An agent has been sorting supplier invoices for eight months. One Monday someone notices it’s coding one type of expense wrong, and the reaction is instant: “let’s switch it off.” It takes ten seconds. Then comes the question nobody asked: who does this by hand? The person who used to do it moved roles in March, the procedure was “whatever she knew,” and a week’s volume doesn’t fit into one afternoon.
The thesis in one line: switching an agent off is a button; disconnecting it without stopping the process is a plan, and almost nobody designs one because an exit plan feels like pessimism. By month six the process no longer knows how to run without the agent, and at that point “suspend” and “halt the business” mean the same thing.
How to disconnect an AI agent: the exit plan nobody designs
The launch gets designed carefully: scope, permissions, testing. The exit is left for “we’ll figure it out.” A real exit plan has three parts, and all three have to exist before the incident:
- The manual step, documented and practiced. Not “someone will do it”: who, with what access, following which instructions and at what volume.
- The threshold that triggers disconnection. A condition written in advance, not an improvised meeting while the agent is still answering.
- Who pulls it. A named person authorized to act without asking permission from three other people.
Why the process stops knowing how to run without the agent
It’s a mechanism, not carelessness. While the agent does the task, the team stops doing it; once they stop doing it, they stop maintaining the judgment: the exceptions, the customers who fall outside the norm, the shortcut only one person knew. That knowledge doesn’t vanish overnight, it evaporates. What survives lives inside the agent’s instructions, which are not a manual for humans.
Three signs you’ve already reached that point: nobody on the team has run the manual step in months, the access it needed was revoked when it was “no longer needed,” and nobody knows how much volume one person could handle. If any one of them is true, switching the agent off is no longer a reversible option, even though the button works.
What the manual step has to spell out
- The steps and their exceptions, written by whoever knows them, not reverse-engineered from the agent’s instructions.
- Live access. The accounts, permissions and tools the manual process needs, checked rather than assumed.
- Real capacity. How much volume fits by hand and what gets priority when it all can’t; that call gets made now, not at six in the evening.
- The rehearsal. A periodic drill where a person runs the manual step on real cases. A procedure that has never been executed is a hypothesis.
The first rung of the exit is almost never “off”: it’s dropping autonomy to “the agent proposes, a person sends.” That’s only possible if you defined a scale of autonomy levels for an AI agent before you needed it.
When to disconnect: a written threshold, not a meeting
A threshold turns a debate into an action. It doesn’t have to be numeric; it has to be unambiguous and have an owner:
| Signal | Disconnection | Who decides |
|---|---|---|
| An error that touches money, a deadline or a specific customer | Partial: remove the tool that caused it or lower autonomy | Process owner |
| Sustained drift in the quality metric that defines success | Intermediate: move to “proposes, a person sends” until reviewed | Process owner, with weekly review |
| An action outside its scope or access it should never have had | Full and immediate, no meeting | Whoever holds the switch |
| Reasonable doubt that its use could create a legal risk | Full until clarified, plus notifying whoever needs to know | Leadership, with legal input |
Detection can be automated, for example with a supervisor agent that checks the one doing the work, but what gets disconnected and how far is a decision a person sets before it happens.
What does the EU AI Act say about suspending an agent?
Article 26(5) of Regulation (EU) 2024/1689 requires the deployer of a high-risk system who has reason to think its use may present a risk to inform the provider and the market surveillance authority without delay, and to suspend use of the system (Article 26 on the European Commission’s official AI Act portal).
Two caveats. First, the obligation applies to high-risk systems; many business agents aren’t, and for them this is good practice, not a mandate. Second, the rule requires being able to suspend, not how to do it without breaking anything: suspending with no reversion plan is halting the process and leaving the problem to whoever has to work by hand that afternoon.
Is disconnecting an agent the same as retiring it?
No, and mixing them up causes mistakes. Disconnecting is temporary and reversible: the agent, its credentials and its history stay in place, and a person takes over the work while the problem is fixed. Retiring is permanent: permissions are revoked, the log is archived and you decide what happens to whatever the agent had open. Disconnection should take minutes; retirement can take its time. Everything that governs both, from permissions to the log, is in governance and control of AI automation.
Exit checklist before an agent goes to production
| Question | If the answer is “no” |
|---|---|
| Is the manual step written down, with its exceptions? | The process can’t survive the agent |
| Has anyone run it on real cases in the last few months? | It’s a hypothesis, not a plan |
| Is the access needed to do it still active? | The exit is closed even though the button works |
| Is there a written threshold and a person authorized to act? | It’ll be decided in a meeting, with the agent still answering |
| Do you know how much volume one person can handle and what takes priority? | Switching it off means losing whatever doesn’t fit |
Who responds, with which severities and from which runbook is covered in who responds when an automation goes down. And if you’d rather not build or staff that function yourself, it’s what we cover with AI agent incident management.
The line to take away: an agent you can’t switch off is a risk, but one you switch off while nobody can do its job is the same risk with a button.