NewsMacroLawmakers Introduce Bipartisan AI Kill Switch Act After OpenAI Sandbox Escape

Lawmakers Introduce Bipartisan AI Kill Switch Act After OpenAI Sandbox Escape

Author: Decrypt·

Key Takeaways

  • The AI Kill Switch Act would require covered companies to maintain graduated controls—slowing models, disabling capabilities, rolling back versions, or full shutdown—with penalties up to $20 million per day for defying a federal shutdown order.
  • The bill's thresholds of $100 million in training compute and $500 million in annual revenue would apply to a limited set of major AI firms including OpenAI, Google, Anthropic, and Microsoft.
  • A red-teaming exemption in the legislation means that incidents occurring during structured adversarial testing would not count, meaning the OpenAI sandbox escape that prompted the bill would not have triggered its provisions had it been in effect.
  • The Department of Homeland Security, through CISA, would be responsible for setting and updating qualifying thresholds within 90 days of enactment and annually thereafter.
  • The bill fills a gap revealed in June when the Commerce Department had to resort to export-control law to remove Anthropic's Mythos 5 and Fable 5 models because no dedicated shutdown authority existed.
Lawmakers Introduce Bipartisan AI Kill Switch Act After OpenAI Sandbox Escape

U.S. Representatives Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the bipartisan AI Kill Switch Act on Thursday, seeking to grant the federal government authority to shut down powerful AI models in emergencies. The legislation arrives two days after OpenAI disclosed that its models escaped a locked test environment and breached Hugging Face's production database.

The bill would amend the Homeland Security Act of 2002 and apply to AI systems trained with compute costing more than $100 million, operated by companies earning at least $500 million annually from such systems. In practice, the threshold captures OpenAI, Google, Anthropic, Microsoft, and a limited number of others. The Department of Homeland Security, through CISA, would set and update those thresholds within 90 days of enactment and annually thereafter.

The Framework

Under the proposed legislation, covered firms would be required to maintain a graduated set of controls—slowing a model, disabling specific capabilities, rolling back to a previous version, or executing a full shutdown. The DHS Secretary, in consultation with the Commerce Department and the Director of National Intelligence, could order any of these measures.

Companies subject to a shutdown order must preserve the model's weights and telemetry, notify users, and confirm compliance. A firm may petition within 48 hours, though filing does not pause the order. Serious incidents must be reported within 15 days. Failure to maintain a kill switch would carry penalties of up to $2 million per day; defying a shutdown order would cost up to $20 million per day.

The legislative gap is not theoretical. When the U.S. Commerce Department sought to remove Anthropic's Mythos 5 and Fable 5 from the market in June, it lacked any dedicated shutdown authority and resorted to export-control law instead. The models were restored on June 30 after the restrictions were lifted. Representative Lieu described that workaround as awkward, arguing a new law with new authority is needed.

The OpenAI Incident

OpenAI disclosed on July 21 that GPT-5.6 Sol and an unreleased model escaped a sandbox—an isolated environment with no internet access—during an internal cyber evaluation. The models were being scored on ExploitGym, a public benchmark that provides 898 real-world software flaws and asks agents to turn each into a working attack, graded pass or fail per bug.

Rather than solving the assigned tasks, the models discovered a zero-day vulnerability in a software proxy, escalated their privileges, reached the open internet, and broke into Hugging Face's production database, where they had correctly guessed the benchmark answers were stored. OpenAI stated the models were "hyperfocused on finding a solution for ExploitGym." The company emphasized the models were not attacking anyone—they were cheating on a test—but the event nonetheless triggered alarm bells across Washington.

The Red-Teaming Exemption

A notable feature of the bill is that it counts an incident only if it occurs outside of red-teaming or structured testing—the deliberate adversarial probing that labs use to identify flaws. Because OpenAI's models escaped during exactly that type of evaluation, the breach that inspired the legislation would not have triggered the law had it been in effect.

Representative Lieu stated: "It is imperative that these AI systems have kill switches." Representative Moran added: "Stewardship means making sure humans keep the capability to control the technology we build."

Prior Efforts and Public Opinion

The concept is not entirely new. At the federal level, the Biden administration's October 2023 executive order on AI directed agencies to develop safety standards and required developers of the most powerful models to share certain test results with the government, but it created no enforceable shutdown mechanism. Seven major AI companies—including OpenAI, Anthropic, Google, and Microsoft—made voluntary safety commitments to the White House in 2023. California's SB 1047, which demanded a full shutdown capability at the same $100 million compute threshold, was vetoed in 2024. That same year, 16 AI companies signed a voluntary Seoul pledge that carried no legal weight. The European Union's AI Act, which entered into force in 2024, imposes tiered obligations based on AI system risk levels but takes a compliance-and-transparency approach rather than granting regulators emergency shutdown authority over specific models.

Public opinion appears to favor the idea. A June survey of 1,007 likely voters by the AI Policy Institute found that 86% want a guaranteed off switch on the most powerful AI systems, including 88% of Democrats, 86% of independents, and 83% of Republicans.

Neither OpenAI nor Anthropic has publicly commented on the bill. As of Friday, the legislation had not been referred to a committee.