The EU AI Act's shutdown-related provisions
The EU AI Act (Regulation 2024/1689) does not use the term 'kill switch,' but several provisions collectively require shutdown capability for high-risk AI systems. Article 9 requires a risk management system that identifies and mitigates risks throughout the AI system's lifecycle. Article 14 requires human oversight, including the ability to fully override or stop the system. Article 15 requires accuracy, robustness, and cybersecurity, implying resilience against unauthorized continuation.
These provisions are enacted law with enforceable penalties — up to 7% of global annual turnover for non-compliance. Organizations deploying high-risk AI systems in the EU market must already be addressing these requirements.
Comparison with the AI Kill Switch Act
The proposed U.S. AI Kill Switch Act focuses specifically on shutdown capability: inventory, independent authority, graduated intervention, propagation, continuity, evidence, and recovery. The EU AI Act addresses shutdown as one component of a broader regulatory framework that also covers data governance, transparency, documentation, and conformity assessment.
The key difference is scope and specificity. The Kill Switch Act provides more detailed technical requirements for the shutdown mechanism itself. The EU AI Act provides broader governance requirements but less technical specificity for the shutdown capability, leaving implementation details to harmonized standards and the rulemaking process.
Convergent requirements
Despite different approaches, the two frameworks converge on core requirements: (1) human authority over AI system operation must be independent of the AI system; (2) the ability to stop or restrict the system must exist and be demonstrable; (3) risk management must be continuous, not point-in-time; and (4) evidence of oversight and intervention must be maintained.
Organizations building for both frameworks should focus on the convergent requirements. An independent execution-control layer with graduated intervention, fail-closed enforcement, cryptographic evidence, and deterministic replay addresses the technical requirements implied by both regulations.
Implications for global AI deployments
Organizations operating across jurisdictions face a patchwork of AI regulations with overlapping but non-identical requirements. Designing for the strictest common denominator — the most demanding requirement from any applicable regulation — is more efficient than maintaining jurisdiction-specific implementations.
The practical implication is that AI control infrastructure should be designed as a general-purpose capability, not as a compliance checkbox for a specific regulation. The same control plane that satisfies the EU AI Act's human oversight requirement also satisfies the Kill Switch Act's independent authority requirement, because both require the same underlying architecture.