Skip to content
Holding·last review26 May 2026

As of mid-2026, the majority of enterprises running production AI agents cannot terminate a misbehaving agent within their own stated incident-response window, because containment is specified as kill criteria in the risk register rather than built and tested as a runtime control plane with the four primitive actions (purpose binding, kill switch, network isolation, credential revocation). Kiteworks' 2026 Data Security and Compliance Risk Forecast measured the gap at 60% cannot terminate quickly, 63% cannot enforce purpose limitations, 55% cannot isolate networks, with the government-sector figures materially worse. Microsoft Agent 365 with Intune and Defender (GA 1 May 2026, runtime-controls preview from June 2026) is the first major-platform consolidation of the four primitives in a customer-administered control plane, which moves the question from engineering integration to procurement evaluation but does not resolve the cross-platform standardisation gap.

Claim is scoped to the runtime-control-plane reading of the agent containment problem in 2026 enterprise deployments. Does not assert kill criteria are unimportant; asserts the criteria layer is mature and the architecture layer is immature, and that the EU AI Act Article 14 'stop button or similar procedure' language plus the NIST AI RMF Manage function plus the Kiteworks measurement together define a procurement-and-engineering investment most enterprises have not made. 30-day review cadence calibrated to the security-advisory adjacent landscape and the pace at which the Microsoft Agent 365 preview and equivalents are reaching general availability. Trigger conditions: (1) a major agent platform ships a verified one-action kill-and-revoke primitive that the customer can invoke unilaterally with a documented SLA — would move toward Partial because the architecture gap is closing at the platform layer; (2) Kiteworks 2027 or an equivalent enterprise survey shows containment-capable figures crossing 50% — would move toward Partial or Not holding depending on direction; (3) a published 2026 enterprise incident where an agent was terminated successfully through a documented kill-architecture primitive within the stated incident-response window — would confirm the architecture is operationally tractable and shift the discussion from gap to standardisation; (4) Microsoft Agent 365 with Intune and Defender exits preview with verified runtime-blocking and the equivalent capabilities ship in the other major enterprise stacks (Google Vertex AI Agent Builder, AWS Bedrock Agents, Salesforce Agentforce, SAP Joule, ServiceNow Now Assist) — would change the procurement-side path from custom integration to platform-default.

Published
26 May 2026
Last reviewed
26 May 2026
Next review
+30d· 25 Jun 2026
Embed this claimiframe + oEmbed
HTML iframe
Paste-the-URL (Substack, Medium, Notion, WordPress)

The card auto-updates when the claim's status, last-reviewed date, or correction log changes. Embedders never need to refresh — the card is rendered live from the canonical record.

Watch this claim

Email-me when AM-171's status, next review date, or correction log changes. One email per change. No newsletter subscription, no other mail.

The claim: As of mid-2026, the majority of enterprises running production AI agents cannot terminate a misbehaving agent within their own stated incident-response window, because containment is specified as kill criteria in the risk register rather than built and tested as a runtime control plane with the four primitive actions (purpose binding, kill switch, network isolation, credential revocation). Kiteworks' 2026 Data Security and Compliance Risk Forecast measured the gap at 60% cannot terminate quickly, 63% cannot enforce purpose limitations, 55% cannot isolate networks, with the government-sector figures materially worse. Microsoft Agent 365 with Intune and Defender (GA 1 May 2026, runtime-controls preview from June 2026) is the first major-platform consolidation of the four primitives in a customer-administered control plane, which moves the question from engineering integration to procurement evaluation but does not resolve the cross-platform standardisation gap.

About this register

The Reporting register tracks claims published from articles addressed to senior enterprise IT leaders — CIOs, IT directors, heads of platform. Claims are reviewed on a 30–90 day cadence; each review either reaffirms the claim, marks one substantive part as Partial, or marks it Not holding once the underlying evidence has been overtaken.

Recent corrections in Reporting

  • AM-002 · Not holding · 06 May 2026

    URL state changed. The /the-agentic-ai-revolution-real-world-success-stories-and-strategic-insights-from-2024-2025/ slug now serves a deliberately rewritten retrospective (claimId AM-130, "Agentic AI 2024-2025 retrospective", published 04 May 2026) against audited primary sources. The 28 Apr 2026 redirect to /retractions/ has been lifted to allow that. AM-002 the claim remains Not holding — the original $3.50/dollar + 70% failure-rate framing was withdrawn and is not restored. AM-130 is a separate claim with its own evidence chain. Readers arriving at /holding/AM-002 see the withdrawal here; the article link surfaces the new piece at the URL the original lived at, with this entry as the audit trail.

  • AM-121 · Holding · 2 May 2026

    Klarna walk-back primary-source upgrade — added Siemiatkowski verbatim quotes via Bloomberg-cited-by-Fortune (9 May 2025) and the Uber-style freelance hiring detail via Entrepreneur. Closes the highest-priority evidence gap from the source dossier.

  • AM-115 · Holding · 29 Apr 2026

    Initial publication 29 Apr 2026 — the first Quarterly Claim Review Bulletin. The claim itself is recursive: it asserts that the bulletin will ship quarterly, and the next review (30 Jul 2026) tests whether the Q3 bulletin actually appeared. Status starts as 'up' because the claim is currently true (the Q2 bulletin shipped). The verdict at end of July 2026 will move to Holding, Partial (bulletin shipped but on a delayed cadence), or Not holding (no bulletin shipped).

Reviews coming up in Reporting

  • AM-003 · Holding · next -7d (19 May 2026)

    GPT-5 Pro's tiered-subscription model forces enterprises to classify problems by computational difficulty — $200/month…

  • AM-136 · Holding · next +9d (4 Jun 2026)

    Across the 24-month window May 2024 to April 2026, every major foundation-model provider (Anthropic, OpenAI, Google, AW…

  • AM-020 · Holding · next +23d (18 Jun 2026)

    The 40-60% TCO underestimate on enterprise agentic-AI deployments is not a cost-visibility failure — it is a cross-depa…