The person accountable for an AI agent may not be able to stop it themselves, and by the time the vendor suspends it, the work may already be with another agent.
The original agent may also have started a transaction that stopping it will not reverse, so the payment could already be out the door or the records already shared.
A policy saying a human can intervene is not much of a control if nobody can show that person can stop the agent while it is still running.
Naming an owner is a start, but that person also needs the access and a workable way to use their authority before the next action makes the problem worse.
A few days ago I wrote about a measure I called time to accountable awareness: the time between something unexpected happening and a person with the authority to act understanding that it happened. Knowing only helps if that person can act on it. https://www.linkedin.com/posts/derrickgreenwood_on-june-18-an-openai-agent-looking-up-public-activity-7509209065907208192-FwoW)
The management problem underneath is familiar: give something authority and you need to know where that authority starts and stops.
Once the work crosses organizational boundaries, someone also has to own the handoff, including what happens when either side needs the work to stop. With an agent, that handoff can run straight through a vendor’s support queue.
That puts a limit on what faster escalation can achieve. Some actions need approval before they happen and some boundaries need to be enforced automatically, so the operating decision comes down to which actions an agent can take on its own and where it has to wait for someone to decide.
If I were putting more agents into production now, I would want a fairly boring set of things written down before another policy document: who owns each agent, what it can do without asking, which actions need another decision, who can stop it, and how you rebuild what happened afterward.
I would also want to know what keeps running after someone uses that stop control.
Then I would test the chain. A tabletop exercise with a vendor in the middle can expose confusion about who decides and who gets called.
A controlled test in a safe environment should then show whether the named person has the access they need and whether the intervention contains further harm. That includes identifying work already handed off and checking whether it needs to be stopped separately.
⏱️ I would want the result recorded in elapsed time and observed behaviour. If stopping the agent depends on a support ticket nobody has rehearsed, that is something to discover before the business relies on it.
If one of your production agents crossed a boundary tomorrow morning, could the person accountable actually stop it, and when did you last test that?