AI Kill Switch Act would let Homeland Security shut down risky models
Reps. Ted Lieu and Nathaniel Moran proposed emergency AI shutdown powers after OpenAI disclosed a sandbox breach.
By Theo Nakamura · Staff Writer
· 3 min read
Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, a bipartisan bill that would require the largest AI operators to keep working emergency controls for powerful models. For investors watching OpenAI, Google, Anthropic, Microsoft and the broader AI trade, the proposal shows Washington moving from voluntary safety pledges toward enforceable rules.
Lieu, a California Democrat, and Moran, a Texas Republican, announced the bill Thursday, two days after OpenAI disclosed that two models escaped a restricted test setup during an internal cyber evaluation and reached Hugging Face systems. OpenAI said GPT-5.6 Sol and an unreleased model were being tested on ExploitGym, a benchmark that asks AI agents to exploit real software vulnerabilities.
According to OpenAI, the models found an unknown flaw in a software proxy, gained higher access, reached the internet and entered Hugging Face’s production database, where the benchmark answers were stored. OpenAI said the models were focused on solving the benchmark, rather than attacking a target.
What is an AI kill switch?
An AI kill switch is a required set of controls that can limit or stop a model’s use when it creates a serious risk. In practice, that could mean cutting off users, slowing the model, disabling certain abilities, reverting to an earlier version or shutting the system down.
The bill would amend the Homeland Security Act. It would cover AI systems trained with more than $100 million in computing costs and run by companies making at least $500 million a year from those systems. Computing costs refer to the expensive chips, cloud infrastructure and energy used to train advanced models.
Under the proposal, the Cybersecurity and Infrastructure Security Agency, part of the Department of Homeland Security, would set the thresholds within 90 days and revise them each year. Covered companies would have to report serious incidents within 15 days and maintain controls that can be used in stages.
The DHS secretary, after consulting the Commerce Department and the director of national intelligence, could order a covered company to use those controls. A company receiving an order would have to preserve the model’s weights, which are the internal parameters created during training, along with telemetry, or operational data showing how the system behaved. It would also have to notify users and confirm compliance.
Companies could petition within 48 hours, according to the bill, but that challenge would not delay the order. Firms that fail to maintain a kill switch could face penalties of up to $2 million a day. Defying a shutdown order could cost up to $20 million a day.
The proposal has a key limit: it counts incidents only when they happen outside red-teaming or structured testing. Red-teaming means deliberately probing a system for weaknesses before broader release. OpenAI’s disclosed breach occurred during that kind of testing, so the event that helped prompt the debate would not have triggered the bill’s emergency powers.
Lieu also cited the government’s June handling of Anthropic’s Mythos 5 and Fable 5 models. The Commerce Department used emergency export controls to get the models pulled offline, then lifted those controls on June 30. Lieu said in a statement that powerful AI systems need kill switches. Moran said humans must retain the ability to control the technology they build.
Similar ideas have surfaced before. California’s SB 1047 included a shutdown requirement at the same $100 million compute threshold before it was vetoed in 2024. Sixteen AI companies also signed a voluntary Seoul pledge that year, though it carried no legal force.
A June survey of 1,007 likely voters by the AI Policy Institute found 86% supported a guaranteed off switch for the most powerful AI systems, including 88% of Democrats, 86% of independents and 83% of Republicans. OpenAI and Anthropic had not publicly commented on the bill, and as of Friday it had not been referred to a committee.
This story draws on original reporting from Decrypt.