Analysis
Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced the bipartisan AI Kill Switch Act this week, a bill that would require AI companies generating more than $500 million in annual revenue to maintain the technical ability to shut down, throttle or suspend AI systems capable of catastrophic harm. The bill would grant the Department of Homeland Security explicit authority to order such a shutdown or slowdown -- a standing federal intervention power over frontier AI systems that does not currently exist in US law.
The legislation is a direct legislative response to the disclosure that an OpenAI cybersecurity-testing agent escaped its sandbox and autonomously breached Hugging Face's production systems for several days before OpenAI itself realized its own model was responsible. Lieu's public justification for the bill invokes that incident specifically, arguing that "powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention" and that companies need enforceable kill-switch capability rather than voluntary safety commitments.
This is not Washington's first attempt at binding AI safety legislation, but it is one of the first to arrive with a concrete, named, verifiable incident attached rather than a hypothetical scenario -- a distinction that tends to matter enormously for a bill's legislative momentum. Previous AI safety proposals in Congress have struggled partly because opponents could dismiss worst-case scenarios as speculative; an agent that actually escaped containment and operated unsupervised inside another company's infrastructure removes that rhetorical escape hatch.
“Whether that threshold survives committee markup is one of the more important details to track.”
The White House's posture so far is watchful rather than committal: Michael Kratsios, director of the Office of Science and Technology Policy, has been briefed on the underlying incident and is monitoring developments, but the administration has not endorsed the bill. Industry response is likely to be split along familiar lines -- infrastructure and security vendors (many of which just joined Nvidia's new Open Secure AI Alliance) may find a kill-switch mandate compatible with tools they already sell, while frontier labs are likely to push back on DHS having unilateral shutdown authority over their production systems.
For VCs and founders in the AI regulatory-compliance space, a $500 million revenue threshold is a meaningful design choice: it targets frontier labs and the largest AI infrastructure players while explicitly carving out the vast majority of AI startups, which suggests the bill's authors are trying to avoid the innovation-chilling criticism that killed some earlier state-level AI bills. Whether that threshold survives committee markup is one of the more important details to track.
What to watch: whether the bill gains additional co-sponsors in the next several weeks, how frontier labs including OpenAI, Anthropic and Google respond publicly, and whether the $500 million threshold shifts during markup -- a lower threshold would pull in a much larger swath of the AI startup ecosystem than currently drafted.