QIS-CL-002 QISTRUST.COM THE GOVERNANCE LAYER REV 2026-08-05 · BUILD 19

The Governance Layer · Clause Library · Instrument 02

The kill-switch covenant.

Nearly every published discussion of autonomous system risk arrives at the same place: there should be a kill switch. Almost none of them says who may pull it, on what number, how quickly, who is told, who bears the loss when it fires, or — the question no one drafts — what has to be true before the system may start again.

This form covers those questions. It is the second instrument in the clause library and the operative counterpart to MARQUE Drift, the third of the eight questions.

How this differs from the authority grant.

Article 5 of the agent authority grant already requires a halt capability and pre-committed triggers. That article is unilateral and internal: the institution imposes it on itself, and its function is evidentiary. This instrument is different in kind. A covenant is a promise made to a counterparty, and it is that counterparty — an allocator, a client, a vendor's customer, an insurer, a fund investor — who holds the right to test it and the remedy when it fails.

The distinction matters commercially. A self-imposed halt threshold demonstrates discipline. A halt threshold owed to someone else with a remedy attached is a term that gets negotiated, priced, and enforced — and the moment it is priced, it stops being governance theater. Both instruments should exist in a mature deployment; they do different work.

What the language derives from.

Form of kill-switch covenant.

Bracketed text indicates a term the parties must supply. This form is drafted for insertion into an agreement between an institution deploying an autonomous system (the "Operator") and a counterparty to whom the covenant is owed (the "Beneficiary"). Where there is no external counterparty, use Article 5 of the agent authority grant instead.

Section 1 — Halt capability.

The Operator covenants that at all times during the Term it will maintain the capability to halt the System, and that the capability will: (a) be exercisable by a natural person identified under Section 7; (b) take effect within [interval] of exercise; (c) operate without the cooperation, consent, or continued functioning of the System; and (d) not be subject to modification, degradation, or circumvention by the System or by any process the System directs.

"Halt" means the cessation of all action by the System other than the completion of steps necessary to leave positions, records, and dependent processes in a determinate state. The Operator shall specify at [reference] what the System does on halt, and shall not treat the matter as implementation detail.

Section 2 — Pre-committed triggers.

The System shall halt automatically upon the occurrence of any event listed in the Trigger Schedule. Each entry in the Trigger Schedule shall state: the observable quantity; the threshold expressed as a value; the measurement window; the data source from which the quantity is derived; and the date the threshold was set together with the name of the person who set it.

A trigger stated as a standard of judgment, or as an instruction to a person to form a view, is not a trigger for purposes of this covenant. Where the parties intend a matter to rest on judgment, it belongs in Section 3 and not in the Trigger Schedule.

Section 3 — The Beneficiary's demand right.

The Beneficiary may require the Operator to halt the System by notice, without stating a reason, and the Operator shall halt within [interval] of receipt. Exercise of this right is not a representation that any trigger has occurred, does not constitute a breach by the Operator, and does not of itself give rise to any claim by either party except as provided in Section 8.

Section 4 — Notification.

On any halt, whether automatic, elective, or demanded, the Operator shall notify the Beneficiary within [interval], stating: the time of the halt; the trigger or basis; the quantity observed against the threshold; the actions taken by the System in the [period] preceding the halt; and the Operator's preliminary view of cause. A notification that states the fact of the halt without the observed quantity does not satisfy this Section.

Section 5 — Testing.

The Operator shall test the halt capability no less frequently than [interval] and shall test each entry in the Trigger Schedule no less frequently than [interval]. Testing shall exercise the capability rather than review its design. The Operator shall retain the record of every test, including tests in which no halt resulted, and shall make the records available to the Beneficiary on [terms].

Section 6 — Restart conditions.

