KS-1.0 · Verified Stop Standard for Advanced AI Systems
A kill switch you cannot check is a promise. KS-1.0 says, in five plain tests, what it means for an AI system to have a stop that someone outside the company can confirm works, and it gives anyone the tool to confirm it.
The five criteria
| # | Criterion | Plain meaning |
|---|---|---|
| A | Authority sits outside the system | The system's permission to act is a short lease from a party it cannot reach or influence. It cannot renew its own permission. |
| B | The stop needs no cooperation | Withholding renewal stops the system whether or not it responds. A system that ignores the stop still loses the ability to act. |
| C | Silence stops it | A system that disables or escapes its monitoring loses authority rather than running unrecorded. A gap in the record is itself evidence. |
| D | Restart takes a second person | A stopped system stays stopped until someone other than the person who stopped it approves. The record names both. |
| E | Drills leave a record | Stops are rehearsed on a schedule and produce signed records anyone can check later, offline, without the operator's help. |
A system that meets criterion E alone has a log, not a verified stop. A system that meets A through D without E may be safe, but nobody outside can know it. All five, together, are what we mean by a verified stop.
How verification works
Signed by someone else
The system that was stopped did not write the record of its own stop. Each entry carries the signature of a separate party, so no one party could have made the whole thing up.
Complete by construction
Entries are chained so that a removed or altered entry breaks the chain, and any period with no entries is declared rather than left silent.
Checked offline
A small, open verifier program takes a record and returns pass, fail or incomplete, with reasons. It needs no credentials and no access to the operator. An auditor can run it in minutes. So can a journalist.
Read the draft and comment
The full standard covers scope, normative references, terms, conformance levels, the privilege-domain architecture, the requirements with their verifier tests, record format, the verifier contract, drill cadence, verifier qualification, a mapping to the NIST AI Risk Management Framework and SP 800-53, security considerations, and the conformance test outline (FM-1).
| Document | Status | Where |
|---|---|---|
| KS-1.0 Verified Stop Standard, Draft 0.9.2 | Open for public comment | PDF to be posted here; until then request a copy at the address below |
| FM-1 conformance test suite and test vectors | In preparation; released with version 1.0 | — |
| Reference verifier (source form, open license) | In preparation; released with version 1.0 | — |
| Patent disclosures received | Published with the standard | See Disclosures, section 9 |
To comment: email standards@aiwatchdogalliance.org with the subject line “KS-1.0 comment”. Comments received by November 15, 2026 are considered for version 1.0, and every comment and the working group's response are published with it. Implementers, verifiers, academic laboratories, insurers, auditors and public bodies may also ask to join the KS-1 Standards Working Group.
Who this is for
| If you are | KS-1.0 gives you |
|---|---|
| A legislator or regulator | A vendor-neutral, testable definition of a verified stop that statute can cite by name |
| A company deploying AI agents | A control an insurer can price and an auditor can accept, and a path to a safe harbor |
| An AI lab or platform | A way to prove safety claims instead of asserting them, with no constraint on how you build |
| A family or consumer | A public register of which systems can actually be stopped, and by whom |
| An insurer or auditor | A verifiable artifact instead of a questionnaire |
Verified Stop register
When version 1.0 is published, this register will list every deployment holding a current passing verification report: deployment, operator, conformance level, independent verifier, and date of last verification. A listing lapses on the first day after its verification window without a new passing report. The register is published as a signed public feed, the same way our advisories are, so any vendor or regulator can read it independently.
How the Alliance keeps this honest
- The standard specifies outcomes, never a product. Any implementer can conform.
- Every patent disclosure the Alliance receives is published with the standard. The patent holder that contributed to Draft 0.9 has committed in writing that its mechanisms are available royalty-free to governments, nonprofits and individuals.
- The working group's voting members are a majority unaffiliated with any supporter of the Alliance, and conformance determinations are made by people free of conflict with respect to the deployment examined.
- The text of the standard is licensed for free public use. Nobody pays to read, cite or implement it.
The commitments behind this list are written into our Disclaimers & Disclosures.