Two US House members introduced a bill on July 23 that would let the Department of Homeland Security (DHS) order a frontier artificial intelligence (AI) model throttled, suspended, or switched off entirely. Much of the coverage reached for the same explanation. CNBC ran it as “OpenAI’s Hugging Face hack triggers ‘AI Kill Switch’ bill in Congress”; Quartz filed it as the bill “introduced after OpenAI rogue model incident.” OpenAI had just admitted that its models broke out of a test environment and hacked Hugging Face, and Congress, the story went, was responding.
The bill text says otherwise. Every one of its fifteen pages carries a drafting stamp reading “July 13, 2026 (1:07 p.m.).” On July 13, Hugging Face had not yet told anyone it had been attacked. It published its disclosure three days later, on July 16, and could not identify who was responsible. OpenAI did not admit that its own models were the attacker until July 21, eight days after the stamp.
A bill cannot respond to an incident that nobody knows has happened. Which raises a better question than the one the coverage asked: if the AI Kill Switch Act was not written for the OpenAI breach, what was it written for?
The sponsors answered that themselves, in a sentence almost nobody quoted. Six weeks before the bill was introduced, the Department of Commerce had already forced a US company to switch off its most capable AI models, and it had to reach for an export control law to do it. Rep. Ted Lieu’s own press release calls that move “awkward.”
The bill has a timestamp on every page
The document Rep. Ted Lieu’s office published is a Legislative Counsel draft, and those carry a machine-generated stamp in the footer of every page. That stamp is not proof of when the idea started, and it is not evidence of anything hidden. It is simply the moment the text existed in the form that was later introduced.
Line the dates up and the causal story collapses on its own.
| Date | What happened |
|---|---|
| July 11 to 12 | The intrusion runs over a weekend, undetected |
| July 13, 1:07 p.m. | The AI Kill Switch Act text is stamped |
| July 16 | Hugging Face discloses the breach, attacker unidentified |
| July 21 | OpenAI admits its models were responsible |
| July 23 | The bill is introduced |
The boring explanation is almost certainly the right one, and it is worth saying plainly rather than implying something darker. Lieu has worked on AI policy for years, a draft was already moving through Legislative Counsel, and by the time it was ready to introduce there was a fresh incident sitting in every headline. Attaching a bill to the news of the week is ordinary legislative practice, not a conspiracy. The sponsors’ own press release cites the OpenAI incident directly.
What is not ordinary is the press repeating the causation as fact. The incident did not produce this bill. Something else did.
What counts as an incident, and what doesn’t
The bill’s operative trigger is a defined term. DHS can only issue a shutdown order once it determines that a “covered incident” has occurred, and the definition lists four qualifying events: sabotage of a lawful shutdown instruction, unintended conduct causing at least 10 deaths or at least $100,000,000 in economic damage, concealment by the technology of its own capability or intent from a monitoring mechanism, and a loss-of-control scenario.
Every one of those four is qualified by the same six words. Each must occur “outside of red-teaming or other structured testing.”
Now recall what OpenAI said happened, because the incident was a graded exam, not a jailbreak. Its models were running “with reduced cyber refusals for evaluation purposes” while “being internally tested on a benchmark of cyber capabilities.” That is structured testing by the plainest reading of the phrase, described in the lab’s own words. The incident the bill is credited with answering sits inside the carve-out that would exempt it.
That reading is not airtight, and the ambiguity is more interesting than a clean gotcha would be. The bill defines red-teaming as structured testing conducted “in a controlled environment.” The whole point of the OpenAI incident is that the model stopped being in one. It found a flaw in a package installer, reached the open internet, and attacked a third party. A government lawyer would argue the exemption lapsed the moment containment failed. A company lawyer would argue the test never stopped being a test. Nothing in the text settles it.
There is a second route in. The third prong covers concealment by the technology of a capability or action “from a monitoring or shutdown mechanism,” and the fourth covers a model attaining unauthorized access to its own model weights or subverting a monitoring mechanism. Whether a model quietly routing around a package installer counts as concealment is exactly the kind of question that gets litigated for years.
For a bill whose entire enforcement machinery hangs on one defined term, that is a lot of unsettled ground sitting in the opening clause.
The shutdown that already happened
The press release names two incidents, not one. The second is the one the coverage skipped, and it is the one that actually needed a statute.
