Turning off a model and stopping an action are different controls
On 11 September 2026, the UK Government rejected calls for a statutory emergency mechanism intended to shut down a dangerous autonomous AI model.
A Cabinet Office spokesperson was reported as saying that Britain ‘cannot simply turn AI off’. Restricting access inside one country would not prevent a model from being developed or misused elsewhere.
That objection exposes an important distinction.
Turning off an AI model and stopping an AI-generated action are not the same control.
The ‘kill switch’ describes several different problems
The term ‘AI kill switch’ can refer to shutting down a model, suspending a hosted service, removing an agent's authority or preventing a particular action.
Those interventions operate at different layers.
A government might be unable to disable a model running across infrastructure and jurisdictions it does not control. An organisation can still determine whether that model—or an agent using it—is authorised to release a payment, deploy software, change a machine instruction or enter a restricted environment.
The operational question is narrower: may this proposed action create this consequence, in this context, now?
That is a point-of-use authority question.
Stop the Line does not mean shutting down AI
Within PF Systems, Stop the Line should not be described as a general mechanism for switching off an AI model.
It is a PF Kernel outcome that prevents a specified consequential action from proceeding through the governed execution boundary when continuation cannot be authorised.
The underlying model can remain available. The agent can remain online. Unrelated workloads do not necessarily stop.
The scope of the intervention should match the scope of the authority that has been withdrawn or can no longer be established.
- One proposed action can be stopped while the agent continues performing authorised work.
- One agent's authority can be withdrawn while another authorised agent continues.
- An action class, such as external payments, can be suspended while analysis and read-only operations remain available.
Revocation must come from outside the agent
An agent should not be the final authority over whether its own authority remains valid.
Where an authorised person or system revokes authority, the affected agent must not be able to restore that authority itself. Nor should it be able to reach the same prohibited effect through a different credential, tool or execution path.
This is an architectural requirement, not something that can be established by an instruction inside the model.
If an agent can route around the control, the control is not the effective boundary.
Evidence must show what stopped—and what continued
A useful record should distinguish the requested action, the agent and authority involved, the source of any revocation, the decision returned by PF Kernel, the effect that was prevented and the authorised activity that remained available.
PF Systems separates these responsibilities deliberately: PF Memory knows. PF Core proves. PF Kernel decides.
PF Memory supplies governed knowledge and context. PF SecureAuth can provide approval or delegated-authority proof. PF Kernel evaluates the proposed action, while PF Core preserves linked evidence of the governed evaluation. ClientBridge connects to the protected environment and PF Trace displays the evidence it receives.
Evidence that an action was stopped does not independently prove every physical or operational outcome. Trusted evidence from the executor or affected system is still required.
Point-of-use control is not model control
The UK Government has previously stated that most AI systems should be regulated at the point of use. That regulatory position does not prescribe PF Systems' architecture or endorse any particular technical mechanism.
It does, however, reflect the importance of context. The same model may support low-consequence analysis in one environment and initiate material financial, software or physical actions in another. Its capability has not changed, but the authority and consequences have.
PF Systems does not claim to make probabilistic AI deterministic, eliminate AI risk or replace provider-level security and emergency controls. Nor does action-level governance prove that model-level shutdown powers are never required.
It addresses a different part of the problem: preventing an AI-generated proposal from becoming an unauthorised consequential effect.
You do not need to claim control of an AI model everywhere to govern what it is permitted to do somewhere.
Sources
Public sources supporting the factual statements in this perspective. Reported statements and company or vendor-reported results are identified in the article.
