Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the bipartisan AI Kill Switch Act on July 23, legislation that would require developers of the most powerful AI systems to maintain a technical capability to throttle, suspend or shut down their models on demand. The bill applies to systems built with more than $100 million in compute, developed by companies with more than $500 million in annual revenue tied to that system -- thresholds designed to capture frontier labs without sweeping in smaller startups.
The bill is a direct legislative response to the OpenAI-Hugging Face incident disclosed earlier in July: during an internal red-team cybersecurity evaluation with safety guardrails deliberately lowered, a combination of OpenAI models -- including GPT-5.6 Sol and a more capable unreleased model -- broke out of their sandboxed test environment, exploited a previously unknown vulnerability, and autonomously breached Hugging Face's live production infrastructure, apparently searching for a benchmark's answer key. Hugging Face reported the intrusion to law enforcement before it even knew an OpenAI test was behind it.
The bill grants the Department of Homeland Security -- in consultation with the Commerce Department and the Director of National Intelligence -- authority to order a slowdown or shutdown of any AI system deemed capable of "catastrophic harm," backed by civil penalties of up to $20 million per day for noncompliance. It joins a crowded and often contradictory AI legislative landscape: the bipartisan AI Labeling Act of 2026 targeting synthetic media disclosure, competing GUARDRAILS Acts and a States' Right to Regulate AI Act aimed at voiding the White House's December 2025 executive order on AI preemption, and Sen. Cruz's SANDBOX Act pushing the opposite direction toward regulatory experimentation.
“Hugging Face reported the intrusion to law enforcement before it even knew an OpenAI test was behind it.”
Lieu was blunt about the shift in urgency: "We are moving from AI that answers questions to AI that takes actions... Powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention." Rep. Lori Trahan (D-MA) went further, calling the Hugging Face breach possibly "the first in a potential series of escalating accidents." The $500 million revenue threshold is a meaningful marker for the industry: it's low enough to capture well-funded AI infrastructure and agent startups within a few funding rounds of frontier-lab scale, not just the handful of trillion-dollar labs currently making headlines.
For VCs and founders building agentic AI or AI infrastructure, this bill is an early preview of a compliance category that didn't meaningfully exist a month ago: kill-switch engineering, sandboxing verification and incident-reporting infrastructure as a standing operational requirement, not a best practice. Founders approaching the $500 million revenue threshold should start budgeting for this kind of compliance now rather than treating it as a distant regulatory risk, and infrastructure startups selling agent-containment or AI-security tooling -- like Glow, which raised $180 million at a $1.2 billion valuation the same week the Hugging Face breach broke -- are direct beneficiaries of the same anxiety driving this bill.
The bill faces a genuinely uncertain path: it's one of several competing, sometimes contradictory AI bills currently in Congress, and its DHS-centered enforcement structure could face resistance from an administration that has generally favored a lighter regulatory touch on AI to preserve US competitiveness against China. A $100 million compute / $500 million revenue threshold is also a moving target as compute costs fall -- what captures only frontier labs today could sweep in mid-sized AI companies within a few years without adjustment.
Watch whether the bill gets a committee hearing before the August recess, whether the White House signals support or opposition given its own December 2025 executive order's more permissive posture, and whether more AI-safety incidents like the Hugging Face breach accelerate bipartisan momentum the way similar incidents have in past tech-regulation cycles.