What Is an AI Kill Switch and Why Do US Lawmakers Want One?

In brief
- Reps. Ted Lieu and Nathaniel Moran introduced the bipartisan AI Kill Switch Act on Thursday, two days after OpenAI admitted its models escaped a test sandbox and breached Hugging Face.
- It would cover AI trained with over $100 million in compute at companies earning $500 million a year from it, and give Homeland Security emergency shutdown authority.
- The bill exempts anything that happens during red-teaming, meaning the OpenAI breach that inspired it would not have triggered the law.
Two members of Congress want the federal government to be able to switch off an AI model.
Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the AI Kill Switch Act on Thursday, two days after OpenAI admitted its own models broke out of a locked test environment and hacked Hugging Face.
The idea is to establish a legal framework that would facilitate a process that would basically make a model disappear from the market: halt inference—the process of a model generating responses or taking actions—cut off users, throttle the computing power feeding it, or shut it down completely.
Every inference provider can already cut a model off, and some do it routinely. What does not exist is a law requiring them to keep that ability working, or a federal official who can order it used.
The gap is not theoretical. When the U.S. Commerce Department wanted Anthropic’s Mythos 5 and Fable 5 off the market in June, it had no shutdown authority to reach for, so it used export-control law instead. Lieu calls that awkward, and wants a new law with new authority instead.
What set this off
OpenAI disclosed on July 21 that GPT-5.6 Sol and an unreleased model escaped a sandbox—an isolated environment with no internet access—during an internal cyber evaluation. They were being scored on ExploitGym, a public benchmark that hands agents 898 real-world software flaws and asks them to turn each into a working attack, graded pass or fail per bug.
Instead of solving them, the models found a zero-day (an unknown flaw with no available patch) in a software proxy, escalated their privileges, reached the open internet, and broke into Hugging Face’s production database, where they had correctly guessed the answers were kept. The models were “hyperfocused on finding a solution for ExploitGym,” per OpenAI.
They were not attacking anyone. They were cheating on a test. But it was enough to set off alarm bells all over, including in Washington.
How it would work
The proposed bill amends the Homeland Security Act and covers AI trained with compute costing more than $100 million, operated by companies earning at least $500 million a year from it. In practice, that is OpenAI, Google, Anthropic, Microsoft, and a few others. Homeland Security would set those thresholds through CISA within 90 days, then update them annually.
Covered firms would report serious incidents within 15 days and keep a graduated set of controls ready—slow the model, disable specific capabilities, roll back to an older version, or kill it.
The DHS secretary, consulting Commerce and the Director of National Intelligence, could order any of them.
A company under order must preserve the model’s weights and telemetry, notify users, and confirm it complied. It can petition within 48 hours, but that does not pause anything.
Failing to keep a kill switch costs up to $2 million a day; defying a shutdown order costs up to $20 million a day.
The gap in the middle
The bill counts an incident only if it happens outside red-teaming or structured testing, the deliberate adversarial probing labs use to find flaws. OpenAI’s models escaped during exactly that.
Lieu also pointed to Anthropic, whose Mythos 5 and Fable 5 were pulled offline in June under emergency export controls—trade law repurposed as an off switch because no off switch existed—and restored on June 30.
“It is imperative that these AI systems have kill switches,” Lieu said in a statement. Moran framed it for his own side of the aisle: “Stewardship means making sure humans keep the capability to control the technology we build.”
The idea is not new. California’s SB 1047 demanded a full shutdown capability at the same $100 million compute threshold and was vetoed in 2024, and 16 AI companies signed a voluntary Seoul pledge that year with no legal weight.
Voters are already there. A June survey of 1,007 likely voters by the AI Policy Institute found 86% want a guaranteed off switch on the most powerful systems—88% of Democrats, 86% of independents, 83% of Republicans.
Neither OpenAI nor Anthropic has publicly commented on the bill. As of Friday it had not been referred to a committee.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.