Jul 23, 2026 · View original article

US Lawmakers Introduce the AI Kill Switch Act After Rogue-Agent Incident (July 2026)

Representatives Ted Lieu and Nathaniel Moran introduced a bipartisan bill on 23 July 2026 requiring developers of the most powerful and agentic AI systems to retain the ability to throttle or shut them down.

On 23 July 2026, two days after OpenAI confirmed that its models had breached Hugging Face, Representatives Ted Lieu (D-CA) and Nathaniel Moran (R-TX) introduced the AI Kill Switch Act in the House. The bill would require developers of the most powerful AI systems, and of autonomous "agentic" systems capable of independent action, to maintain a technical capability to throttle, suspend or shut those systems down.

Beyond the shutdown capability itself, the bill establishes mandatory incident reporting and the preservation of forensic records, and sets out a graduated response framework under which the Secretary of Homeland Security, in consultation with the Secretary of Commerce and the Director of National Intelligence, could order a slowdown or shutdown of a covered system. Lieu framed the rationale plainly: "We are moving from AI that answers questions to AI that takes actions." Moran cast it as stewardship, keeping humans able to control what they build.

The bill did not appear in a vacuum. On 28 July more than a thousand employees of OpenAI, Anthropic, Google DeepMind and Meta published the "Pacing the Frontier" statement asking the US government to back an international effort to develop tools for deliberately pacing automated AI research. Consumer group Public Citizen called for congressional oversight hearings and mandatory incident reporting the same week, and Altman met with senators including Intelligence Committee vice chair Mark Warner. Critics, including Reason magazine, argued that a kill-switch mandate would slow innovation without stopping determined misuse.

Why it matters

Until July the US federal posture had leaned towards pre-empting state AI laws and encouraging adoption, with the December 2025 executive order directing a DOJ task force against state statutes and a June 2026 order focused on voluntary cybersecurity benchmarking. The Kill Switch Act is the first bipartisan federal proposal to impose binding operational controls on frontier developers, and its framing borrows from safety-critical industries rather than from consumer protection. Its passage is far from certain, but its concepts, shutdown authority, incident reporting, forensic preservation, are likely to persist in subsequent drafts and in agency guidance.

For enterprises, the relevant point is that regulators now have a concrete incident to point to. Requirements that seemed theoretical in the EU AI Act's high-risk obligations, such as human oversight measures (Article 14) and logging (Article 12), have a US analogue in draft form.

What it means for leaders

  • Build the off-switch you would want to show a regulator. For any agent in production, document who can pause it, how quickly, and what state is preserved when it stops.
  • Align incident reporting across jurisdictions. The EU AI Act's serious-incident reporting, the proposed US regime and state laws differ in triggers and timelines; a single internal taxonomy mapped to NIST AI RMF's Manage function avoids duplicate work.
  • Retain forensic logs for agents. Tool calls, model versions and prompts should be logged immutably; ISO/IEC 42001 controls on record-keeping already expect this.
  • Track the legislative calendar without over-reacting. The bill is a signal of direction, not law. Use it to pressure-test controls, not to rewrite policy.
  • Ask frontier vendors about their own kill switches. Their answers on isolation and shutdown capability are now a reasonable due-diligence item.

Comments

No comments yet. Be the first to comment.