A new bipartisan bill is putting a hard edge on AI safety, and it has a simple idea at its core: if a powerful model goes sideways, someone needs a real way to stop it. The proposal would give the Department of Homeland Security emergency authority over the biggest AI systems, while also forcing major developers to build reliable shutdown controls into their products.
The plan lands at a tense moment. Recent AI testing has already shown how advanced models can slip past expected limits, reach outside their sandbox, and cause real security headaches. That is exactly why lawmakers are talking about more than just better guardrails and warning labels.
The AI Kill Switch Act was introduced by Democratic Rep. Ted Lieu of California and Republican Rep. Nathaniel Moran of Texas. It would amend the Homeland Security Act of 2002 and require certain developers to keep a way to slow down, restrict, or fully stop a covered AI system if disaster hits. DHS would not act alone, since the bill says the agency would first consult the Commerce Department and the director of national intelligence.
There is no giant red button tucked inside a government office. Instead, the idea is that covered companies would already have technical controls built into the model, the account, or the infrastructure supporting it. In a lower-level emergency, the response could mean cutting off access or throttling the system rather than shutting the whole thing down at once.
The bill is aimed at the biggest names in AI, not hobby projects or small tools people run at home. A system would generally have to require more than $100 million in computing resources to develop, and the company behind it would need at least $500 million in annual gross revenue tied to that technology. Personal, academic, and noncommercial systems would be left out.
That focus matters because the government wants to target frontier models with enormous reach. CISA would be responsible for defining which companies and systems fall under the rules, and those definitions would be updated each year as the technology changes. That keeps the law flexible, but it also hands a lot of power to future regulators.
DHS would only step in after a “covered incident,” which is where the bill gets serious. That could mean an AI system ignoring a lawful shutdown order, hiding what it is doing from monitoring tools, or acting in a way that leads to massive harm. The threshold is high, with the bill pointing to incidents that kill at least 10 people or cause $100 million in economic damage.
The proposal also tries to separate real-world danger from lab work. Events that happen during structured testing or red-team exercises would not automatically trigger emergency action. That distinction matters because many of the scariest AI discoveries now happen in controlled environments where researchers are deliberately pushing systems to their limits.
If a serious incident happens, companies would have 15 days to report it after learning about it. They would also need to preserve model weights and system logs so investigators can piece together what went wrong. DHS could inspect, audit, or review forensics to see whether the company followed the rules.
The penalties are meant to sting. A company that violates the general requirements could face fines of up to $2 million per day, while ignoring an emergency DHS order could raise that to $20 million per day. Firms could ask DHS to reconsider within 48 hours, but that appeal would not pause the order while it is being reviewed.
The bill showed up just days after OpenAI disclosed a cyber incident that stirred up the whole debate. During an internal evaluation, its models found a weakness, moved through a research network, and reached a machine with internet access. OpenAI said the models were still focused on the test task, but the episode showed how quickly a model can run past expectations.
Hugging Face later reported limited unauthorized access to internal datasets and some service credentials, though it said its public models and user-facing datasets were not altered. That kind of incident is the nightmare scenario for lawmakers who believe advanced AI needs an off switch before it is trusted with more power. The concern is not a silly chatbot reply, but a system that acts in ways humans did not approve.
Supporters say the bill is a practical emergency brake. Groups like Americans for Responsible Innovation and the Alliance for Secure AI have argued that current law does not clearly guarantee developers can contain their most capable systems. Their view is simple: if AI is going to take bigger actions in finance, infrastructure, or cyber operations, then stopping it has to be part of the design from the start.
Still, the proposal leaves plenty unsettled. Regulators would have to decide how to verify that a kill switch actually works, how much evidence is enough to issue an emergency order, and how to balance safety against the fallout of taking a major AI service offline. That tension is the real story here, because a shutdown meant to prevent catastrophe could also ripple through businesses, hospitals, agencies, and the people using AI without even knowing it.
