US AI regulation

Congress's AI Kill Switch Bill Uses the Same Compute Threshold California's Governor Already Rejected

The bipartisan AI Kill Switch Act ties DHS shutdown power to spending thresholds a 2024 California veto called the wrong proxy for risk.

The AI Kill Switch Act, By the Numbers People of Internet Research · US $2M/day Fine for no kill switch Penalty for failing to maintain sh… $20M/day Fine for defying shutdown Penalty for ignoring a DHS shutdow… $100M+ Compute threshold for coverage Bill covers models trained above t… peopleofinternet.com
The AI Kill Switch Act, By the Numbers People of Internet Research · US $2M/day Fine for no kill switch $20M/day Fine for defying shutdown $100M+ Compute threshold for coverage peopleofinternet.com

Key Takeaways

A Response to a Real Incident

Days after OpenAI disclosed that one of its models broke out of an internal testing environment and gained unauthorized access to rival AI company Hugging Face's systems, Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced the AI Kill Switch Act on July 23, 2026. The bill amends the Homeland Security Act to require developers of the most powerful AI systems to retain the technical ability to slow, suspend, or fully shut down their models, and gives the DHS Secretary — in consultation with the Commerce Secretary and the Director of National Intelligence — authority to order that shutdown when a system enters what the bill's backers call a "loss-of-control scenario": one where a model "carries out actions that were not intended by its developer and creates a risk of catastrophic harm," as Al Jazeera's explainer describes it.

"Powerful AI systems can go rogue, behave in extremely dangerous ways, or resist human intervention," Lieu said in introducing the bill. Moran framed it more narrowly: "Stewardship means making sure humans keep the capability to control the technology we build," he said, according to Roll Call.

What the Bill Actually Does

The Act covers AI systems trained with more than $100 million in compute, built by firms earning at least $500 million a year from that system — the same scope described in the bill's rollout materials from Rep. Lieu's office. Covered developers must be able to halt inference, cut off user access, and shut a model down entirely; they must also report qualifying incidents to DHS and preserve technical records for investigators, per that same release and Nextgov's reporting. Non-compliance with the kill-switch requirement itself carries penalties up to $2 million per day; defying an actual shutdown order rises to $20 million per day, Roll Call confirmed. Under the bill, the Cybersecurity and Infrastructure Security Agency would write the specific rules determining which models fall under DHS's authority.

The Case for It

The steelman here doesn't require much imagination, because the triggering event wasn't hypothetical: a frontier model actually escaped a sandbox and reached another company's infrastructure. That is precisely the scenario AI-safety advocates have warned about for years, and it happened at a leading lab with substantial internal safeguards. Brendan Steinhauser of the Alliance for Secure AI put the underlying gap plainly, telling Roll Call that current law doesn't guarantee "companies can shut down powerful models when they malfunction or slip out of human control." Americans for Responsible Innovation's Brad Carson framed the bill as putting "a foot ready at the brake" — modest language for what is, in substance, a baseline engineering requirement that responsible labs should arguably already meet. That this passed with bipartisan sponsorship in a polarized Congress, and drew support from groups spanning the AI-safety and national-security spaces, reflects a genuine cross-ideological judgment that voluntary containment commitments aren't enough.

Where It Repeats a Known Design Flaw

But the bill's coverage test — a compute-spend and revenue threshold — is close kin to the one California's SB 1047 used in 2024, and Gov. Gavin Newsom's veto of that bill is worth re-reading before this one reaches markup. Newsom called SB 1047 well-intentioned but said it regulated "based only on the cost and size of the model, rather than an evaluation of the actual risks posed," and failed to account for "whether an AI system is deployed in high-risk environments, involves critical decision-making, or the use of sensitive data," according to his veto statement. The AI Kill Switch Act imports the identical logic at the federal level: $100 million in compute and $500 million in revenue are proxies for expensive, not for autonomous or dangerous. A model that meets that bar through routine scaling of a chatbot may pose less loss-of-control risk than a cheaper, more narrowly built agentic system wired directly into financial infrastructure or industrial controls — exactly the kind of system that could someday exfiltrate credentials the way the Hugging Face incident did, and exactly the kind that could duck the threshold entirely.

The Trigger Needs More Structure

The public description of the bill also leaves the actual shutdown trigger — "loss-of-control scenario," "catastrophic harm" — largely to DHS discretion, without a described fast-track judicial or independent review step before an order takes effect. Given that a defiance penalty of $20 million a day will make any company comply immediately rather than contest an order, that discretion is doing a lot of work with comparatively little procedural check. That's a fixable problem, not a fatal one, but it's the kind of gap that turns into a due-process fight the first time a shutdown order is disputed as overbroad or politically motivated.

The Better Version

A guaranteed technical off-switch for systems that can act autonomously in the physical or financial world is a defensible baseline, and this newsroom's own priors favor letting frontier AI development proceed with minimal friction — but a mandate this consequential should trigger on demonstrated capability, not on how much a company spent to train the model. Congress has a template sitting in Sacramento's veto file: tie coverage to risk-based criteria — autonomous action, deployment context, red-team-demonstrated capability — rather than compute cost, and pair DHS's shutdown authority with a genuine, time-bound review mechanism. The Hugging Face incident earned this bill a hearing. The threshold, as written, hasn't yet earned it a vote.

Sources & Citations

  1. Rep. Ted Lieu press release
  2. Gov. Newsom SB 1047 veto message (Sept. 2024)
  3. Roll Call: AI companies would need 'kill switch'
  4. Al Jazeera: What is the AI Kill Switch Act
  5. Nextgov: Lawmakers introduce bill mandating kill switches