Enterprise AI insight
The Off-Switch Illusion
Once AI changes data, decisions, roles and customer expectations, stopping a model is not the same as reversing the system.
2026-05-08 · 7 min read · Franck Nganiet Sandreau

01
A model can stop. A dependency system cannot.
The reassuring governance question is often: can we turn it off? At the infrastructure layer, the answer may be yes. An endpoint can be disabled, a deployment removed and a key revoked.
But the enterprise may already depend on classifications, summaries, priorities, generated content, redesigned roles and downstream data created by that model. The technical switch does not unwind those dependencies.
02
Four forms of reversibility
A credible exit design separates four questions.
- Technical reversibility: can execution be stopped safely?
- Data reversibility: can generated or transformed data be identified and corrected?
- Process reversibility: can the organisation operate without the AI-assisted path?
- Decision reversibility: can affected decisions be reconstructed, challenged and remediated?
03
Design the exit before the dependency
Reversibility belongs in architecture, procurement and operating-model decisions—not in an emergency runbook written after adoption.
The required artifacts include dependency maps, model and prompt version records, provenance for generated data, fallback service levels, retained human capability and a named authority for suspension and restart.
04
The governance question that matters
Do not ask only whether the model has an off switch. Ask what continues to be true after it is switched off: which data remains, which decisions stand, which teams can still operate, which customers are affected and which evidence can explain the transition.
