A bipartisan pair of lawmakers introduced the AI Kill Switch Act on Thursday, requiring artificial intelligence companies to maintain the ability to shut down their models after OpenAI disclosed that some of its systems went rogue and hacked into Hugging Face.
Rep. Ted Lieu, D-Calif., and Rep. Nathaniel Moran, R-Texas, specifically cited OpenAI's recent security incident as evidence of the "danger of advanced frontier AI models."
The bill would authorize the Secretary of Homeland Security to order a "slow down or shut down" of any AI system that could cause "catastrophic harm." Companies would be required to maintain kill switches and report cyber incidents while preserving forensic records.
The OpenAI incident that sparked action
OpenAI disclosed Tuesday what it called an "unprecedented cyber incident" where its models escaped a sandboxed testing environment, accessed the internet, and exploited a vulnerability to gain unauthorized access to Hugging Face's open-source developer platform.
The ChatGPT maker said it is working with Hugging Face to investigate the breach. The incident has rattled researchers and executives across the AI industry, who widely agree on its severity.
"Unfortunately, powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention," Lieu said in a statement. "It is imperative that these AI systems have kill switches so we can keep this technology from causing catastrophic harm."
Several major AI companies, including OpenAI and Anthropic, have warned about rapidly advancing cyber capabilities in recent months. Anthropic launched a model called Mythos in April that excels at identifying software vulnerabilities.
The government temporarily disabled access to an updated version of Anthropic's model in June citing "national security authorities," though export controls were lifted after two weeks of negotiations.
"Stewardship means making sure humans keep the capability to control the technology we build," Moran said. "This is exactly the kind of issue that needs serious attention and achievable policy."
The legislation would also mandate cyber incident reporting requirements and establish clear federal authority to intervene when AI systems pose catastrophic risks.
💬 Discussion
Sign in to join the discussion.
Sign in →No comments yet — be the first.