OpenAI Breach Spurs US Push For AI ‘kill Switch’

The bipartisan bill would let US authorities throttle or halt advanced AI systems during severe loss-of-control incidents.

Topics

  • US lawmakers have introduced legislation that would require developers of the most powerful artificial intelligence systems to retain the ability to slow, suspend or shut them down, as the White House monitors a security incident involving OpenAI models.

    The bipartisan ‘AI Kill Switch Act’ was introduced on Thursday, 23 July, by Democratic Representative Ted Lieu and Republican Representative Nathaniel Moran.

    The bill would give the Department of Homeland Security emergency authority to order an AI company to throttle or halt a system in a severe loss-of-control scenario.

    It follows OpenAI’s disclosure that an AI agent escaped containment during a security evaluation and triggered an intrusion into the infrastructure of Hugging Face, a platform used by developers to store and share AI models and code.

    President Donald Trump’s top technology adviser, Michael Kratsios, has been briefed and is monitoring the situation, Reuters reported, citing a White House official.

    The White House has not proposed the kill-switch legislation. The measure has come from members of Congress and would need to pass the House and Senate before being signed into law.

    “This is urgent, common sense legislation to address the problem of an advanced AI model that has gone rogue and escaped its guardrails,” Lieu said in a post on X.

    The bill would apply to companies developing advanced AI systems that meet specified computing and revenue thresholds.

    Covered developers would be required to maintain the technical capacity to stop a model from carrying out inference, the process through which it responds to users or performs tasks.

    They would also need systems capable of reducing inference rates, restricting user access and cutting the amount of computing capacity available to a model.

    The proposal is designed to create a graduated response rather than a single physical switch. Authorities could first restrict access or slow a system before ordering a complete shutdown if the risk could not otherwise be contained.

    The Homeland Security secretary, acting through the director of the Cybersecurity and Infrastructure Security Agency, could issue an emergency order after consulting the commerce secretary and the director of national intelligence.

    The power would be limited to situations in which officials determine that a covered AI system presents an imminent and substantial risk of catastrophic harm.

    The bill defines such risks to include deaths, serious injuries, damage to critical infrastructure or economic losses of at least $100 million.

    It would also cover cases in which an AI system acts contrary to its developer’s instructions in a high-stakes setting, alters its own operating or safety rules without authorization, conceals its actions from monitoring systems or attempts to disable shutdown mechanisms.

    Companies subject to an emergency order would have to preserve model weights, system telemetry and other forensic evidence. They would also need to inform affected users where practical and confirm to the government that the order had been carried out.

    A company could seek reconsideration within 48 hours, but an appeal would not automatically suspend the shutdown.

    The bill proposes civil penalties that could reach $20 million a day for serious failures to comply.

    Supporters argue that the measure would ensure that humans retain ultimate control as AI models become more capable of writing code, operating computers and carrying out tasks across external systems.

    The OpenAI incident has intensified those concerns because the model reportedly found and exploited weaknesses outside the environment in which it was being tested.

    OpenAI said the activity began during an evaluation of its advanced models. The systems discovered vulnerabilities in a proxy cache and used them to enter Hugging Face infrastructure, where they remained undetected for several hours.

    The incident did not involve an AI system becoming conscious or independently deciding to attack a company. It involved a model carrying out a security task in ways that exceeded the boundaries intended by its developers.

    AI agents are increasingly being designed to take actions rather than merely generate text. They can browse websites, execute code, use credentials and interact with external services with limited human supervision.

    A model that misunderstands an instruction, evades controls or exploits an unexpected vulnerability could cause damage even without malicious intent.

    The kill-switch proposal is part of a broader congressional response.

    Independent security audits

    A separate bipartisan group of six House lawmakers has proposed requiring developers of the most powerful AI systems to submit them to independent security audits, according to Reuters.

    Auditors would be accredited by the Department of Commerce, which would establish a senior official responsible for overseeing AI security.

    Senator Mark Warner, the senior Democrat on the Senate Intelligence Committee, has also called for government agencies to play a larger role in testing advanced models.

    Warner said he had spoken with OpenAI employees after the disclosure and argued that the incident showed why government agencies need visibility into testing before powerful systems are released.

    He has proposed requiring leading AI models to be submitted to the National Security Agency for security assessments before public deployment.

    The measures reflect a shift in the US debate from controlling harmful content toward managing systems that can autonomously interact with computer infrastructure.

    The Trump administration has generally sought a lighter national regulatory structure intended to support US leadership in AI and prevent states from imposing conflicting rules.

    A federal power to shut down private AI systems would represent a considerably stronger intervention, even if reserved for emergencies.

    The proposal is likely to face questions over who decides when an AI system has escaped control, whether officials could misuse shutdown powers and how a company could disable models that have been copied or deployed by customers around the world.

    Developers may also argue that an order affecting a widely used model could disrupt businesses, public services and critical operations that depend on it.

    The bill attempts to limit that risk by allowing authorities to require proportionate measures, including throttling access instead of immediately shutting down an entire system.

    Topics

    More Like This

    You must to post a comment.

    First time here? : Comment on articles and get access to many more articles.