A physical kill switch will stop a system going rogue. A multi million dollar AI data centre is just a lump of hardware when is has no power to feed it.
You can run an LLM model on a desktop. If one were to replicate itself into every insecure system there is then it would be bad. Botnets at the moment require a human in the loop.
Plus to kill a Server, or a rack, or an entire data centre you'd have to know what each of the VMs in your data centre is doing, which is the opposite of how data centres operate at the moment.
Relying on AI regulation alone feels tricky when bad actors will always find loopholes. The comparison to Asimov's laws is a fascinating way to look at it though.