Rep. Ted Lieu (D-CA), with Rep. Nathaniel Moran (R-TX) · 2026
AI Kill Switch Act (H.R. 9917)
Kill Switch Act
A bipartisan bill introduced July 23, 2026 — the same day as the FRONTIER Act — and referred to the Homeland Security Committee. It amends the Homeland Security Act to give the Secretary of Homeland Security, acting through CISA, two powers over the operators of frontier AI. First, within 90 days, a rule requiring every covered entity to maintain the technical capability to stop inference, terminate user access, suspend specific accounts or use patterns flagged as risky, and shut a covered system down entirely, and to report covered incidents within 15 days; the rule is to consider a graduated 'deployment-corrections' ladder from throttling inference and compute to disabling capabilities, suspension, shutdown, and rollback to an earlier version. Second, an emergency authority: once DHS, consulting Commerce and the Director of National Intelligence, determines a covered incident has occurred, it may order proportionate action up to shutdown, with the operator required to preserve weights and telemetry, notify affected users, and confirm compliance, which CISA verifies by audit, telemetry, or on-site inspection. Covered incidents are sabotage of a shutdown instruction, concealment of capabilities from monitoring, loss-of-control scenarios, and unintended conduct causing at least 10 deaths or $100M in damage. Coverage turns on operation, not development: any entity that serves a system trained with more than $100M of compute to third parties through an API or hosted service and earns at least $500M a year from it. Violations carry up to $2M a day, and up to $20M a day for defying an emergency order.
Key Provisions
Covered technology: AI systems developed with more than $100M of compute at prevailing cloud prices; covered entities: operators making such systems available to third parties via API or hosted service with at least $500M in annual revenue from them, with DHS updating both definitions annually
Mandatory shutdown capability: stop inference, terminate user access, suspend flagged accounts or use patterns, and shut the system down, with DHS to consider a graduated deployment-corrections framework from throttling to rollback
Covered incidents reported to DHS within 15 days: sabotage of a shutdown instruction, concealment from monitoring or shutdown mechanisms, loss-of-control scenarios, and unintended conduct causing 10 or more deaths or $100M in damage
Emergency orders after a covered incident, issued by DHS through CISA in consultation with Commerce and the DNI, requiring proportionate action up to shutdown, preservation of weights and telemetry, and user notification
Compliance verified by CISA through audit, telemetry, on-site inspection, or forensic review; subpoena and investigative authority, including abroad
Reconsideration petitions within 48 hours do not stay an order; silence after five days is a denial; judicial review in the D.C. Circuit within 60 days
Civil penalties up to $2M per day, and up to $20M per day for violating an emergency order; CISA publishes voluntary shutdown standards within 180 days
Regulatory Philosophy
Make the off-switch real before it is needed. Rather than evaluate models or verify risk frameworks, the bill regulates a single capability — the ability to stop a running system — and treats it as critical-infrastructure resilience, housed at DHS and CISA rather than Commerce. It is deliberately agnostic about how risk is assessed: it does not require frameworks, audits, or testing, only that the brake exist, be graduated, and be usable on government order once something has gone wrong. That makes it the narrowest frontier bill on the map and, on its single question, the most direct.
Operators serving systems trained with >$100M of compute and earning ≥$500M a year from them
Why it lands there
The only frontier bill on the map whose base is operation rather than development. Whoever serves a covered system to third parties — the lab's own API, a hyperscaler's hosted model service, or a platform that incorporates the model and sells access — must maintain the shutdown capability and obey an order, provided it earns $500M a year from that technology. That pulls the hyperscalers in as operators, and the largest app platforms with them, while a developer that licenses its weights to others and serves nothing itself may fall outside the bill altogether.
Lieu's bill and the FRONTIER Act were introduced on July 23, 2026, and both give a cabinet secretary power to stop a frontier model in an emergency. They put the brake in different hands and pull it at different moments. The FRONTIER Act gives it to Commerce, to be used on a finding of imminent catastrophic risk — before harm — through a provisional-and-final order process with D.C. District Court review. The Kill Switch Act gives it to Homeland Security and CISA, to be used once a covered incident has already occurred, and pairs it with a standing requirement that operators keep the switch working. The FRONTIER Act regulates developers by compute and spending; the Kill Switch Act regulates whoever serves the model and profits from it. And the FRONTIER Act's exclusivity clause, read literally, would leave DHS unable to use this bill's emergency power on catastrophic-risk grounds at all.
+Turns 'kill switch' from a slogan into specified technical capabilities — stop inference, cut access, suspend flagged use, shut down, roll back — with a graduated ladder that avoids all-or-nothing choices
+Covers operators as well as developers, reaching the cloud platforms and hosted services through which frontier models actually reach users
+Defines loss of control concretely — models acting against instructions in high-stakes contexts, altering their own safety restrictions, subverting monitoring, or accessing their own weights
+Requires preservation of weights and telemetry on an order, creating the forensic record that post-incident accountability depends on
+Bipartisan, short, and housed in an existing agency with an existing critical-infrastructure mandate, giving it a plausible path as a standalone measure
Weaknesses
From the perspective of political opposition
−Emergency orders are available only after a covered incident has occurred — the bill provides a brake, not a gate, and nothing in it acts before deployment
−The shutdown capability is meaningless for open-weight models, which the operator-and-revenue test largely exempts anyway
−The $500M revenue threshold is measured per technology, so a developer serving a dangerous model with modest revenue falls outside it entirely
−Leaves the definitions of covered entity and covered technology to annual DHS rulemaking, so the statute's actual reach is set by the agency
−Sits awkwardly beside the FRONTIER Act, introduced the same day, whose exclusivity clause would make the Commerce Secretary's emergency-order procedure the only lawful means of restricting a frontier model on catastrophic-risk grounds
−Silent on everything except the brake — no frameworks, audits, testing, transparency, workers, or preemption