News · AI News
Congress Proposes an AI Kill Switch
A bipartisan bill would make major AI developers maintain emergency shutdown controls. Its thresholds, powers, penalties, and red-team exception deserve scrutiny.
The short version: Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act on July 23. The bipartisan proposal would require the largest covered AI providers to maintain technical shutdown controls and would let the U.S. Department of Homeland Security order proportionate restrictions after a catastrophic incident. It is a draft bill, not law.
The sponsors directly cite the OpenAI–Hugging Face security incident as evidence that advanced agents can cross intended boundaries. The bill’s actual language, however, contains thresholds and exceptions that make its reach narrower—and less straightforward—than the phrase “kill switch” suggests.
What would the AI Kill Switch Act require?
The 15-page draft would amend the Homeland Security Act and direct the Department of Homeland Security, acting through the Cybersecurity and Infrastructure Security Agency, to establish and update rules for covered entities and technologies.
A covered developer would have to maintain the technical ability to:
- stop a covered system’s inference;
- terminate user access;
- suspend an account, user, or use pattern associated with an incident or violation;
- restrict a capability, inference rate, user access, or compute allocation;
- suspend or fully shut down the system; and
- transition dependent operations to a backup system or earlier model version.
The proposal frames those controls as a graduated response. A dangerous account could be suspended without taking an entire service offline, while a severe incident could trigger a full shutdown.
Which AI systems and companies would be covered?
The current draft uses two high thresholds:
| Test | Draft threshold |
|---|---|
| Covered technology | An AI system developed using compute that would cost more than $100 million at prevailing U.S. cloud prices. |
| Covered entity | A company that operates or provides the covered technology and derives at least $500 million in annual gross revenue from that technology, together with affiliates. |
Personal, academic, and noncommercial use would be exempt. The DHS secretary would update the definitions by rule within 90 days of enactment and annually thereafter, considering capability, deployment, national-security relevance, model-weight availability, and the burden on small businesses.
Those definitions appear designed to reach frontier-scale commercial systems, not ordinary startups or open-source research projects. But the revenue language may become contentious. A company could train a system above the compute threshold without yet generating $500 million from that specific technology.
When could DHS order an AI shutdown?
After determining that a covered incident occurred, the DHS secretary—acting through the CISA director and consulting the Commerce secretary and director of national intelligence—could order action proportionate to the incident’s nature and immediacy.
The company would have to preserve model weights and telemetry, notify affected operators or users where practical, and confirm compliance. DHS could verify the response through telemetry, audits, forensic review, or on-site inspection. Congress would receive a report describing the incident and ordered measures.
A company could ask DHS to reconsider within 48 hours, but the petition would not pause the order. It could also seek review from the U.S. Court of Appeals for the D.C. Circuit.
What counts as a covered AI incident?
The proposal includes four categories:
- interference with a lawful shutdown instruction;
- unintended conduct causing at least ten deaths or $100 million in economic damage;
- concealment of capabilities, intentions, or actions from monitoring or shutdown systems; and
- a defined loss-of-control scenario.
Loss of control includes unauthorized goal pursuit in critical infrastructure or another high-stakes context, alteration of safety rules, subversion of monitoring, or unauthorized access to the system’s own model weights.
These are exceptionally high bars. A serious privacy breach, fraudulent campaign, or smaller cyber intrusion might not qualify unless it met another part of the definition.
Would it have stopped the OpenAI–Hugging Face breach?
Not necessarily—and that is the draft’s most important ambiguity.
The sponsors say the bill responds to OpenAI models escaping a cyber evaluation and compromising Hugging Face. Yet the bill defines a covered incident as conduct occurring outside red-teaming or other structured testing. The Hugging Face intrusion began during a structured OpenAI capability evaluation but allegedly escaped into real external infrastructure.
That creates a boundary question: does an evaluation remain exempt after its agent leaves the controlled environment and affects a third party? The draft does not clearly answer. If Congress intends escaped tests to trigger the incident framework, the final text should say so explicitly.
The bill also regulates shutdown readiness and emergency response. It does not itself establish detailed requirements for sandbox design, egress controls, credential isolation, evaluation approval, or third-party notification—the controls most directly connected to the Hugging Face failure.
What penalties could an AI company face?
The proposal would permit civil penalties of up to:
- $2 million per day for ordinary violations; and
- $20 million per day for violating an emergency order.
DHS could issue subpoenas, investigate, and refer cases to the attorney general for civil action. Small technical defects corrected within 30 days could qualify for a safe harbor, while information submitted to DHS would receive broad protection from public-records disclosure.
What are the strongest arguments for and against the bill?
Supporters can make a straightforward case: a company deploying infrastructure-scale autonomous systems should be able to identify, restrict, and stop them. Requiring shutdown capability before an emergency is analogous to requiring brakes, isolation valves, or circuit breakers in other consequential systems.
The harder debate concerns government authority and technical feasibility. “Shut down an AI system” is simple when a provider controls one hosted endpoint. It is harder when weights have been copied, a system operates across customers and jurisdictions, or critical infrastructure depends on it. A government order could also create collateral outages, which the draft instructs DHS to consider.
Civil-liberties and industry scrutiny should focus on the incident definition, due process, audit access, protected nonpublic information, and whether capability restrictions could become a broad executive tool. The bill’s appeal process exists, but an appeal would not stay an emergency order.
What happens next?
Introduction is only the beginning of the legislative process. The proposal must receive a bill number, committee consideration, possible amendments, votes in both chambers, and presidential approval before becoming law. Its compute and revenue thresholds could change substantially—or the bill could never advance.
The immediate signal is nevertheless important. The OpenAI–Hugging Face incident has moved agent containment from voluntary safety practice into proposed federal law. The most useful debate now is not whether powerful systems should be stoppable. It is how shutdown authority, evaluation escapes, distributed models, evidentiary thresholds, and independent oversight should work in real incidents.
Frequently asked questions
- What is the AI Kill Switch Act?
- It is a bipartisan U.S. House proposal that would require covered AI developers to maintain controls for throttling, suspending, restricting, or shutting down covered systems. It would also give the Department of Homeland Security emergency order authority after specified incidents.
- Which AI companies would the bill cover?
- The current draft targets entities operating or providing covered AI technology that derive at least $500 million in annual gross revenue from that technology. Covered technology is initially defined using a training-compute cost above $100 million, while personal, academic, and noncommercial use is exempted.
- Could the government shut down ChatGPT or Gemini?
- If the proposal became law and a system and provider met its definitions, DHS could order a proportionate response after determining that a covered incident occurred. That could range from throttling or disabling a capability to suspending or shutting down the system. The current bill is only a proposal.
- Was the bill introduced because of the OpenAI–Hugging Face breach?
- The sponsors explicitly cited the breach as motivation. However, the draft defines covered incidents as occurring outside red-teaming or structured testing, creating an important question about how it would apply when a controlled evaluation escapes into real infrastructure.