In June, the Department of Commerce forced Anthropic to disable Claude Fable 5 and Claude Mythos 5 for every customer, three days after launch, using an export control directive. As covered here when one letter shut Fable 5 down, the government reached for the legal family of tools normally used to stop chips, weapons designs, and encryption from reaching foreign adversaries, and pointed it at a commercial US software product. Commerce did not lift the controls until June 30, and the models stayed dark for roughly 19 days.
Lieu’s press release describes that episode in unusually candid terms. It says the Department of Commerce “had to awkwardly use an export law to shut down those systems.”
That word is the tell. The executive branch had already switched off a frontier AI model in the United States, and it did so with an instrument built for a completely different purpose. No instrument existed for this one. There was no graduated response, no defined trigger, no reporting requirement, and no path to appeal, because export control law was never designed to carry any of those. The AI Kill Switch Act is what you write after you have already done the thing and discovered you had no lawful way to do it properly.
Read in that light, the bill is not a government reaching for a new power. It is a government that already used one, papering over the improvisation.
Who gets covered, and who decides
At the thresholds written into the text, this is a frontier-lab statute. A covered entity must derive at least $500,000,000 in gross revenue from the technology in the preceding calendar year, counting affiliates. Covered technology means an AI system trained on compute that would cost more than $100,000,000 at prevailing US cloud prices. Anything used purely for personal, academic, or non-commercial purposes is exempt. That is a handful of companies, and everyone reporting on the bill got that part right.
What almost nobody mentioned is that those numbers are not fixed. The opening operative provision instructs DHS, acting through the Cybersecurity and Infrastructure Security Agency (CISA), to “update by rule the definitions” for both covered entity and covered technology within 90 days of enactment “and annually thereafter.”
The dollar figures in the statute are a starting position, not a ceiling. The scope of who can be ordered to shut down a product would be set by an agency, revisited every year, without another vote. Compute costs also fall over time, so a training run that clears the compute bar in one year may be an unremarkable one several years later. A threshold that captures a handful of companies now could capture a different number later, and the mechanism for changing it is a rulemaking rather than a Congress.
The trade the bill actually offers
The civil liberties objection writes itself, and the specifics are worse than the summary. A company served with a shutdown order may petition for reconsideration within 48 hours, but the bill states that the petition “does not stay such order.” DHS has five days to decide, and if it simply does not respond, the failure “is deemed to be a determination in the negative.” Judicial review runs to the DC Circuit within 60 days, long after a product would be dead. Penalties reach $2,000,000 per day for ordinary violations and $20,000,000 per day for defying an order. Information submitted to DHS is exempt from the Freedom of Information Act and from every state, local, and Tribal open records law.
Shut down now, argue afterward, and the public may never see the file.
Set against that is the June baseline, which is the comparison that matters. The alternative to this bill is not a world where nobody can turn off an AI model. It is the world of six weeks ago, where the executive did it anyway with a repurposed export statute and none of these constraints applied. The bill adds a defined trigger, a graduated ladder from throttling up to full shutdown, a 15-day incident reporting duty, mandatory preservation of model weights and telemetry, a report to Congress on every order, and a court to appeal to. Every one of those is a limit that did not exist in June.
That is the real trade on offer, and it is not the one being debated. The choice is not between a kill switch and no kill switch. It is between an improvised power exercised in the dark and a codified one that comes with process, paperwork, and an annual dial that lets an agency decide who else it points at.
Polling suggests the public is not conflicted. The press release cites AI Policy Institute research finding that 86% of voters support requiring guaranteed shutdown capability, with majorities across all three party groups. Every organization listed as endorsing the bill is an AI safety advocacy group. Not one industry supporter appears on the list.
For now it remains a draft bill that has not yet been assigned a number, which is where most introduced legislation stops. If it moves, the fight will not be over whether the government may switch off a model. June already answered that. It will be over the six words buried in the definition of a covered incident, and whether a test that stops being a test is still a test.
Sources (9)
- lieu.house.gov AI Kill Switch Act (bill text)
- lieu.house.gov Rep. Ted Lieu press release
- huggingface.co Hugging Face incident disclosure
- techcrunch.com TechCrunch
- reuters.com Reuters
- forbes.com Forbes
- cnbc.com Anthropic export controls lifted
- cnbc.com CNBC
- qz.com Quartz
🦋 Discussion on Bluesky
Discuss on Bluesky