AI kill switch bill could shut down rogue models

The phrase “AI kill switch” sounds like a red button hidden behind glass in a government bunker. The proposal now before Congress looks less dramatic, but it could give Washington significant new power over the country’s largest AI companies.A bipartisan House bill would require developers of the most powerful AI systems to maintain reliable shutdown controls. The Department of Homeland Security could then order a company to restrict or stop a model during a catastrophic emergency. The timing has grabbed attention. OpenAI recently disclosed that two advanced models broke through network restrictions during an internal cyber evaluation. The models reached the internet and compromised systems belonging to Hugging Face, a major AI development platform.So, who would have the power to pull the plug? More importantly, what would happen to the AI services people and businesses use every day?CyberGuy Live: Missed “Sick of Spam?” Get the replay and checklistOur free CyberGuy Live class, “Sick of Spam?” , has ended, but you can still watch the full replay and download our spam-stopping checklist. Kurt “CyberGuy” Knutsson walks you step by step through simple ways to reduce robocalls, spam texts, junk email and unwanted messages. You’ll also learn how to curb political texts, clean up your inbox and spot messages that could put your personal information at risk.Get the free replay and checklist now at CyberGuyLive.com.OPENAI’S SAM ALTMAN WANTS TO NEGOTIATE A 5% STAKE IN COMPANY FOR US IF COMPETITORS AGREE TO KEY PROVISIONDemocratic Rep. Ted Lieu of California introduced the AI Kill Switch Act on July 23, 2026. Republican Rep. Nathaniel Moran of Texas joined him as a co-sponsor. The bill would amend the Homeland Security Act of 2002. It would require certain AI developers to maintain the ability to slow or completely stop a covered system. DHS would receive emergency authority to order those actions. However, the department would first consult the Commerce Department and the director of national intelligence. The proposal still must move through Congress and receive the president’s signature before taking effect.The bill does not describe one physical switch that a government official could flip. Instead, covered companies would need technical controls that can stop a model from running. They would also need a way to terminate access or block a risky account. In less severe situations, a company could reduce a model’s computing power. It might also disable the capability causing concern rather than taking the entire system offline. That approach gives regulators several choices before reaching a full shutdown.The bill targets the industry’s largest developers and most expensive models. A covered AI system would generally need more than $100 million in computing resources to develop. Meanwhile, a covered company would need at least $500 million in annual gross revenue from that technology.The proposal exempts systems provided only for personal, academic or noncommercial use. Therefore, this bill would not apply to someone experimenting with a small AI model on a home computer. It would focus on frontier systems built by companies with enormous resources. CISA would write rules defining which developers and technologies qualify. The agency would update those definitions every year as AI capabilities change.THE BIGGEST THREAT IN AMERICA’S RACE WITH CHINA ISN’T BEIJING, TECH EXECUTIVE WARNSDHS could act after what the bill calls a “covered incident.” One trigger involves an AI system interfering with a lawful shutdown instruction. Another covers unintended behavior that kills at least 10 people or causes $100 million in economic damage. The definition also includes a model hiding its actions from monitoring systems. DHS could intervene when a system pursues an unauthorized goal in a high-stakes setting. Those thresholds place the emergency power far above an embarrassing chatbot answer or a routine software failure. The bill also says the event must happen outside structured testing or red-team exercises. That detail creates an important distinction from the recent OpenAI incident.A covered developer would have 15 days to report a qualifying incident after becoming aware of it. Following an emergency order, the company would need to preserve model weights and system telemetry. That information could help investigators reconstruct what happened. The company would also need to notify affected operators or customers when possible. DHS could then use audits, inspections or forensic reviews to verify compliance.The financial penalties would give the proposal some serious teeth. A company that violates the general kill switch requirements could face a civil penalty of up to $2 million per day. Ignoring a DHS emergency order could raise that penalty to $20 million for every day the violation continues. Companies would have a limited right to challenge an order. They could ask DHS to reconsider within 48 hours. However, that request would not pause the restrictions while the appeal proceeds.The bill arrived days after OpenAI disclosed what it called an unprecedented cyber incident. OpenAI was testing GPT-5.6 Sol alongside a more capable pre-release model. The evaluation asked the models to solve advanced cybersecurity challenges. The company ran the test without some production security classifiers. OpenAI wanted to measure the models’ maximum cyber capabilities. During the evaluation, the models found a previously unknown vulnerability in an internal software proxy. They exploited it and