Banks Cannot Put a Kill Switch on AI Agents They Cannot See

This week’s Bangkok Post carries a timely and serious piece on AI risk. The experts it quotes are the right people to ask, and their advice is sound: limit agent permissions, keep a kill switch outside the agent’s own decision-making, hold suppliers to the same standard as internal systems.

My concern is the impression it leaves, that this is a checklist. It is not.

The controls assume you own the runtime. Most banks, and enterprises, run on vendor software: core banking, CRM, fraud engines, service desks. Agents now arrive inside those products as features. You did not design them, you cannot inspect them, and your logs show what the vendor chooses to expose.

Take Salesforce. In September 2025, Noma Security disclosed ForcedLeak, a flaw in Agentforce rated 9.4 in severity that could let attackers steal CRM data through indirect prompt injection. The malicious instructions were hidden in an ordinary Web-to-Lead form and executed later, when an employee asked the agent a routine question. The exit route was a domain on Salesforce’s allowlist that had expired, which the researchers bought for about $5. Salesforce patched it, and there is no evidence it was exploited. But ask honestly: which bank’s security team would have found that themselves?

A month earlier, attackers used OAuth tokens stolen from the Salesloft Drift chatbot integration to pull data from company Salesforce tenants, bypassing MFA. Google put the count at over 700 organisations. Victims included several prominent cybersecurity vendors. If they could not see it coming, a regional bank will not.

The attackers are not waiting. The article is right that existing tools will not disappear even if development paused. I would go further: they are in use today. Anthropic’s threat report of 10 September describes breaches completed in two to three hours, with individual operators handling dozens of victims in parallel. One extortion crew breached a SaaS provider and used that foothold to extract data from roughly 200 of its downstream customers, with AI agents doing nearly all the work. The report’s own conclusion is that AI has pushed the cost back onto defenders. Closer to home, Check Point Research reported Thailand entering the global top 10 of ransomware targets for the first time in the first quarter.

The governance arrived late, and the bill goes to the buyer. Agentforce shipped in late 2024. The first framework written for agentic AI came from Singapore’s IMDA on 22 January 2026, more than a year later. It is voluntary, yet organisations remain legally accountable for what their agents do. NIST opened its AI Agent Standards Initiative on 17 February 2026; the NIST AI RMF, often recommended as Thailand’s reference point, dates from January 2023, before agents were mainstream. The Bank of Thailand’s September 2025 guidelines rightly cover AI built by third parties. So the bank is accountable for a system only the vendor can see. The industry sold autonomy first and left customers to work out supervision.

What a board should ask for

AskWhy
Contractual right to agent action logs, in your SIEMYou cannot govern what you cannot observe
Ability to switch off vendor AI features per tenantA kill switch you actually hold
Vendor disclosure of embedded models, tools and allowlistsForcedLeak was an allowlist nobody audited
Inventory and rotation of every OAuth token and AI API keyDrift was a token problem, not a Salesforce bug
A defence budget that assumes AI-speed attackersHours, not weeks, from access to exfiltration

None of this is easy or cheap. It needs people who can read an agent trace and a procurement function willing to walk away from a vendor who refuses visibility. That is the honest message for Thai boards: guardrails are not a framework you adopt. They are a capability you pay for — a procurement negotiation, not an IT policy document.

Disclosure: I am CEO of Xponential, which builds AI agents for Siam Piwat Group, CEO of Pivot Digital advisory group, and an independent director of GXBank. Views are my own.

Sources: Bangkok Post, 21 September 2026; Infosecurity Magazine and The Hacker News on ForcedLeak; Salesforce security advisory and Google Threat Intelligence on the Salesloft Drift incident; Anthropic, Detecting and Countering Misuse of AI, September 2026; Check Point Research Q1 2026 ransomware report; IMDA Model AI Governance Framework for Agentic AI; NIST AI Agent Standards Initiative; Bank of Thailand AI Risk Management Guidelines, September 2025.


Discover more from Axel Winter

Subscribe to get the latest posts sent to your email.

Discover more from Axel Winter

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Axel Winter

Subscribe now to keep reading and get access to the full archive.

Continue reading