The andon cord comes from the Toyota Production System, where any worker on the assembly line could pull a physical rope to halt production the instant something looked wrong, no committee approval or business case required. The mechanism mattered more than the individual’s judgment: Toyota didn’t trust any one person to always be right, so it built a stop that anyone could pull and made pulling it the expected, unpunished response to doubt.
Most AI governance frameworks describe this idea in policy language, a section on incident response or escalation paths, without ever building the actual mechanism. The gap shows up as delay: by the time a genuine problem is confirmed through the proper channels, the system has usually been live and causing harm for weeks. A real andon cord needs a named individual, not a committee, an explicit trigger for what counts as a defect, and a cultural guarantee that pulling it early is treated as the system working.
The test of whether an AI programme has one: ask who can stop a deployment today, at 3pm, without first building a case for it. If the honest answer takes more than one name, the cord does not yet exist.