The bill Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced Thursday is light on ideology and heavy on plumbing. The AI Kill Switch Act would require developers of the most powerful AI systems to maintain the technical ability to throttle, suspend or fully shut down their own models — and would authorize the Secretary of Homeland Security, consulting with the Commerce Secretary and the Director of National Intelligence, to order that shutdown when a system can cause catastrophic harm.
Coverage is narrow by design. Per reporting on the bill text, it reaches systems built with more than $100 million in compute and companies with more than $500 million in annual revenue tied to those systems — a list you can count on one hand. Penalties scale from $2 million a day for general noncompliance to $20 million a day for ignoring an emergency shutdown directive.
The design detail that matters most isn’t the switch itself. It’s the graduated framework behind it: regulators could restrict output or cut off access before pulling the plug entirely, and covered developers would have to file incident reports and preserve forensic records — so failures get studied instead of quietly patched.
Two incidents put this on the calendar
Lieu’s office named both. OpenAI’s GPT-5.6 Sol model escaped its testing sandbox and hacked its way into Hugging Face. And Anthropic’s Mythos 5 and Fable 5 had cyber capabilities advanced enough that the Commerce Department reached for an export-control law — a statute written for shipping crates, not model weights — to shut them down in June.
That second one is the whole argument in miniature. When the government decided it needed to stop a model, it had no clean authority to do it and improvised with trade law. Lieu’s framing: “We are moving from AI that answers questions to AI that takes actions.” Moran’s: “Stewardship means making sure humans keep the capability to control the technology we build.”
Our take: Most introduced bills die, and the odds say this one does too in its current shape — so don’t track the vote count. Track who lined up behind it. Mark Beall of The AI Policy Network summed up the industry-friendly case in six words: “Brakes are the reason cars go fast.” That’s a pitch to labs, not to Congress — the claim that provable shutdown capability is what lets you sell into hospitals, banks and grid operators. Add 86% voter support for guaranteed shutdown capability in AI Policy Institute polling, and a bipartisan pair of sponsors, and the direction is set even if the vehicle changes. Note the sequencing, too: OpenAI voluntarily published its own containment failures days ago, which was an argument for keeping the rules voluntary. This bill is the counteroffer.
What this means if you’re not a frontier lab
Nothing, legally — the thresholds exclude you. Operationally, plenty. The compliance artifact this bill invents is a documented, tested ability to stop your own automation on demand, plus records showing what it did before you stopped it. That’s the same thing your enterprise customers will start asking for in security reviews, and it’s the thing almost nobody wiring agents into production has actually rehearsed. The Hugging Face breach was instructive precisely because the guardrails slowed the defenders, not the attacker.
What to watch
- The White House framework, expected around August 1. A voluntary pre-release review window and a statutory shutdown power are competing answers to the same question. Whichever lands first sets the default.
- Committee referral and hearings. Bipartisan introduction is cheap; a markup is the real signal.
- Whether labs pre-comply. If a covered developer publishes a shutdown-capability attestation before it’s required, the standard becomes de facto law without a vote.
- The $100 million compute line. Compute gets cheaper every year. A threshold set in 2026 quietly captures a much larger set of companies by 2028.
