Formerly known as Wikibon

Google Shipped a Sovereign Mesh With a Kill Switch

Google shipped a “Sovereign Agent Mesh” with a remote kill switch and a 24-hour self-destruct. Then you find the same thing sitting in the terms of service you already signed.


Last week Google engineers open-sourced SAM — the Sovereign Agent Mesh. Peer-to-peer networking for autonomous agents. Zero config, zero trust, no broker in the middle. The post went viral.

I cloned the repo and read the source. Here is what “sovereign” means inside it, in Google’s own words.

POST /admin/revoke:

“Revoked nodes are marked as banned. When the node next attempts a proactive /refresh handshake, the request is denied with a 403 Forbidden status, and the node’s local daemon immediately terminates.”

That is a remote kill switch, documented as one.

It is not the only way your node dies. Every credential in the mesh is “cryptographically bound to a strict 24-hour expiration,” and when renewal fails, node.go does this:

logger.Fatalf("Identity expired and renewal failed. Exiting to avoid network partition.")

os.Exit(1). Lose the control plane for a day and your entire fleet terminates itself. There’s a third path too — three minutes without a router and the node exits.

And the control plane that holds this switch? On the path the README’s one-liner puts you on — the install, the skill, the quickstart — it’s bananas.sam-mesh.dev. Google’s box.

node-configuration.md, line 7, unprompted: “While the control plane is the central authority…”

One issuing authority. Credentials that expire daily. A remote kill. And cmd/sam-node/main.go line 508: “A node’s identity is only valid for the mesh that issued it.” No federation, anywhere.

That is not a sovereign. That is a suzerain.


Run it through the five pillars

01 · Territorialwhere data and compute physically reside; at rest and in motion. The data plane is genuinely peer-to-peer and end-to-end encrypted; relays carry ciphertext, not payloads. Real, and it earns marks. But your identity, your policy set and your node registry live on Google’s box. 2/5

02 · Operationalwho runs and secures the environment. Keys, paging, audit logs. Google mints every credential, holds the only root key every node trusts, and can end your process with one API call. You do get a genuine local veto — your own deny rules evaluate before the control plane’s. That’s the point you earn. 1/5

03 · Technologicalwho owns the stack and the IP. Can you audit, fork, self-host? Apache-2.0, readable, forkable, built on libp2p and Biscuit. This is the pillar Google actually earns, and I’ll say so plainly. Docked for no release signing and no checksums — install.sh is a bare curl | tar — and for “not an officially supported Google product,” which is a maintenance commitment of zero. 4/5

04 · Legalwhich jurisdiction governs access. CLOUD Act, MLATs, vendor HQ. The root of trust is held by a US company. The CLOUD Act reaches “possession, custody, or control.” There is no MLAT friction, no jurisdiction of your choosing, and nothing to appeal to. 0/5

05 · Financialfreedom from vendor lock-in. Predictable cost, no forced migration. No broker, no licence, no per-token meter — genuinely good. Docked for the absence of federation: switching control planes destroys your identity outright. That is lock-in at the identity layer, and it is a forced migration by definition. 3/5

10 / 25

Run the same test on a self-hosted control plane and it comes out at 18/25 — you hold the root key, you mint your own tokens, nobody can revoke you. Same commit, one configuration flag, eight points.

The README’s one-liner points you at the 10.

Sovereignty you have to know to configure is a feature flag with a marketing budget.


Nobody else in this category builds it this way

I audited the alternatives from source, the same depth, same checklist. Self-hostable zero-trust overlays — SAM’s actual peers.

  • Nebula (Slack, MIT): no control plane at all. An expired certificate loads fine and the daemon runs forever. No hardcoded keys. No telemetry. No phone-home of any kind.
  • NetBird: retries an unreachable control plane for 3 * 30 * 24 * time.Hour — three months — and never exits.
  • Headscale: node expiry defaults to never. The client backs off indefinitely and keeps its tunnels up.
  • ZeroTier: reloads a cached network config from disk and rejoins a dead controller’s network.

Four peers. Zero self-destruct timers. Google shipped the only agent mesh in its class that kills itself when it can’t phone home — and put the word sovereign in the product name.

Then there’s SPIRE. Apache-2.0, CNCF-graduated, run by a technical steering committee with an 80% supermajority rule, cosign-signed images, independently audited by Cure53, zero phone-home. It ships genuine trust-domain federation: two independently operated deployments interoperate with no shared administrator. Exactly the property “sovereign” is supposed to describe.

SPIRE has never once called itself sovereign. SAM, which cannot federate at all, put it on the box.


The scale test tells on itself

Google’s own benchmark is genuinely impressive — 1,000 Firecracker microVMs on one host, 40,000 requests, zero failures, policy enforcement in 18 microseconds.

Then open tests/scale/results/fleet-1k/environment.json:

"control_plane":"bananas.sam-mesh.dev"

The only published evidence that any of this scales was produced against Google’s testnet. Not against a self-hosted control plane. The sovereign configuration has never been demonstrated at scale. The one where Google holds the kill switch has.

And the repo carries the line “not an officially supported Google product.” Nobody at Google reviewed this as a product — and the word still went on the box. That’s not a strategy. That’s a reflex.


Now check the terms you already signed

Here’s where it stops being a side project and starts being a pattern.

Google Cloud Terms of Service §8.6 lets Google terminate your service immediately if you “violated or caused Google to violate Anti-Bribery Laws or Export Control Laws” — defined in §3.3 to include EAR, OFAC and ITAR. American law, reaching your European deployment, with immediate effect.

