Signal Scout
Signal Scout | Research | October 2, 2026

AI kill switches: the downstream risk

A problem statement, with early data and a proposed next step.

1
Problem statement

What happens to critical systems when a frontier model they depend on becomes unavailable?

There is a lot of research and policy activity around creating an AI kill switch. [1][2][3] The dependency chain, and what happens downstream when the switch is used, is less understood. There is some work in that area [4][5][6], but if we don't evaluate the problem thoroughly, an off-button scenario will likely have mission-critical impacts.

Who feels it

The lab controls the switch, but it only controls the model. The impact lands on everyone who built on it. Anything running on that model could stop, from business automation like support queues and SOC triage to applications that are genuinely mission-critical. An agent can stop partway through a task, leaving work half done with its credentials still active. The lab can't see any of that, and many dependent applications likely haven't planned for it.

How hard-wired things are

Of 330,153 public repositories SignalScout measures, 45,299 call a model provider's API and 71.5% of those (32,393) use only one provider, with no router or other secondary model. We see similar concentration when we filter the data: 61.2% of repos that are containerized with automated testing, and 61.7% of company-owned repos. These are public repos, and private code may look different, but it is a rough signal of how concentrated model dependencies are. [7]

What's missing

The Cloud Security Alliance has established AI provider concentration as an enterprise resilience problem [4], but the open question is whether that risk becomes systemic across everyone who depends on a widely used model. I haven't found anyone checking whether the existing guidance is followed, or adding up exposure across companies. In July 2026 the UK put four cloud providers under direct financial oversight as critical third parties but didn't include any AI model providers. [8]

A model for this already exists

There is a precedent in the Dodd-Frank Act which was created after the 2008 financial crisis to mitigate systemic risk to the banking system. [9] It requires the largest banks to submit resolution plans showing how they could be wound down in the event of material financial distress or failure. Regulators found most of those plans inadequate for years; just the act of creating these plans forced banks to consider their dependency risk. An AI version would ask a deployer what depends on the model, what happens if it disappears tomorrow, and whether that's been tested.

Next steps

The dependency chain for model disablement must be better understood. Start by evaluating a sample of mission-critical workflows for the impact of losing model access. Then build dependency simulations to estimate the wider impact on critical infrastructure and the economy if a frontier lab model were disabled. Frontier models are becoming critical infrastructure, and this work should inform the standards, regulation and playbooks that follow.

2
References

References

  1. Office of the Governor of California, executive order on independent oversight and an AI kill switch, September 18, 2026. https://www.gov.ca.gov/2026/09/18/governor-newsom-issues-executive-order-to-accelerate-independent-oversight-and-advance-the-creation-of-an-ai-kill-switch/
  2. Faegre Drinker, briefing on the AI Kill Switch Act (H.R. 9917), September 8, 2026. https://www.faegredrinker.com/en/insights/publications/2026/9/the-white-house-gold-eagle-initiative-scales-back-the-ai-kill-switch-act-and-bill-gates-warnings-and-proposals
  3. "The 2025 Peregrine Report: 208 Expert Proposals for Reducing AI Risk" (proposal #157, "Build the Off Button"). https://riskmitigation.ai
  4. Cloud Security Alliance, "AI Provider Concentration Risk: Enterprise Resilience," June 19, 2026. https://labs.cloudsecurityalliance.org/research/ai-provider-concentration-risk-enterprise-resilience-v1-csa/
  5. J. Shelby, "The AI Resilience Gap: Bringing Artificial Intelligence Inside the Operational Resilience Perimeter," arXiv:2607.07359, July 2026. https://arxiv.org/abs/2607.07359
  6. Cloud Security Alliance, "AI Concentration Risk Moves From Theory to Institutional Warning," September 27, 2026. https://labs.cloudsecurityalliance.org/research/csa-research-note-ai-concentration-systemic-risk-20260927-cs/
  7. SignalScout, method and caveats (wave 2026-09-29, indicator set 0.9.2).
  8. R. Beri, "Britain Regulated Four Clouds. Not the Models Inside.," August 10, 2026. https://www.beri.net/article/uk-critical-third-parties-ai-model-layer-resilience-register-gap
  9. Federal Reserve Board, "Living Wills (or Resolution Plans)." https://www.federalreserve.gov/supervisionreg/resolution-plans.htm

* Based on the dependency files of public GitHub repos as of September 29, 2026, counting a repo as single-provider when it lists one provider's SDK and no router or self-hosted model.