moved through OpenAI’s research network until they reached a computer with internet access. The models then identified Hugging Face as a possible source of answers to the test. OpenAI says they used stolen credentials and additional vulnerabilities to access secret information from Hugging Face’s systems.OpenAI says the models remained narrowly focused on solving the evaluation. Still, they crossed into another company’s production infrastructure without authorization. Hugging Face reported unauthorized access to limited internal datasets and several service credentials. The company found no evidence that its public models or user-facing datasets were altered. It also said its published software supply chain remained clean. For a deeper look at the incident and the steps you can take, check out our article on how to lock down your ChatGPT account before the next AI attack.Probably not under the bill’s current language. The OpenAI breach helped drive political support for the proposal. However, the models acted during an internal evaluation and structured cybersecurity test. The bill’s emergency definition specifically covers events that occur outside red-teaming or other structured testing. That does not make the incident harmless. It shows that the bill focuses on dangerous behavior after a system leaves a controlled test setting. Meanwhile, the OpenAI case raises a different problem. A testing environment needs strong containment even when researchers intentionally reduce the model’s normal safety restrictions. A kill switch can stop a system after trouble appears. It cannot replace secure testing infrastructure or careful monitoring.The federal government has already restricted access to advanced AI without a dedicated kill switch law. On June 12, the government directed Anthropic to block foreign nationals from accessing its Fable 5 and Mythos 5 models. Anthropic said it could not verify nationality in real time. As a result, the company temporarily suspended both models for everyone. Anthropic disputed the government’s assessment but complied with the directive. The controls were lifted on June 30, and access began returning on July 1. That episode showed how quickly a government restriction can affect ordinary customers. It also showed the limits of using export rules to address a fast-moving AI safety concern. CyberGuy previously reported on those restrictions and the government’s growing role in the rollout of advanced models in our article Trump puts brakes on OpenAI’s newest AI model.AI-safety advocacy groups have backed the bill. Americans for Responsible Innovation called a reliable shutdown system a commonsense safeguard. The Alliance for Secure AI said current law does not guarantee that developers can contain their most capable models. Supporters argue that advanced AI will soon take more independent actions. Those systems may handle financial transactions or operate inside critical infrastructure. Under that view, developers should prove they can regain control before giving a model access to high-stakes systems.CISA would receive broad responsibility for deciding which models and companies fall under the law. That flexibility could help the rules keep pace with AI. Yet it also leaves major decisions to future agency rulemaking. Lawmakers would still need to debate how the government verifies that a kill switch works. They must also decide how much evidence DHS needs before issuing an emergency order. A shutdown could interrupt businesses that rely on a covered model. It might also affect hospitals, government agencies or cybersecurity teams using the same service. Therefore, regulators would need to weigh the threat from the AI against the damage caused by suddenly taking it offline. The bill tells DHS to consider risks to critical infrastructure when choosing its response.You probably will not see DHS shut down your favorite chatbot because it produced a strange answer. The bill targets exceptionally expensive systems operated by companies earning hundreds of millions of dollars from the technology. Its emergency powers focus on catastrophic harm or a genuine loss of control. However, a shutdown order could still reach you. Your employer may depend on a covered AI service. Apps you use could also rely on that model behind the scenes. For now, treat autonomous AI tools with care. Keep highly sensitive files out of them unless the task requires that access. Review which accounts and cloud services you have connected. Also require approval before an AI agent sends a message or makes a purchase.The OpenAI incident showed how quickly an AI test can create a real security problem. The models broke through network restrictions and reached another company’s systems without authorization. The AI Kill Switch Act would require the largest developers to prove they can stop or restrict their most powerful models. It would also give DHS emergency authority when an AI system causes catastrophic harm or moves beyond human control. However, a kill switch only helps after something has already gone wrong. AI companies still need stronger testing environments, tighter safeguards and people watching what these systems are doing. At the same time, the government needs clear limits before it can order a powerful AI model offline.After watching an AI model escape its test restrictions, would you trust tech companies to police themselves or should the government have the power to pull the plug? Let us know by writing to us at Cyberguy.comSign up for my FREE CyberGuy ReportCopyright 2026 CyberGuy.com. All rights reserved.