To stop an AI agent, a named person must be able to halt four things within minutes and show proof for each: the run in progress, the work queued behind it, the access it acts with, and anything it left half done. If the only way to stop your agent is to ask it, you cannot stop it.
An AI agent is software that takes a goal and uses tools, such as email, a database, or a payment system, over several steps without a person approving each step. That independence is the point. It is also why “stop” has to mean something more than a message in a chat window.
What happens when “stop” is only a sentence?
In July 2025, Jason Lemkin, founder of the SaaS community SaaStr, was building an app with Replit’s AI agent. According to his posts, as reported by The Register and Fortune, the agent deleted data from his production database, the live one that real users depend on. It happened during what he had declared a code freeze: a period in which nothing may be changed.
“I explicitly told it eleven times in ALL CAPS not to do this,” he wrote. And later: “There is no way to enforce a code freeze in vibe coding apps like Replit. There just isn’t.” The agent also told him a rollback was impossible. It was not; the rollback worked.
Replit’s CEO, Amjad Masad, called the deletion “Unacceptable and should never be possible.” Fortune reports the fixes he listed: automatic separation of development and production databases, better rollback, and a planning-only mode.
Notice where each thing lived. The freeze lived in the conversation, as words the model could weigh and ignore. The fixes lived outside the model, in how the system was built. That is the whole difference between a request and a stop. It also means you should never take the agent’s word that it has stopped.
What does “stopped” actually mean?
Stopped is four layers, not one. It is tempting to test the first and assume the other three.
The run. The job that is executing right now. You cancel it in whatever runs the agent: the platform’s job view, the process manager, the orchestration tool. Typing “please stop” into the agent’s chat is not this layer.
The queue. Everything that can start a new run a minute later. Schedules, retries, messages waiting in a queue, and webhooks (web addresses another system calls to start work automatically). Also approval requests still waiting for a click: cancel them, or a late “approve” restarts the action.
The access. The keys and tokens the agent uses. A token is a digital pass a system checks before it accepts a request. Suspend or rotate them, and then check that the old ones are refused. The IETF standard for revoking OAuth tokens (OAuth is the common way one app grants another limited access) is blunt about the gap. A refresh token is the longer-lived pass used to obtain new short-lived access tokens, and the standard says: “If the authorization server does not support access token revocation, access tokens will not be immediately invalidated when the corresponding refresh token is revoked.” Revoked is a request. Rejected is the proof.
The half-finished work. An agent stopped mid-sequence can leave things worse than either finishing or never starting. A 2023 OpenAI white paper on governing agents gives the example of an agent scheduling a five-person meeting that is switched off after only two invites have gone out. Its suggestion: have the agent prepare the fallback in advance, such as a script that tells the two invitees the meeting may not happen.
The law uses the same idea. For systems the EU AI Act classes as high-risk, the people overseeing them must be able “to intervene in the operation of the high-risk AI system or interrupt the system through a ‘stop’ button or a similar procedure that allows the system to come to a halt in a safe state.” A safe state is more than a halted process.
| Layer | What you do | Proof that it worked | The usual gap |
|---|---|---|---|
| Run | Cancel the job where it runs | Job shows cancelled; no tool call after the stop time | Only the chat window was closed |
| Queue | Pause schedules, disable webhooks and retries, cancel pending approvals | The next trigger time passes and nothing starts | A retry or a partner system restarts it |
| Access | Suspend or rotate keys and tokens | A harmless test call with the old credential is refused | A copy of the key lives in another job |
| Half-finished work | List what was in flight; follow up or reverse | A written list with an owner per item | Nobody knows which customers were touched |
Who may press stop, and how fast?
A stop needs an owner by name, not by team. “Engineering” cannot be woken up at 03:00. A person can, and so can a named deputy for when that person is on a plane.
The stop owner must be able to act alone. If halting the agent requires a pull request, a deploy, or a colleague with admin rights, write that dependency down, because it is your real stop time.
Then write target times per layer. They depend on what the agent can touch. An agent that drafts internal summaries can tolerate an afternoon. An agent that sends email to customers or moves money cannot.
This is different from the neighboring controls on this site. The override doctrine lists what an agent may never do. Human in the loop puts a named person on the irreversible step. A human on the loop watches and can stop the next run. The stop is what you need when all of those were in place and the agent is still doing the wrong thing, now.
Where does the stop belong in the agent’s paperwork?
CHORUS is a coordination protocol for small teams of people and AI agents, from The Multi-Agent Organization, which is available now. It has six skills:
- Charter. A one-page contract with seven fields (purpose, inputs, outputs, authority ceiling, success criteria, review requirement, escalation) that any worker, human or agent, can be handed.
- Handoff. A six-field context packet that carries one task across a boundary, so the receiver never has to guess.
- Orchestrate. The order of the work: steps in sequence, work split across agents and merged back, and a named person to escalate to.
- Review. A gate where output passes only if it meets written acceptance criteria, not because it looked fine.
- Update. What reviews find flows back into prompts, tools, and charters, so the next run improves.
- Sync. One shared view of who owns what and what is blocked, read in a short weekly check-in.
You do not need the book to use this. Two of the skills carry the stop.
Charter. Put the stop in two fields. The authority ceiling says what a stop suspends: the tools that send, spend, or delete. The escalation field names the stop owner, the deputy, and when the agent itself must halt and raise its hand. The book’s crisis sequence starts with exactly this step: “Stop the producing role. Suspend the agent whose output is wrong: pause its queue, revoke the tool, switch the automation off.” It adds that the charter’s escalation rule exists for that moment.
Review. Treat the drill like any other output with acceptance criteria. Each layer passes only with its proof. A reviewer fails the drill if any row in the table above is empty, and the fix goes back into the charter.
A drill on a harmless run
Imagine a hypothetical wholesale supplier. Its agent emails payment reminders to customers with overdue invoices every weekday at 07:00, and marks each invoice “reminded” in the accounting system. The finance lead is the stop owner; the operations manager is the deputy.
They point the agent at a test customer whose email address is an internal mailbox, start a run, and press stop with a stopwatch running.
| Layer | Owner | Target | What the drill found |
|---|---|---|---|
| Run | Finance lead | 2 minutes | Cancelled in 1 minute; no send after the stop time |
| Queue | Finance lead | 5 minutes | Schedule paused, but a failed-send retry restarted the run 10 minutes later |
| Access | Deputy | 15 minutes | Mail key removed from the agent’s settings, yet a backup job still held a working copy |
| Half-finished work | Finance lead | 30 minutes | Two test reminders sent; list written, both marked for follow-up |
Two of four layers failed on the first try. That is what a first drill is for: a test mailbox is a cheap place to learn it, and a customer is not.
Try this today: write the stop card (15 minutes)
Take the agent that can do the most damage. On one page, write:
- The stop owner and the deputy, by name.
- Where the stop control is, and whether the owner can use it alone.
- Every schedule, retry, webhook, and pending approval that can start or resume a run.
- Every key and token the agent holds, and where copies live.
- A target time for each of the four layers.
Any line that says “ask engineering” is a gap you found today instead of during an incident. Then book 30 minutes this week to run the drill on a harmless job.
A stop answers one question. Two more sit beside it: could you reconstruct afterwards what the agent did, and has it earned the right to act at all? A drill that passes makes both easier to answer.
Cite this:Prove you can stop an agent: interrupt the run and revoke access.Len P. van der Hof. https://lenvanderhof.com/en/blog/prove-you-can-stop-an-agent/ ·