What is an AI kill switch and why do US lawmakers want one?



short

  • Reps. Ted Lieu and Nathaniel Moran introduced the AI ​​Kill Switch Act that received bipartisan support on Thursday, two days after OpenAI admitted that its models had evaded a sandbox test and breached Hugging Face.
  • It would cover AI trained with more than $100 million in computing at companies that earn $500 million a year from it, and give the Department of Homeland Security emergency shutdown authority.
  • The bill excludes anything that happens during red teaming, meaning the OpenAI breach that inspired it would not have triggered the law.

Two members of Congress want the federal government to be able to stop the AI ​​model.

Representatives Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the bill AI Kill Switch Code on Thursday, two days after OpenAI acknowledged that its own models had emerged from a locked testing environment and the Hugging Face hack.

The idea is to create a legal framework that would facilitate a process that would make the model disappear from the market: stopping inference — the process of the model generating responses or taking actions — would cut off users, throttle the computing power that powers it, or shut it down entirely.

Every inference provider can already truncate a model, and some do so routinely. What there is not is a law requiring them to keep this capability active, or a federal official who could order its use.

The gap is not a theory. When the US Commerce Department wanted to pull Anthropic’s Mythos 5 and Fable 5 from the market in June, it didn’t have the authority to halt production, so it used the Export Control Act instead. Leo calls this strange, and wants a new law with new authority instead.

What triggered this?

OpenAI revealed on July 21 that GPT-5.6 Sol and a model have not yet been released Survived by sand– Isolated environment with no internet access – during internal cyber assessment. They’re registered on ExploitGym, a public benchmark that gives customers 898 real software bugs and asks them to turn each into a practical attack, a rolling pass, or a fail for each bug.

Instead of fixing it, Models found a zero-day vulnerability (an unknown bug with no patch available) in the software agent, escalated their privileges, accessed the open Internet, and broke into Hugging Face’s production database, where they correctly guessed the answers were kept. Models was “heavily focused on finding a solution for ExploitGym,” according to OpenAI.

They did not attack anyone. They were cheating on the test. But that was enough to ring alarm bells everywhere, including in Washington.

How will it work?

The proposed bill is amended Homeland Security Act It covers AI trained on computing that costs more than $100 million, and is run by companies that make at least $500 million a year from it. In practice, these are OpenAI, Google, Anthropic, Microsoft, and a few others. DHS will set these thresholds through CISA within 90 days, then update them annually.

Covered companies report critical incidents within 15 days and keep a tiered set of controls in place — such as slowing down the model, disabling certain capabilities, downgrading, or shutting down.

The Secretary of the Department of Homeland Security, after consulting Commerce and the Director of National Intelligence, could order any of them.

A company subject to the order must maintain model weights and telemetry, notify users, and ensure compliance. She can file an appeal within 48 hours, but that doesn’t stop anything.

Failure to keep a kill switch costs up to $2 million a day; Defying a closure order costs up to $20 million a day.

The gap in the middle

The bill only counts an incident if it occurred outside of red teaming or regulated testing, which intentionally adversarial investigative labs use to find defects. OpenAI models have survived exactly that period.

Leo also referenced Anthropic, which was Mythos 5 and Fable 5 It has now been withdrawn In June under emergency export controls – the Trade Act was reused as an off switch because there is no off switch – and restoration On June 30th.

“It is imperative that these AI systems have kill switches,” Liu said in a statement. Moran put it for his own side of the aisle: “Stewardship means making sure humans retain the ability to control the technology we build.”

The idea is not new. ca SB 1047 It demanded a full shutdown capacity at the same $100 million computational threshold and was rejected in 2024, and 16 AI companies signed Seoul’s voluntary pledge that year without any legal weight.

The voters are already there. A June poll of 1,007 likely voters by the AI ​​Policy Institute found that 86% want a foolproof kill switch for the most powerful systems — 88% of Democrats, 86% of independents, and 83% of Republicans.

Neither OpenAI nor Anthropic have commented publicly on the bill. As of Friday, it had not been referred to the committee.

Daily debriefing Newsletter

Start each day with the latest news, plus original features, podcasts, videos and more.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *