
What happened
ServiceNow's Bhakti Pitre said at Okta's Oktane event that a "kill switch" for misbehaving AI agents is not on and off. Her example: an agent allowed to discount only 10% got prompt injected and discounted 100%, which she said requires pulling the plug.
Why it matters
Pitre's point is that the hard part is not stopping an agent but knowing whether to stop it. An agent that merely stops producing results may need only a pause and investigation, while one acting outside its authority is a bigger problem, she said.
What to watch
Pitre said no single provider sees every layer an agent touches, from endpoint to network to gateway, so containment may hinge on coordination between vendors. Watch Veza's identity security technology, which Pitre said ServiceNow uses to adjust excessive agent permissions.
WHO IT HITSEnterprise IT and security teams running AI agents in production — especially those granting agents authority over pricing or customer-facing actions — will need governance that ties containment decisions to the business processes an agent supports, not just technical risk.
Summaries like this, in your inbox every morning.
ServiceNow has spent the year pitching itself as the control tower for enterprise AI, and that ambition now extends to what happens after agents are deployed. At Okta's Oktane event, vice president of AI platform security product Bhakti Pitre framed agent containment as a governance question rather than a technical one. The company's five-step framing — discover, observe, govern, secure and measure — underpins its expanded AI Control Tower, with containment scaled to risk.
Pitre's example draws the line between an agent that stops producing results, which might need only a pause and investigation, and one that was authorized to discount only 10% but got prompt injected into discounting 100%. ServiceNow can map an agent to the business processes that depend on it, and it uses Veza's identity security technology to adjust excessive permissions. Pitre also noted that no single provider sees every layer an agent touches, from the endpoint to the network and the gateway, and said ServiceNow is working with Okta to secure agent session tokens and agent identities.
One reading of the stakes is that as enterprises move AI agents into production, containment may depend less on any one vendor's kill switch than on whether security, identity and cloud providers cooperate. Pitre's own comments suggest the technical act of stopping an agent is easy, while deciding whether to do so is where business context becomes essential — for the security teams accountable when an agent's permissions exceed what the work requires.
For example, today's edition would include:
AI-summarized, only the topics you pick: one digest a day via Email, LINE, or Slack.
Free · 30 seconds with Google · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. The AI reads this article, earlier AIToday articles, and Wikipedia, and cites its sources. Q&As are published on this page for other readers too.
Kalkine Media reports that Home Depot (NYSE:HD) is introducing an AI assistant for its retail operations

Daniel Roher's Netflix documentary 'The AI Doc: Or How I Became an Apocaloptimist' presents both AI safety exp…

NVIDIA announced the NVIDIA Open Agent Safety Platform, an open software platform and reference design to secu…

AMD said Monday it agreed to acquire World Labs, Fei-Fei Li's San Francisco AI lab, for about $8.2 billion in…

Bank of America announced Payments Insights, a new CashPro capability that analyzes payment efficiency, cross-…

NVIDIA announced its NVIDIA Open Agent Safety Platform, combining OpenShell open-source software for secure ag…
