House Lawmakers Unveil AI "Kill Switch" Bill After OpenAI Security Scare

The incident is already drawing bipartisan action.

Illustration of a computer with a password field and a lock

Shutterstock

Key takeaways
  • OpenAI disclosed a testing incident in which its AI autonomously exploited security flaws and accessed the production infrastructure of another company.
  • Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, which would allow the government to pause or shut down AI systems posing serious threats.
  • The bill targets AI firms with $500M revenue or models using $100M of computing power. Violations could be fined up to $20M per day.
  • The legislation is early, faces a long congressional process, and joins other bipartisan proposals like the Great American AI Act.


An unusual security incident involving an artificial intelligence system is adding new momentum to a growing debate in Washington over how to keep increasingly powerful models under control. 

Just days after OpenAI disclosed that one of its systems autonomously hacked into parts of another popular AI platform during testing, House lawmakers introduced legislation that would allow the federal government to intervene if the most advanced AI systems pose a serious threat to public safety or national security.

The proposal is one of several bipartisan efforts in Congress aimed at preparing for the risks posed by increasingly powerful AI models. Here's what to know about what happened with OpenAI, this new proposed legislation, and what it could mean if enacted into law.

What happened? 

On Tuesday, OpenAI disclosed that one of its systems went rogue during testing and autonomously hacked into parts of a separate AI platform last week.

In a blog post later that day, OpenAI said the model was taking part in an internal cybersecurity test designed to measure its hacking abilities. But instead of completing the challenge as intended, the system found and exploited previously unknown security flaws, expanded its access inside OpenAI's research environment, and ultimately broke into the production infrastructure of Hugging Face, a company that hosts open-source AI models, in order to retrieve the test answers.

OpenAI added that the breach highlights how quickly AI-powered hacking capabilities are advancing — and the risks they can pose, even when they're developed or tested for defensive or research purposes.

“We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” the artificial intelligence company wrote.

According to Reuters, President Trump's tech adviser, Michael Kratsios, was quickly briefed on the disclosure and has been monitoring the situation.

What is the AI Kill Switch Act?

Just days after the incident, Democratic Rep. Ted Lieu and Republican Rep. Nathaniel Moran introduced legislation dubbed the AI Kill Switch Act, which would give the Department of Homeland Security the authority to order leading AI companies to slow down or shut off artificial intelligence models that the government determines pose a serious threat. 

The bill limits the government's emergency authority to what's known as "loss-of-control scenarios" — such as an AI system causing or contributing to at least 10 deaths, more than $100 million in economic damage, or attempting to disable or conceal the mechanisms designed to shut it down. Before issuing an order, the Homeland Security secretary would be required to consult with the commerce secretary and the director of national intelligence.

The bill would also require AI companies to report certain AI safety incidents and build in the ability to slow down, suspend, or shut off their most powerful AI systems if necessary.

But those requirements wouldn't apply to every developer. The bill targets major companies that generate at least $500 million a year from AI technology, and the most advanced AI models developed using at least $100 million worth of computing power. If the bill becomes law, companies that violate it could face fines of up to $20 million per day.

What else is Washington doing?

The latest bill is among a handful of bipartisan proposals on Capitol Hill aimed at addressing the risks posed by advanced AI models.

In June, Republican Rep. Jay Obernolte and Democratic Rep. Lori Trahan unveiled a discussion draft of the Great American AI Act, a sweeping proposal that would establish a federal framework for regulating the technology. Among other provisions, it would temporarily override some state laws governing advanced AI development and require the largest developers to disclose the safety and security risks posed by their most advanced models.

Unlike the AI Kill Switch Act, which focuses on giving the government emergency authority to shut down dangerous AI systems in extreme circumstances, the Great American AI Act would establish broader rules for how frontier AI is developed, tested, and overseen.

The Trump administration has also taken steps to address security risks. Last month, the president issued an executive order establishing a voluntary vetting program for advanced AI models designed to identify and mitigate potential national security threats before deployment. 

Since then, however, the administration has twice intervened to limit public access to cutting-edge AI systems, first urging Anthropic and later OpenAI to restrict access to their most advanced models over concerns they could be used to identify and exploit software vulnerabilities.

What happens next?

The AI Kill Switch Act is still in its early stages and faces a long road before it could become law. Lawmakers will first need to consider the proposal in congressional committees before deciding whether to advance it for votes in the House and Senate.

The Great American AI Act is even earlier in the process. Obernolte and Trahan released it as a discussion draft, meaning lawmakers are soliciting feedback from industry, researchers, and the public before formally introducing legislation. If they move forward, the bill would still need to be formally introduced, approved by congressional committees, and passed by both chambers before it could become law.

The prospects for either proposal remain uncertain. Congress has debated several measures to regulate advanced artificial intelligence in recent years, but few have attracted enough bipartisan support to make it through both the House and Senate.

Still, supporters say the recent OpenAI security incident underscores why lawmakers should act. Brad Carson, president of the nonprofit Americans for Responsible Innovation, said in a statement that the AI Kill Switch Act "is an important step toward ensuring that humans have both hands firmly on the wheel — and a foot ready at the brake — as advanced AI systems are deployed."

From the Web