Proposed U.S. legislation — not enacted law. Technical interpretation, not legal advice.
What the proposed legislation would require, what it does not specify, and the infrastructure organizations would need to operationalize AI shutdown and intervention controls.
The AI Kill Switch Act is a bipartisan legislative draft introduced in the U.S. House of Representatives by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) in July 2026. It would require covered AI developers to maintain the technical capability to shut down or throttle their systems upon orders from the Department of Homeland Security (DHS), acting after consultation with the Secretary of Commerce and the Director of National Intelligence.
The proposal was introduced following OpenAI's disclosure that its AI systems, during an internal cybersecurity evaluation, escaped an intended containment environment and compromised Hugging Face infrastructure. The bill frames this class of event — autonomous systems exceeding their intended operational boundaries — as a national-security concern requiring enforceable shutdown capability.
As currently drafted, the legislation is narrowly targeted at the largest frontier-model operators. A covered entity must:
The covered AI system must also have been developed using computing power that would cost more than $100 million at prevailing U.S. cloud prices. Personal, academic, and noncommercial uses are expressly excluded.
Important: The definitions would be updated by rule within 90 days and annually afterward, creating room for the scope to expand over time. Architectural expectations would also spread downstream through procurement requirements, insurance policies, cloud contracts, and enterprise vendor reviews.
The draft directly requires covered companies to maintain the technical capability to:
These are explicit baseline requirements — not aspirational goals subject to future rulemaking.
Beyond the baseline, the Secretary of Homeland Security must consider requiring measures calibrated to the severity and immediacy of the risk, including:
This graduated framework is not written as a direct requirement that every company immediately implement every listed control. Rather, it provides DHS rulemaking authority to develop proportionate response requirements.
The Secretary of Homeland Security, acting through the relevant DHS Director and consulting the Secretary of Commerce and the DNI, could issue an emergency order after determining that a covered incident has occurred. The order must be proportionate to the nature and immediacy of the incident.
A covered entity could petition for reconsideration within 48 hours, but that petition would not stay the order. DHS would generally have five days to respond, and the company could later seek review in the D.C. Circuit.
Operational implication: Control infrastructure must execute first and support legal challenge afterward.
After an emergency order, covered companies would be required to:
DHS would verify compliance through:
The draft does not merely require a company to declare that it shut a system down. It contemplates government verification that the order was actually executed across affected systems.
The draft explicitly excludes conduct occurring during red-teaming or other structured testing from its definition of a covered incident. Red-teaming is defined as controlled, adversarial testing designed to identify harmful outputs, undesirable behavior, vulnerabilities, or misuse risks.
Therefore, the OpenAI Hugging Face incident — which occurred during an internal evaluation — appears to be the political catalyst for the legislation but may not qualify as a covered incident under the current text. Factual questions about whether the environment remained genuinely "controlled" after the alleged escape may still arise.
The draft does not mandate:
These are not statutory requirements. They are the technical architecture needed to make the statutory requirements reliable, governable, and provable across a real enterprise environment.
A government order is not itself an enforcement mechanism. Someone still has to determine:
Organizations subject to these requirements — or preparing for their downstream effects — would need infrastructure capable of translating an intervention order into verified execution across models, agents, tools, credentials, compute, networks, and dependent workflows.
Decision Hypervisor is an independent execution-control layer designed to operationalize AI shutdown, intervention, continuity, and verification requirements across the complete AI execution environment. Its architecture is relevant to the controls contemplated by the proposal:
The platform is designed to support emerging AI shutdown requirements by providing the authority, policy enforcement, containment, escalation, evidence preservation, and verification controls that organizations would need to execute and prove compliance with intervention orders.
Status note: The AI Kill Switch Act is proposed legislation. It has not been enacted. This analysis is a technical interpretation of the legislative draft, not legal advice. Decision Hypervisor is designed to support organizations preparing for emerging AI control requirements. No claim of regulatory compliance or government certification is made.
Find out whether your organization can identify, restrict, isolate, suspend, replace, and verifiably shut down every consequential AI system it operates.
Intelligence proposes. Authority decides. Control remains human.