Standard / soft law
Deployed AI should have override, decommission, and monitoring mechanisms
NIST AI RMF MANAGE 4.1 expects post-deployment monitoring plus appeal, override, decommissioning, and incident response. Detect a deployed AI system (especially agentic) with no override/disengage/kill-switch or monitoring hooks.
Who it applies to
- Duty falls on: developer, deployer
- Systems covered: consequential decision
- Organisations adopting NIST AI RMF for deployed AI. Voluntary.
The guard to add
Check a runtime kill switch before each automated AI action, add a circuit breaker and operator override, and emit monitored action metrics with an incident route.
In the agent loop, worker, or scheduled job that applies model output, check a runtime disengage control before every action: a feature flag or config value (for example a LaunchDarkly flag ai-agent-enabled or AI_AGENT_ENABLED) that operators can flip without a deploy, plus a circuit breaker that halts the loop when anomalies cross a limit. Each action emits a span or counter (OpenTelemetry, Prometheus) wired to an alert and an incident route, an operator override endpoint can cancel or reverse queued actions, and a decommission runbook in the repository says how to retire the model and what takes its place.
Where it goes: 15 agent action surface, 3 config and feature flags, 10 logs and telemetry.
Example (Python agent + LaunchDarkly + OpenTelemetry), before:
for call in response.tool_calls:
result = TOOLS[call.name](**call.arguments)After:
ld = ldclient.get()
ctx = Context.builder('support-agent').kind('service').build()
tracer = trace.get_tracer('agent')
for call in response.tool_calls:
if not ld.variation('ai-agent-enabled', ctx, False): # operators flip it, no deploy
raise AgentDisengaged('kill switch off')
if breaker.is_open(): # e.g. error or refund spike
raise AgentDisengaged('circuit breaker open')
with tracer.start_as_current_span('agent.tool_call') as span:
span.set_attribute('tool.name', call.name)
result = TOOLS[call.name](**call.arguments)
ACTIONS.labels(tool=call.name).inc() # alerted in PrometheusControl: No override/decommission mechanism for deployed AI. The same guard addresses 1 item. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Monitor how often adverse AI decisions are reversed, and suspend models that are usually wrong
- Cigna PXDX batch claim denials (reported) (2022; alleged (not proven)). ProPublica, citing internal Cigna records, reported that Cigna's PXDX system was used to reject more than 300,000 claims over two months in 2022, with physicians spending an average of 1.2 seconds on each. Cigna disputes the reporting; related lawsuits are ongoing. Source: ProPublica / The Capitol Forum · evidence grade: press of record · cited by Make human review of adverse AI decisions substantive, not nominal
Rule id nist-ai-rmf.manage-4-1-oversight · review status: primary source derived