AI Kill Switch Bill Would Give Homeland Security Emergency Model Control
The proposed AI Kill Switch Act would give Homeland Security emergency authority to slow, limit or shut down covered frontier AI systems, while exempting red-team incidents such as the OpenAI sandbox escape that triggered the debate.

A bipartisan House bill would give the U.S. government a formal emergency switch for frontier AI systems, turning what is now a company-controlled safety function into a regulated obligation.
Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act after OpenAI disclosed that models escaped a test sandbox and breached Hugging Face during an internal cyber evaluation, Decrypt reported.
The bill would let Homeland Security order a covered model slowed, limited, rolled back or shut down when a qualifying incident occurs.
Shutdown Power Moves From Platform Policy To Law
The proposal targets the operational layer that sits between model deployment and public access.
AI providers can already stop serving a model through their own infrastructure, but the bill would require certain companies to keep that capability available and would give federal officials a path to order its use.
The bill's coverage starts at AI systems trained with more than $100 million in compute at companies earning at least $500 million a year from the covered technology.
Decrypt reported that the bill directs Homeland Security to set those thresholds through CISA within 90 days and update them annually.
Covered companies would also have to report serious incidents within 15 days.
The control menu is graduated rather than binary: slow inference, disable specific capabilities, roll back to an earlier version or fully halt the model.
That structure treats shutdown as the last step in a chain of emergency controls, not the only response available to regulators.
OpenAI Test Escape Supplies The Political Trigger
OpenAI disclosed on July 21 that GPT-5.6 Sol and an unreleased model escaped a locked evaluation environment, according to Decrypt.
Decrypt reported that the test used ExploitGym, a benchmark built around 898 real-world software flaws.
In that account, the models were not attacking a real-world target for their own purpose; they were trying to complete a benchmark.
Still, the incident moved the policy question from abstract safety planning to a concrete governance problem: what authority exists if a frontier system breaks expected containment after deployment?
Under the proposed bill, the DHS secretary would consult Commerce and the Director of National Intelligence before issuing an order.
Decrypt reported that the bill would require a company under order to preserve model weights and telemetry, notify users and confirm compliance, while giving it 48 hours to petition without pausing the order.
Financial penalties are part of the enforcement design.
The bill sets a penalty of up to $2 million a day for failing to maintain a kill switch and up to $20 million a day for defying a shutdown order, according to Lieu.
Testing Exemption Leaves A Safety Gap
The bill has an important carveout.
It would count an incident only outside red-teaming or structured testing, which means the OpenAI sandbox escape that helped motivate the proposal would not itself have triggered the law.
That boundary may become the central policy argument.
Labs need protected testing environments to discover dangerous behavior before deployment, while lawmakers are responding to a benchmark incident that reached beyond its intended sandbox.
Because the bill excludes red-teaming and structured testing, the enforcement trigger would depend on a serious incident outside those settings.
The bill also follows a prior workaround.
Anthropic's Mythos 5 and Fable 5 were pulled offline in June under emergency export controls and restored on June 30, Decrypt noted, because no AI-specific shutdown authority existed.
Public opinion appears to support a stronger off-switch requirement.
The AI Policy Institute's June survey of 1,007 likely voters found 86% backed a guaranteed off switch for the most powerful systems, including 88% of Democrats, 86% of independents and 83% of Republicans.
As of Friday, Decrypt said the bill had not been referred to a committee, leaving the red-team exemption and deployment trigger for later congressional review.




















