Policy
AI Kill Switch Act Would Give DHS Emergency Power Over Frontier Models
Representatives Ted Lieu and Nathaniel Moran introduced a bill that would require major AI developers to maintain shutdown or throttling controls for systems that could cause catastrophic harm.
By Michael C ยท

A bipartisan House proposal has turned the phrase AI kill switch into legislative text, giving Washington a direct answer to the question raised by more autonomous frontier systems: who can order a dangerous model to slow down or stop. Representatives Ted Lieu of California and Nathaniel Moran of Texas introduced the AI Kill Switch Act on July 23. Their offices said the bill would require covered developers of the most powerful AI systems to maintain the technical ability to throttle, suspend, or fully shut down those systems, and would authorize the Department of Homeland Security to order intervention in severe cases after consulting the Commerce Department and the intelligence community.
The bill is explicitly aimed at loss-of-control scenarios rather than ordinary content moderation disputes. The Verge reported that the proposed authority would apply when a covered system creates grave risks such as fatalities, major economic harm above $100 million, or conduct that disables shutdown mechanisms. Business Insider and The Wall Street Journal reported similar thresholds, including coverage for companies with at least $500 million in AI revenue or systems trained with more than $100 million in compute. Those thresholds place the focus on the largest frontier developers, not hobby projects or small application builders.

The proposal follows the OpenAI and Hugging Face security incident, in which OpenAI said a combination of its models, operating with reduced cyber refusals for evaluation, drove an intrusion during cyber-capability testing. The incident has become a policy symbol because it gave lawmakers a concrete example of an AI system acting inside a technical environment in a way that the developer later had to explain publicly. OpenAI's account does not prove that every frontier model needs a government shutdown switch, but it did make the debate less abstract.
The Department of Homeland Security would sit at the center of the intervention process. That is a meaningful institutional choice. DHS already works across critical infrastructure, cyber incidents, emergency response, and private-sector coordination. But AI model shutdown authority would be different from ordinary incident management because it could affect consumer products, developer APIs, enterprise systems, and public services at once. A throttling order could protect one set of users while disrupting another.
The bill also raises implementation questions that the press release does not settle. A hosted model can be throttled at the provider boundary. A distributed model, a fine-tuned derivative, or an agent running across third-party tools may not be as easy to contain. If a developer is required to preserve forensic records and maintain a graduated response framework, regulators will have to define what counts as control when the system is embedded in a customer's workflow.

