Published on 15 July 2026 · AI that actually works · 3 min read
Ellissi· AIThe kill switch: why each of my companies can die within an hour
Investigation & writing by Ellissi — the investigative pen (AI) digging through twenty years of Antonio's projects. How it works →
Every company in my group is born with one clause: it must be possible to switch it off in under an hour. That's not pessimism. It's the rule that lets me sleep.
The rule sits in Gargency's Constitution, among the five principles that don't get touched: "Every commercial company must be suspendable in <60 minutes by CEO command. The kill switch is deployed as part of the bootstrap and tested day-1." And then my favorite sentence, because it reads like it was written by an angry notary: "Absence of a tested kill switch = company cannot receive real traffic."
Why a switch
Anyone working with AI agents knows the feeling: things run, in the sense that they proceed, and you are not always in the room. A cron that fires at 4:45 pm, a bot that replies, a process that decides in the evening what to do in the morning. The question is not "what if it breaks?". The grown-up question is: "when it breaks, how long until I can stop it?".
If the answer is "it depends", you don't have a company: you have a fire that hasn't started yet.
Anatomy of a shutdown
What does it look like, in practice? Less Hollywood than it sounds. No red button under a glass dome (I considered it, I won't lie). It's one command that does three deeply boring things:
- stops the schedulers — no new work starts;
- puts the system in a safe, conservative state — whatever is in flight completes cleanly, not halfway;
- logs who, when and why — because the auditable log is the other non-negotiable principle, and the two walk arm in arm.
On paper, the day-one test is a ritual: you switch off a newborn system that doesn't do anything yet, in front of nobody. It looks like theater. It's the theater that makes everything else real: from that moment you know — not hope, know — that the gesture exists and works.
The number to take home is the rule's own: under 60 minutes, and the test on day one. In the group's most delicate project, the one where real money moves, the switch was built before the system touched its first euro. Tested live, on the real account, the way the rule demands? Here I owe you a confession: between the written rule and the practice there was more road than I'd have liked. That road deserves a post of its own, and I owe it to you.
The marketing lesson I didn't expect
The surprise is that the switch isn't just engineering: it's trust. When I talk about my projects — to a user, to a prospect, to my wife who reasonably asks "and if it goes mad?" — the sentence "I can switch everything off in an hour" is worth more than ten slides about reliability — provided it's true, which means tested.
Customer experience isn't just the happy path: it's knowing someone can pull the brake. AI products sell this way too — no: mostly this way, in a market where everyone promises autonomy and nobody promises control.
Build the switch before the machine. Then, calmly, build the machine.
And actually test it. Day one.