§8.7: on termination, all access to Customer Data ends. The main agreement states no grace period at all.

Same mechanism as SAM. Different document. Already binding on you.


And the product named “Data Boundary” documents Google walking through it

This one is from Google’s own documentation, not a critic’s reading. On Bigtable and Spanner split boundaries:

“These split boundaries are accessible by Google personnel for technical support and debugging purposes, and are not subject to administrative access data controls in Assured Workloads.”

On Compute Engine:

“It is possible for scripts, daemons, and binaries that are included with the guest environment to access unencrypted at-rest and in-use data.”

And on the base EU Data Boundary package, your support ticket is “routed to global support personnel.”

A product called Data Boundary, documenting Google-personnel access outside the boundary, in Google’s own docs.

The whole edifice rests on a 2022 line from Adaire Fox-Martin, then President of Google Cloud Go-to-Market: “the control of encryption keys is the strongest and most effective technical measure against extraterritorial requests for data.”

Read the structure of that sentence. It is a technical answer to a legal question. Google’s own whitepaper concedes the legal one: the CLOUD Act compels data under a US provider’s “possession, custody, or control… regardless of where that data is physically stored.”


Europe graded it. Google came last.

17 April 2026. The European Commission awards €180m in sovereign cloud framework contracts, grading every bidder on its own Cloud Sovereignty Framework.

Three winners are European-owned — OVHcloud/Post Telecom, STACKIT, Scaleway. All three score SEAL-3.

The fourth bid contains S3NS, the Thales–Google joint venture. It scores SEAL-2 — the bare eligibility floor. A full tier below every European-owned rival.

CISPE’s Francisco Mingorance: “Recognising S3NS, which leverages Google’s cloud technology, as ‘sovereign’ is clearly an own goal and threatens to institutionalize sovereignty washing.”

That is not an activist op-ed. That is the Commission’s own assessment methodology putting a number on the gap — and buying it anyway.


The rest of the ladder, scored the same way

Google offeringTerrOperTechLegalFin/25
SAM — self-hosted control plane4335318
Google Dedicated / S3NS PREMI3NS4414215
Google Distributed Cloud air-gapped5313113
SAM — as Google ships it2140310
Google Cloud Data Boundary211015

Nothing Google sells you clears 15. The only entry above it is the one you have to build, operate and patch yourself — which is not a product anyone is selling.

And once you start counting, the word is everywhere and it is load-bearing nowhere.

  • Google Distributed Cloud air-gapped: “built to remain disconnected in perpetuity.” Google Cloud Dedicated, same company: partners may block updates only “in exceptional circumstances” and run severed for “up to 12 months.” Independence with an expiry date — and Google publishes no account anywhere of how patches physically reach an air-gapped site.
  • Munich, November 2025: the “Sovereign Cloud Hub.” It’s a demo and training centre. A showroom, branded as a milestone.
  • African Union, February 2026: an MoU to advance “Africa’s sovereign AI capacity.” What ships: official training, and free access to Gemini Pro and NotebookLM. Sovereignty delivered as a free tier on someone else’s proprietary model. That is customer acquisition wearing a flag.

The test

Google is not the only offender. Microsoft was asked under oath at the French Senate whether it could guarantee French data would never reach US authorities and answered “non, je ne peux pas le garantir.” NVIDIA books national independence as a $30bn revenue segment. Armor shipped a product literally named “Sovereign AI” whose two launch releases never name the underlying infrastructure and never explain the name.

But Google is the one that has industrialised it — four years of shipping the word across a cloud tier, a JV, an air-gapped box, a showroom, a continental MoU, and now a peer-to-peer mesh whose defining feature is that Google can switch your nodes off.

So: one question, asked of every vendor selling you sovereign anything.

Which sovereign — and against whose legal process?

SAM’s README never answers it. Armor’s launch never answers it. Versa answers “deployment model.” Google answers with encryption keys, which is an answer to a different question entirely.

Sovereignty is not a feature you can ship. It is a control position you either hold or you don’t — over the crown jewels, with the risks named out loud and accepted on purpose.

Everything else is theatre with a compliance budget. And theatre with a kill switch is not theatre. It’s a lease.

— Amit


SAM read from source at HEAD 674af93, 23 Aug 2026. Peer comparison from source audits of slackhq/nebula, netbirdio/netbird, juanfont/headscale, zerotier/ZeroTierOne and spiffe/spire.

Sources: github.com/google/sam · Google Cloud ToS · EU Data Boundary limitations · Google government-requests whitepaper · Advancing digital sovereignty on Europe’s terms, 2022 · EC sovereign cloud award, 17 Apr 2026 · The Register on the SEAL scores · GDC air-gapped · AUC–Google MoU · French Senate report No. 830 · NVIDIA Q4 FY26 call

Article Categories

Join our community on YouTube

Join the community that includes more than 15,000 #CubeAlumni experts, including Amazon.com CEO Andy Jassy, Dell Technologies founder and CEO Michael Dell, Intel CEO Pat Gelsinger, and many more luminaries and experts.
"Your vote of support is important to us and it helps us keep the content FREE. One click below supports our mission to provide free, deep, and relevant content. "
John Furrier
Co-Founder of theCUBE Research's parent company, SiliconANGLE Media

“TheCUBE is an important partner to the industry. You guys really are a part of our events and we really appreciate you coming and I know people appreciate the content you create as well”

Book A Briefing

Fill out the form , and our team will be in touch shortly.
Skip to content