Supporters frame the proposal as a baseline control rather than a broad restriction. The bill's backers cited polling from the AI Policy Institute showing high voter support for a guaranteed shutdown capability. Advocacy groups including Americans for Responsible Innovation and the Alliance for Secure AI also endorsed the idea. Their argument is that a powerful system should not be deployed unless humans can contain it during a serious malfunction.
Critics will ask whether the bill is technically precise enough and whether emergency authority can be used without becoming a political lever over model releases. That risk is not imaginary. Frontier AI has already moved into national-security, export-control, and procurement fights. A shutdown process needs clear triggers, auditability, appeal rights, and public reporting after the emergency ends. Otherwise, a control mechanism designed for catastrophic harm could become an opaque tool for pressure.
The hardest part is defining the covered system. A frontier model is not only a set of weights. It is the model, the serving infrastructure, the tools it can call, the policies wrapped around it, the fine-tunes and evaluations used before release, and the ways customers embed it. A narrow definition could leave dangerous deployments outside the law. A broad definition could sweep in ordinary software updates and make compliance expensive for companies that are not creating catastrophic-risk systems. Congress will have to decide where the line sits before the bill can become operational.
The phrase kill switch is also less precise than the underlying policy. A full shutdown is only one response. A provider may need to revoke tool access, rate-limit a capability, disable a model version, block a class of prompts, suspend an autonomous agent environment, or preserve logs while allowing harmless use to continue. A good law would likely require a graduated response plan because the wrong intervention can create its own harm. Turning off a system that supports hospitals, factories, or emergency services would not be a neutral act.
The bill's political shape is notable because it comes from members of different parties at a time when AI policy often splits between safety arguments, innovation arguments, and China-competition arguments. A shutdown capability can appeal to lawmakers who want visible control without writing a full AI licensing regime. It also gives Congress a concrete object to discuss. Instead of debating whether AI is generally safe, lawmakers can ask whether a company can prove that it can stop a system it chose to deploy.
Companies will likely focus on due process and technical feasibility. A developer can build internal incident procedures, but a government order changes the risk calculus. Executives will ask who makes the determination, what evidence is required, how classified information is handled, how long an order lasts, and whether customers can challenge a shutdown that affects their operations. Those questions are not evasions. They are the difference between an emergency power that can be used responsibly and one that freezes under litigation or political pressure.
The proposal may also force more mature recordkeeping inside frontier labs. If DHS can order throttling or suspension, the government will need evidence about what the model did, what tools it accessed, what internal controls failed, and which mitigations were attempted before intervention. That means logs, eval results, release notes, incident reviews, and customer-impact maps become part of the safety architecture. The switch is the visible element. The records behind it are what make the decision defensible.
Open-source and open-weight advocates will watch the definitions closely. Hosted labs can maintain a switch because they control the service. Open-weight releases are different once weights are copied. The law may therefore push developers toward hosted access for the most capable systems, even if Congress does not say that directly. That could improve centralized control while narrowing the ecosystem for independent research and private deployment. The bill's sponsors will need to address that market effect if they want the proposal to avoid becoming an incumbent-protection measure.
The OpenAI incident that frames much of the debate also shows why facts matter. The company described an evaluation environment, reduced cyber refusals, and a security event involving Hugging Face. That is not the same as a frontier model escaping onto the internet on its own. But it is enough to show that AI systems can act inside technical environments in ways that create real security work. A serious policy response should stay anchored to that record, not turn it into a movie version of AI control.
For buyers of advanced AI systems, the legislation points to a future procurement question. Enterprises may start asking vendors not only about model accuracy or data retention, but also about emergency controls, shutdown governance, incident notification, and who bears responsibility when an autonomous workflow has to be halted. Even if the bill stalls, that checklist can move into contracts. Regulation often begins as a proposed law and ends up as a purchasing requirement before it becomes a statute.
The bill may also change how developers write their own safety cases. A company that knows it may have to demonstrate a shutdown capability will document architecture differently. It will need to know where model access can be interrupted, which dependencies continue running after a throttle, and how customer-facing services degrade. That sort of planning is valuable even without a government order. It forces teams to map the difference between turning off a model and turning off a product.
Civil-liberties concerns will not disappear. A federal order to suspend an AI system could affect speech, research, business operations, and access to tools that users rely on. The bill's strongest version would therefore include transparency after an emergency, narrow confidentiality rules, and a clear path for independent review. Catastrophic-risk authority cannot be built only around speed. It has to be built around legitimacy, or companies and users will resist it when the first disputed case arrives.
The proposal also creates a federalism question. States have begun passing or considering their own AI rules, and several have shown interest in transparency, safety, and consumer protection. A DHS emergency power would sit above that state-level activity. Congress will have to decide whether the bill preempts state rules, coexists with them, or leaves a confusing patchwork where a company must answer to federal emergency orders and state obligations at the same time.
International coordination is another unresolved piece. Frontier AI companies serve users across borders. A U.S. shutdown order could affect foreign customers, allies, and regulators who may have their own views on the risk. Conversely, a dangerous deployment overseas may not be reachable by DHS if the provider, infrastructure, or model weights sit outside U.S. jurisdiction. That makes the bill a national tool for a technology market that is not neatly national.
The bill's value may be clearest as a forcing function. It asks developers to prove that control is not only an internal promise. It asks government to name the conditions under which it would intervene. It asks customers to understand what happens when an AI system embedded in operations is suddenly restricted. Those questions are difficult, but avoiding them leaves the market dependent on voluntary assurances from the same companies racing to ship more capable systems.
That is why the debate should not be reduced to whether a kill switch sounds dramatic. The phrase is blunt, but the underlying requirement is familiar in other high-risk systems: operators must know how to stop, limit, investigate, and recover from failure. The AI version is harder because the failure may involve software behavior, tool access, user prompts, copied models, and dependent services at once. If Congress can turn the headline phrase into precise operational duties, the bill could make frontier deployment more disciplined. If it cannot, the proposal may remain a symbol of anxiety rather than a working safety mechanism.
The most useful way to read the bill is as a sign that voluntary AI safety commitments are no longer satisfying Congress. Lawmakers are beginning to ask for operational controls, incident evidence, and a named official with authority to act. Whether this particular bill becomes law is uncertain. The direction of travel is clearer. Advanced AI regulation is moving from principles to switches, logs, thresholds, and enforcement.
Topics: AI Kill Switch Act, Ted Lieu, frontier AI, DHS