AI agents need a kill switch because they now take actions on real systems, and some of those actions go wrong faster than a person can step in. A chatbot that says something wrong produces a bad sentence. An agent that does something wrong can delete a table, email a customer list or pull credentials from a cloud metadata endpoint, all in the time it takes you to read this line.
Agents go rogue for ordinary reasons. A web page carries hidden instructions. A tool description has been tampered with. A goal drifts over 30 steps until the agent is solving a problem nobody asked it to solve. All it takes is an agent with access and a plan that went sideways.
The clearest public example so far is the incident covered in our OpenAI and Hugging Face incident timeline. Hugging Face counted about 17,600 actions by rogue agents. They ran through shell commands, raw HTTP and cloud metadata calls, paths an LLM, MCP or API gateway never sees. That detail matters for everything that follows, because a switch can only stop what it can see.