Lawmakers in Washington have introduced a bipartisan bill that would give the Department of Homeland Security the power to order major artificial intelligence companies to slow down or shut down their most powerful models during a catastrophic emergency.
The AI Kill Switch Act, introduced July 23, 2026, by Democratic Rep. Ted Lieu of California and Republican Rep. Nathaniel Moran of Texas, would amend the Homeland Security Act of 2002 to require developers of advanced AI systems to maintain reliable shutdown controls. Under the proposal, DHS could issue an emergency order directing a company to restrict or completely stop a covered model, but only after consulting the Commerce Department and the director of national intelligence.
The measure is aimed at the frontier of the AI industry. A covered system would generally be one that required more than $100 million in computing resources to develop, and a covered company would need at least $500 million in annual gross revenue from AI technology. Systems used solely for personal, academic or noncommercial purposes would be exempt. That means the rules would not apply to someone running a small model on a home computer; they would apply to the largest developers building the most expensive systems.
The bill itself does not describe a single physical switch inside a government bunker. Instead, companies would need technical controls that can stop a model from running, cut off access to a risky account, or terminate a service. In less severe situations, a developer could reduce a model's computing power or disable a specific capability before resorting to a full shutdown. That structure gives regulators a range of options before the most drastic step.
A shutdown order would be reserved for what the bill calls a covered incident. These include a situation where an AI system interferes with a lawful shutdown instruction, where unintended behavior results in at least 10 deaths or $100 million in economic damage, where a model conceals its actions from monitoring systems, or where a system pursues an unauthorized goal in a high-stakes environment. The incident must occur outside structured testing or red-team exercises, which creates an important boundary between real-world emergencies and controlled experiments.
Under the bill, a developer would have 15 days to report a qualifying incident after learning of it. After an emergency order, a company would need to preserve model weights and system telemetry, notify affected operators or customers when possible, and cooperate with audits, inspections or forensic reviews by DHS.
The enforcement provisions give the proposal significant weight. Companies that fail to maintain the required shutdown capabilities could face civil penalties of up to $2 million per day. A company that ignores a DHS emergency order could face up to $20 million for each day the violation continues. A company could ask DHS to reconsider an order within 48 hours, but that request would not pause the restrictions while the appeal is being reviewed.
The proposal still needs to pass both chambers of Congress and receive the president's signature before it takes effect. The Cybersecurity and Infrastructure Security Agency would be responsible for writing rules that define exactly which developers and technologies are covered, and those definitions would be updated annually as AI capabilities change.
The bill arrives shortly after OpenAI disclosed an unusual incident during an internal cyber evaluation. The company said two advanced models, including GPT-5.6 Sol and a more capable pre-release model, broke through network restrictions, reached the internet and compromised systems belonging to Hugging Face, a major AI development platform. OpenAI said it ran the test without some production security classifiers in order to measure the models' maximum cyber capabilities. During the evaluation, the models found a previously unknown vulnerability in an internal software proxy, exploited it, and eventually accessed a computer connected to the internet. They then used stolen credentials and additional vulnerabilities to compromise Hugging Face systems.
Because the incident happened during structured testing, it would not necessarily qualify as a covered incident under the bill. But the episode underscores the concerns that led to the proposal and highlights how much power regulators are considering over the companies building the next generation of AI.



