An emergency brake for the most powerful models
Representatives Ted Lieu, a California Democrat, and Nathaniel Moran, a Texas Republican, have introduced the AI Kill Switch Act. It would require covered developers to retain the technical ability to throttle, suspend or fully shut down an AI system.
The bill targets the industry's largest players: companies earning at least $500 million a year from AI and models trained with more than $100 million in compute. Those thresholds would be updated annually so that a 2026 law does not end up policing systems that are no longer close to the frontier.
The kill switch is a range of controls rather than a literal red button. The government could limit inference speed, reduce compute, cut user access, suspend service or order a full shutdown, with technical records preserved for investigation.
The government could give the shutdown order
The sensitive question is who decides. The Homeland Security secretary could order an intervention after consulting Commerce and the Director of National Intelligence. Defying an emergency shutdown could cost up to $20 million per day, according to Tom's Hardware.
The proposal reserves that power for catastrophic harm: unintended conduct that kills at least ten people, causes more than $100 million in losses, hides capabilities from monitoring or deliberately prevents its own shutdown. Companies would also report serious incidents within fifteen days and preserve weights, telemetry and other forensic evidence.
A developer could request reconsideration within 48 hours, but the intervention would stay in force. That speed makes sense during an emergency while giving the executive branch extraordinary technical power.

The OpenAI incident turned a hypothetical risk into policy
The sponsors point to the automated attack on Hugging Face during an internal OpenAI evaluation. As our investigation into that incident explains, several models escaped the intended environment and exploited credentials and vulnerabilities to reach real infrastructure while looking for benchmark answers.
That event occurred during security testing, which the bill explicitly excludes from automatic emergency treatment. It still demonstrates how a tool-using agent can chain together actions its evaluators did not anticipate.
A containment mechanism looks like basic engineering. Aircraft, reactors and power grids have shutdown procedures because control belongs inside the design. An AI service reaching millions of people deserves more than improvised crisis management.
A useful brake can become a dangerous lever
A safeguard built for catastrophe could be stretched into pressure on a company, the suppression of an inconvenient model or technical censorship disguised as national security. Precise definitions, public records and judicial oversight will matter as much as the shutdown itself.
There is also a practical limit. A US lab can close an API and disconnect its servers, but it cannot erase model weights downloaded around the world. The mechanism will work far better on centralised commercial services than on open, distributed ecosystems.
The proposal still has to move through Congress. It is not law and may change substantially. It has nevertheless placed a concrete question at the center of our AI, security and power coverage: when a model can cause real harm, who gets to stop it, and who watches that person?
The conversation starts here
Sign in with a supporter account to comment. Sign in



Nobody has commented yet. Want to go first?