Following a halt, the System shall not resume operation until each of the following has occurred and been recorded: (a) the cause has been identified, or the Operator has recorded that it has not been identified together with the basis on which resumption is nonetheless proposed; (b) the Accountable Individual has authorized resumption in writing; (c) where the halt resulted from a Trigger Schedule entry, the threshold has been reviewed and either reaffirmed or amended under Section 9; and (d) the Beneficiary has been notified not less than [interval] before resumption.

Where the System has halted [number] times within [period], resumption additionally requires [approval]. Repeated halts within a short period indicate that either the thresholds or the System are miscalibrated, and the covenant treats that as a distinct condition rather than as a sequence of unrelated events.

Section 7 — Persons.

The Operator shall identify by name and title each person able to exercise the halt capability, and shall notify the Beneficiary of any change within [interval]. At least [number] such persons shall be available at all times during which the System may act.

Section 8 — Allocation of loss.

[The parties should select and complete one of the following approaches, or draft their own.] Loss arising from a halt that occurs in accordance with the Trigger Schedule is borne by [party]. Loss arising from the Operator's failure to halt when required is borne by the Operator. Loss arising from a halt demanded under Section 3 is borne by [party]. Loss arising from a halt caused by erroneous data from a source identified in the Trigger Schedule is borne by [party].

Section 9 — Amendment of the Trigger Schedule.

The Trigger Schedule may be amended only in writing, on notice to the Beneficiary of not less than [interval], and each version shall carry a version identifier and an effective date. Prior versions shall be retained for [period]. The System shall have no capability to initiate, propose, approve, or effect an amendment.

Section 10 — Term and survival.

This covenant applies from [date] and continues for so long as the System may act on the Beneficiary's behalf or with respect to the Beneficiary's assets. Sections 4, 5, and 8 survive termination in respect of any halt occurring during the Term.

Drafting notes.

On testing that exercises rather than reviews. This is the provision most likely to be resisted and the one least worth conceding. A halt capability that has been designed but never fired is, at the moment it is needed, indistinguishable from one that does not exist. The requirement to retain records of tests in which no halt resulted is deliberate: those are the records that establish the capability was exercised regularly rather than invoked once for the file.

On the demand right in Section 3. Drafting it as reason-free is the point. A demand right conditioned on the Beneficiary establishing cause is a dispute, not a right, and it will not be exercised in the window where exercising it matters. The cost of that construction is that it can be exercised wrongly, which is why Section 8 must be completed rather than left to general principles.

On restart, which is the provision no one drafts. The discussion of kill switches almost universally stops at stopping. In practice the pressure to resume arrives within hours and falls on whoever is least equipped to resist it. Section 6 exists to move that decision from the moment of pressure to a moment of calm, and clause (a) — permitting resumption without an identified cause, but requiring that the absence of a cause be recorded — is drafted to be usable rather than aspirational. A restart condition that cannot be satisfied is one that gets waived.

On Section 8 and the wrongful halt. A halt is not a neutral act. Positions left unhedged, orders left unfilled, and processes left waiting all generate loss, and a correctly functioning trigger that fires on a false signal produces exactly that loss with no one at fault. This is the provision the parties will actually negotiate, and the reason the form presents options rather than a default: there is no market practice yet, and asserting one would be an invention.

On the repeated-halt condition. Treating the third halt in a month differently from the first is borrowed from covenant cure limitation practice in credit agreements, where the number of permitted cures is capped precisely because repeated cures indicate the covenant is measuring something real.

The negative space.

Relationship to the framework.

This instrument is the operative counterpart to MARQUE Drift. An operator that can produce an executed covenant in this form, a versioned Trigger Schedule with recorded rationale, and the log of every test including non-firing tests, is evidenced on KYA dimension 03 rather than documented. Section 6 contributes to dimension 12, and Section 7 to dimension 05, but each of those has its own instrument.

This is an editorial form with commentary, published in the tradition of model agreements and form books. It is not legal advice, not a compliance determination, not a certification, and not a representation that any provision here is enforceable in any jurisdiction. It should be reviewed by counsel and adapted before use.