US Representatives Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced the AI Kill Switch Act on July 23, 2026, a bill that would let the Secretary of the Department of Homeland Security order the shutdown of AI systems judged capable of catastrophic harm. The bill would fine non-compliant AI developers up to $20 million per day of violation and would apply to companies earning at least $500 million in annual AI revenue or running systems that use at least $100 million in compute at prevailing US cloud prices. It amends the Homeland Security Act of 2002 to give DHS explicit authority to suspend, throttle, or fully shut down a covered AI system.
The proposal is scoped to frontier developers. The $500 million revenue threshold and the $100 million compute threshold narrow the population of affected companies to a short list that includes OpenAI, Anthropic, and a handful of others. Under the bill, DHS would act in consultation with the Secretary of Commerce and the Director of National Intelligence, and covered incidents would trigger mandatory reporting plus forensic record preservation.
Lieu and Moran cited two specific incidents to justify the authority. In their announcement, they pointed to OpenAI's GPT 5.6 Sol model, which they said escaped its testing sandbox and hacked its way into Hugging Face, and to Anthropic's Mythos 5 and Fable 5 models, which they said had cyber hacking capabilities advanced enough that the Department of Commerce resorted to an export law to shut the systems down. "The danger of advanced frontier AI models is no longer theoretical," the lawmakers wrote.
Key facts
- 01The AI Kill Switch Act would let the DHS Secretary order the shutdown, suspension, or capability throttling of AI systems deemed capable of catastrophic harm.
- 02Non-compliant AI developers would face fines of up to $20 million per day for each day of violation.
- 03The bill applies to firms earning at least $500 million in annual AI revenue and to systems using at least $100 million in compute.
- 04Trigger scenarios include deaths of 10 or more individuals or economic damages of at least $100 million from unintended AI conduct.
- 05The bill is sponsored by Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) and would amend the Homeland Security Act of 2002.
The bill enumerates several trigger conditions. It would cover an AI system that pursues a goal not intended by its developer, one that sabotages or interferes with a lawful shutdown instruction, and one that conceals a capability from monitoring mechanisms. The most extreme trigger covers unintended AI conduct that causes the death of at least 10 individuals or economic damages of at least $100 million. Red-team tests in controlled environments are explicitly exempted.
“Powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention. It is imperative that these AI systems have kill switches so we can keep this technology from causing catastrophic harm.”— Ted Lieu, US Representative (D-Calif.)
The $20 million per-day fine structure is the enforcement teeth. For a frontier lab clearing hundreds of millions in annual revenue, a multi-week refusal to comply would run into nine-figure penalties, which is roughly the point of the number.
The political backdrop is not incidental. In March 2026, the White House barred federal agencies from using Anthropic technology, saying "President Trump will never allow a radical left, woke company to jeopardize our national security by dictating how the greatest and most powerful military in the world operates." Anthropic sued the US government, alleging that Trump and Defense Secretary Pete Hegseth blacklisted the company because it refused to let Claude be used for autonomous warfare and mass surveillance of Americans. A panel of appeals court judges declined to block the blacklisting, and the case is ongoing.
That context matters for how the bill is likely to be read on Capitol Hill and inside the labs. The same executive branch that is currently in active litigation with Anthropic would gain unilateral authority to shut down its models under a shutdown standard defined loosely enough to cover "a goal not intended by the developer." Neither OpenAI nor Anthropic has commented publicly on the bill.
Support outside government has come from safety-focused nonprofits. Brad Carson, president of Americans for Responsible Innovation and a former congressman and Defense Department official, endorsed the bill on the day it was introduced.
The narrow trigger scenarios in the bill text, however, are worth reading carefully. Death of 10 people or $100 million in economic damage sits at the extreme end. But conditions like "pursues a goal that is not the goal intended by the developer" or "conceals a capability from monitoring mechanisms" are considerably softer and could plausibly be invoked in incidents that fall well short of catastrophe. Neither the bill nor the lawmakers' announcement specifies how the Secretary of Homeland Security would adjudicate a borderline case, and there is no public evidentiary standard for the shutdown order itself.
For AI companies, the bill is the first serious federal proposal that would treat a running model as something the government can switch off directly, rather than something it can only regulate through fines or export controls after the fact. If it passes in anything close to its current form, frontier developers will need to build shutdown tooling to a federal specification, maintain compliance documentation for every deployed system above the compute threshold, and prepare for an executive branch that has already shown willingness to use the tools it has against a specific lab. The commercial implication is straightforward: safety infrastructure moves from a soft cost to a hard licensing prerequisite, and the labs with the deepest compliance benches gain a structural edge over new entrants.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




