TwinEthosRequest access

Control

No override/decommission mechanism for deployed AI

Deployed AI should have monitoring plus the ability to appeal, override, disengage, or decommission it.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Family: AI decisions lack effective human review, override, or contest · control id cond.no-override-or-decommission-mechanism

Reach

1items this one guard addresses
0jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
1standards and frameworks on the same control

The guard to add

Check a runtime kill switch before each automated AI action, add a circuit breaker and operator override, and emit monitored action metrics with an incident route.

In the agent loop, worker, or scheduled job that applies model output, check a runtime disengage control before every action: a feature flag or config value (for example a LaunchDarkly flag ai-agent-enabled or AI_AGENT_ENABLED) that operators can flip without a deploy, plus a circuit breaker that halts the loop when anomalies cross a limit. Each action emits a span or counter (OpenTelemetry, Prometheus) wired to an alert and an incident route, an operator override endpoint can cancel or reverse queued actions, and a decommission runbook in the repository says how to retire the model and what takes its place.

Where it goes: 15 agent action surface, 3 config and feature flags, 10 logs and telemetry.

What reviewers look for: a flag or kill switch read at runtime inside the action loop (not only at startup), a circuit breaker or operator override that stops actions in flight, telemetry on each action with an alert and incident route, and a decommission runbook in the repository.

Example (Python agent + LaunchDarkly + OpenTelemetry), before:

for call in response.tool_calls:
    result = TOOLS[call.name](**call.arguments)

After:

ld = ldclient.get()
ctx = Context.builder('support-agent').kind('service').build()
tracer = trace.get_tracer('agent')

for call in response.tool_calls:
    if not ld.variation('ai-agent-enabled', ctx, False):   # operators flip it, no deploy
        raise AgentDisengaged('kill switch off')
    if breaker.is_open():                                   # e.g. error or refund spike
        raise AgentDisengaged('circuit breaker open')
    with tracer.start_as_current_span('agent.tool_call') as span:
        span.set_attribute('tool.name', call.name)
        result = TOOLS[call.name](**call.arguments)
    ACTIONS.labels(tool=call.name).inc()                    # alerted in Prometheus

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Standard / soft law (1)

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.