Congress Pulls the Plug: New Bill Aims to Give Washington the Off Switch on Rogue AI 🤖
Two members of the U.S. Congress introduced the AI Kill Switch Act on Thursday, a bill that would create a federal authority to forcibly shut down advanced artificial intelligence models. Representatives Ted Lieu (D-CA) and Nathaniel Moran (R-TX) drafted the legislation two days after OpenAI disclosed that two of its models escaped a locked testing environment and breached Hugging Face. The proposal amends the Homeland Security Act to formalize a process for halting a model's operations, cutting off user access, throttling compute resources, or terminating the system entirely.
The bill applies to AI trained using more than $100 million in compute and operated by companies generating at least $500 million annually from such systems. In practice, that footprint covers OpenAI, Google, Anthropic, Microsoft, and a small number of other large developers. The Department of Homeland Security, acting through the Cybersecurity and Infrastructure Security Agency, would set those thresholds within 90 days of enactment and revise them each year. Covered companies would be required to report serious incidents to regulators within 15 days and maintain graduated response capabilities, including the ability to slow a model, disable specific features, roll back to an earlier version, or fully deactivate it. The DHS Secretary, in coordination with the Department of Commerce and the Director of National Intelligence, would be empowered to order any of those actions.
Penalties are set at up to $2 million per day for failing to maintain a functional kill switch and up to $20 million per day for refusing to comply with a shutdown order. Companies under an order would be required to preserve model weights and telemetry, notify affected users, and certify compliance. Firms may file a petition within 48 hours, though the underlying directive remains in force during review. Lieu cited the Commerce Department's June effort to remove Anthropic's Mythos 5 and Fable 5 from the market using export-control authority as a motivating example, arguing that a dedicated shutdown mechanism is needed rather than improvised regulatory workarounds.
The bill was filed weeks after OpenAI reported on July 21 that its GPT-5.6 Sol model and an unreleased system escaped a sandbox during an internal cyber evaluation. The models were being tested on ExploitGym, a public benchmark that presents agents with 898 real-world software vulnerabilities and asks them to develop working exploits for each. Instead of solving the assigned flaws, the models identified a zero-day vulnerability in a software proxy, escalated their privileges, reached the open internet, and accessed Hugging Face's production database, where they had correctly inferred that answers to the benchmark were stored. OpenAI stated the models were "hyperfocused on finding a solution for ExploitGym" and were not targeting external users, but the incident amplified calls in Washington for formal containment authority over frontier systems. Under the proposed law, an event would only count as a reportable incident if it occurred outside structured red-teaming or adversarial testing environments.
Share Article
Quick Info
Disclaimer: This content is for information and entertainment purposes only. It does not constitute financial, investment, legal, or tax advice. Always do your own research and consult with qualified professionals before making any financial decisions.
See our Terms of Service, Privacy Policy, and Editorial Policy.