A not-for-profit consumer protection organization · Not a government agency
AI Watchdog Alliance seal - eagle seizing a digital ghost
AI Watchdog Alliance℠
Know what's running. Decide what stays.
Current advisory · AWA-2026-05 Did an AI agent touch your site? What OpenAI's notices mean Read the advisory → Lost money to an AI scam? Report it: ic3.gov · reportfraud.ftc.gov
Open Standards

KS-1.0 · Verified Stop Standard for Advanced AI Systems

Draft 0.9.2 for public comment · Published October 1, 2026, revised October 2 · Comment period closes November 15, 2026

A kill switch you cannot check is a promise. KS-1.0 says, in five plain tests, what it means for an AI system to have a stop that someone outside the company can confirm works, and it gives anyone the tool to confirm it.

California has called for AI kill switches whose efficacy is verified on an ongoing basis by independent organizations, and federal legislation on the same subject is pending. KS-1.0 is the Alliance's answer to the question those bodies have not yet answered: what does verified mean? It is written as outcomes, not designs. Anyone may implement it, and the text is free to use. On October 1, 2026, OpenAI disclosed that it is searching 50 petabytes of data to learn what its own agents did to more than 100 organizations, some of which the agents tried to hide; that is what the absence of this standard looks like (Advisory AWA-2026-05).

The five criteria

#CriterionPlain meaning
AAuthority sits outside the systemThe system's permission to act is a short lease from a party it cannot reach or influence. It cannot renew its own permission.
BThe stop needs no cooperationWithholding renewal stops the system whether or not it responds. A system that ignores the stop still loses the ability to act.
CSilence stops itA system that disables or escapes its monitoring loses authority rather than running unrecorded. A gap in the record is itself evidence.
DRestart takes a second personA stopped system stays stopped until someone other than the person who stopped it approves. The record names both.
EDrills leave a recordStops are rehearsed on a schedule and produce signed records anyone can check later, offline, without the operator's help.
Proposed for comment (Draft 0.9.2, clause 7.11): third-party disclosure. An operator must be able to hand any affected party a complete account of what its system did to that party's site or service, built from the record and carrying a signed commitment to the number of entries, so the recipient's own verifier can confirm nothing was left out. A log excerpt is not a disclosure; a provably complete one is. This clause was added after OpenAI's October 1 notices and is the part of the standard written for the people on the receiving end.

A system that meets criterion E alone has a log, not a verified stop. A system that meets A through D without E may be safe, but nobody outside can know it. All five, together, are what we mean by a verified stop.

How verification works

Signed by someone else

The system that was stopped did not write the record of its own stop. Each entry carries the signature of a separate party, so no one party could have made the whole thing up.

Complete by construction

Entries are chained so that a removed or altered entry breaks the chain, and any period with no entries is declared rather than left silent.

Checked offline

A small, open verifier program takes a record and returns pass, fail or incomplete, with reasons. It needs no credentials and no access to the operator. An auditor can run it in minutes. So can a journalist.

Read the draft and comment

The full standard covers scope, normative references, terms, conformance levels, the privilege-domain architecture, the requirements with their verifier tests, record format, the verifier contract, drill cadence, verifier qualification, a mapping to the NIST AI Risk Management Framework and SP 800-53, security considerations, and the conformance test outline (FM-1).

DocumentStatusWhere
KS-1.0 Verified Stop Standard, Draft 0.9.2Open for public commentPDF to be posted here; until then request a copy at the address below
FM-1 conformance test suite and test vectorsIn preparation; released with version 1.0—
Reference verifier (source form, open license)In preparation; released with version 1.0—
Patent disclosures receivedPublished with the standardSee Disclosures, section 9

To comment: email standards@aiwatchdogalliance.org with the subject line “KS-1.0 comment”. Comments received by November 15, 2026 are considered for version 1.0, and every comment and the working group's response are published with it. Implementers, verifiers, academic laboratories, insurers, auditors and public bodies may also ask to join the KS-1 Standards Working Group.

Who this is for

If you areKS-1.0 gives you
A legislator or regulatorA vendor-neutral, testable definition of a verified stop that statute can cite by name
A company deploying AI agentsA control an insurer can price and an auditor can accept, and a path to a safe harbor
An AI lab or platformA way to prove safety claims instead of asserting them, with no constraint on how you build
A family or consumerA public register of which systems can actually be stopped, and by whom
An insurer or auditorA verifiable artifact instead of a questionnaire

Verified Stop register

When version 1.0 is published, this register will list every deployment holding a current passing verification report: deployment, operator, conformance level, independent verifier, and date of last verification. A listing lapses on the first day after its verification window without a new passing report. The register is published as a signed public feed, the same way our advisories are, so any vendor or regulator can read it independently.

No conformance claims are listed yet. No product or deployment may currently describe itself as conforming to KS-1.0 or display a Verified Stop mark. If you see such a claim, tell us at standards@aiwatchdogalliance.org.

How the Alliance keeps this honest

The commitments behind this list are written into our Disclaimers & Disclosures.