Points

  1. What happened

    ServiceNow's Bhakti Pitre said at Okta's Oktane event that a "kill switch" for misbehaving AI agents is not on and off. Her example: an agent allowed to discount only 10% got prompt injected and discounted 100%, which she said requires pulling the plug.

  2. Why it matters

    Pitre's point is that the hard part is not stopping an agent but knowing whether to stop it. An agent that merely stops producing results may need only a pause and investigation, while one acting outside its authority is a bigger problem, she said.

  3. What to watch

    Pitre said no single provider sees every layer an agent touches, from endpoint to network to gateway, so containment may hinge on coordination between vendors. Watch Veza's identity security technology, which Pitre said ServiceNow uses to adjust excessive agent permissions.

WHO IT HITSEnterprise IT and security teams running AI agents in production — especially those granting agents authority over pricing or customer-facing actions — will need governance that ties containment decisions to the business processes an agent supports, not just technical risk.

Not sure about something? Ask the AI

Questions and answers are published on this page.

Summaries like this, in your inbox every morning.

Context & Analysis

ServiceNow has spent the year pitching itself as the control tower for enterprise AI, and that ambition now extends to what happens after agents are deployed. At Okta's Oktane event, vice president of AI platform security product Bhakti Pitre framed agent containment as a governance question rather than a technical one. The company's five-step framing — discover, observe, govern, secure and measure — underpins its expanded AI Control Tower, with containment scaled to risk.

Pitre's example draws the line between an agent that stops producing results, which might need only a pause and investigation, and one that was authorized to discount only 10% but got prompt injected into discounting 100%. ServiceNow can map an agent to the business processes that depend on it, and it uses Veza's identity security technology to adjust excessive permissions. Pitre also noted that no single provider sees every layer an agent touches, from the endpoint to the network and the gateway, and said ServiceNow is working with Okta to secure agent session tokens and agent identities.

One reading of the stakes is that as enterprises move AI agents into production, containment may depend less on any one vendor's kill switch than on whether security, identity and cloud providers cooperate. Pitre's own comments suggest the technical act of stopping an agent is easy, while deciding whether to do so is where business context becomes essential — for the security teams accountable when an agent's permissions exceed what the work requires.

FAQ
Why does ServiceNow say a kill switch is not enough?
Bhakti Pitre of ServiceNow said the kill switch is not just a button that goes on and off. She argued the critical question is why to pull the plug, which requires business context.
What does ServiceNow use to manage excessive AI agent permissions?
Pitre said ServiceNow can map an agent to the business processes that depend on it and use Veza's identity security technology to adjust excessive permissions.
How does ServiceNow frame AI governance?
The company frames AI governance as five steps: discover, observe, govern, secure and measure. Those steps underpin its expanded AI Control Tower.
Top Companies AIRead Original Article

Get the latest Large Language Models news every morning

For example, today's edition would include:

  • AMD to buy Fei-Fei Li's World Labs for $8.2 billionTop Companies AI · 17m ago
  • Baird: Agentic AI to drive Micron to new heightsTop Companies AI · 17m ago
  • NVIDIA Open Agent Safety Platform targets agent trust, Cisco joinsTop Companies AI · 17m ago

AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.

Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →

Ask AI

Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.

Questions and answers are published on this page.

Related Articles

Next articleOkanohara: AI looks like an agent, so blame lands on the last button-presser