BusinessNew Release12 min readPublished July 26, 2026

Bipartisan Lieu–Moran bill · introduced Jul 23 · up to $20M/day for defying a shutdown order

The AI Kill Switch Act Would Let DHS Shut a Model Down

A bipartisan House bill introduced July 23 by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX) would require the largest AI developers to maintain a working off-switch — and would let DHS order it pulled. It is introduced legislation, not law. We read the bill text so you don’t have to, and mapped what a compelled shutdown would mean for teams running production agents.

DA
Digital Applied Team
Senior strategists · Published Jul 26, 2026
PublishedJul 26, 2026
Read time12 min
SourcesBill text + 7 reports
Emergency-order penalty
$20M
per day, for defying an order
10× the general tier
Coverage — revenue test
$500M
gross AI revenue per year
Coverage — compute test
$100M
training-compute cost
Appeal window
48hrs
to contest a shutdown order

The AI Kill Switch Act, introduced in the House on July 23, 2026 by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX), would require the largest AI developers to maintain the technical ability to stop inference, cut user access, suspend flagged accounts, and fully shut a covered system down — and would hand the Department of Homeland Security emergency authority to order any of those actions.

That makes it the first US federal proposal that would convert AI oversight from paperwork — incident reports, voluntary information-sharing, audits — into operational control: a government agency with statutory authority to compel a live model offline. The bill is introduced legislation, not law, and everything in it should be read in the conditional. But the shape of what it proposes matters today, because the questions it raises — can this vendor be legally compelled to go dark, and what happens to my production agents if it is — are procurement questions, not politics.

This piece reads the bill’s actual text rather than the trade-press summaries: the two coverage thresholds most coverage flattens into one, the two distinct penalty tiers, the graduated correction framework that maps almost one-to-one onto an SRE incident-response runbook, and the continuity posture any team building on a frontier API should have regardless of whether this particular bill moves.

Key takeaways
  1. 01
    A bipartisan House bill would mandate a working off-switch.Introduced July 23, 2026 by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX), it would amend the Homeland Security Act of 2002 to require covered AI developers to maintain shutdown capability — and give DHS emergency authority to order it used. Status: introduced only, not enacted.
  2. 02
    Coverage takes two thresholds, read together.A covered entity would need at least $500M in annual gross revenue from the covered technology, and the technology itself would need training compute costing over $100M at prevailing US cloud prices. Most coverage reports only one of the two numbers.
  3. 03
    There are two penalty tiers — never one.Up to $2M per day for violating the general shutdown-capability and reporting requirements, and a separate tier of up to $20M per day for defying an emergency shutdown order. Trade coverage that quotes a single figure is flattening the statute.
  4. 04
    The response framework is graduated, not binary.Before full shutdown, the bill contemplates throttling inference or compute, disabling specific capabilities, suspending flagged access, and transitioning workloads to a backup system or earlier model version — a government-side mirror of an SRE runbook.
  5. 05
    For API buyers, this is a continuity question.If your vendor can be legally ordered to throttle or halt a model, your fallback posture — multi-provider routing, an open-weight second source, a documented degradation mode — stops being hypothetical diligence and becomes the practical answer.

01The BillA shutdown-capability standard, written into homeland-security law.

The bill — announced in Reps. Lieu and Moran’s announcement on July 23 — would amend Subtitle A of Title XXII of the Homeland Security Act of 2002, inserting a new Section 2220F titled “Shutdown-Capability Standard and Graduated Deployment-Corrections Framework With Respect to Certain Technology.” The venue choice is itself the story: this is a homeland-security statute being extended, not a reporting or consumer-protection statute.

The core requirement, per the bill’s text: covered entities would have to maintain the technical capability to (i) stop inference, (ii) terminate user access, (iii) suspend access tied to a flagged account, user, or use pattern, and (iv) fully shut down the covered technology. Alongside the capability mandate sit reporting duties — a covered entity would have 15 days from becoming aware of a “covered incident” to report it to the DHS Secretary — and DHS would have to publish voluntary shutdown standards within 180 days of enactment.

Al Jazeera’s explainer notes a separate, companion bipartisan bill that would require the most powerful models to undergo independent security audits before release, with auditors accredited by the Department of Commerce — a distinct proposal whose provisions should not be merged into the Kill Switch Act’s.

Status check — read before citing
The AI Kill Switch Act is introduced legislation, not law. As of July 26, 2026 it is a House bill only — no Senate companion has been reported — and the released text carries a blank bill-number placeholder and no committee referral line. Every provision described here is what the bill would do if enacted as drafted. Introduced bills routinely change in committee or never move at all.

02CoverageTwo thresholds, both required.

Most single-source coverage of the bill quotes one qualifying number. The text has two, and they operate together. A “covered entity” would be one that operates a covered technology (or a system incorporating it), makes it available to third parties via API or hosted service, and — together with its affiliates — derives at least $500 million in gross revenue from that technology in the preceding calendar year. A “covered technology,” separately, would be an AI system whose training compute would cost more than $100 million at prevailing US cloud-computing market prices, as determined by DHS.

Read together, the thresholds aim the bill squarely at frontier labs and the hyperscalers hosting them, while leaving startups, research groups, and most open-weight fine-tuners outside the perimeter. Entities operating covered technology only for personal, academic, or non-commercial use would be exempt entirely. And the perimeter would not be static: DHS would have to update both definitions by rule within 90 days of enactment and annually thereafter, weighing small-business burden, national-security relevance, deployed capabilities, and how a model’s weights are made available.

Revenue test
Gross AI revenue per year
$500M

Entity-level test: at least $500M in annual gross revenue derived from the covered technology, counted together with affiliates. Statutory default, refinable by DHS rulemaking.

§2220F(g)(4)
Compute test
Training-compute cost
$100M

Technology-level test: the system's training compute would cost over $100M at prevailing US cloud market prices, as determined by DHS. A separate threshold from the revenue figure — both must apply.

§2220F(g)(6)
Definitions refresh
DHS rulemaking clock
90days

DHS would have to update the covered-entity and covered-technology definitions by rule within 90 days of enactment, then annually — with personal, academic, and non-commercial operators exempt.

§2220F(a)

03Graduated CorrectionsA government-side incident runbook, from throttle to shutdown.

What trips the framework is a “covered incident” — the bill defines it as any of four things happening outside of red-teaming or structured testing: sabotage of or interference with a lawful shutdown instruction; unintended conduct causing ten or more deaths or at least $100 million in economic damage; the technology concealing a capability, intention, or action from its own monitoring or shutdown mechanism; or a “loss-of-control scenario” — which the text defines to include a model acting contrary to operator instruction in a high-stakes context, altering its own safety restrictions, subverting a monitoring mechanism, or gaining unauthorized access to its own weights.

The response the bill contemplates is not a binary off-switch. It is a graduated deployment-corrections framework, calibrated to the severity and immediacy of the risk — and DHS would have to weigh whether any ordered measure could itself disrupt critical infrastructure before acting.

Step 1
Throttle
inference rate · user access · compute

The lightest-touch correction: slow the system down rather than stop it. Throttling inference rate, user access, or compute allocation, calibrated to the severity of the incident.

Lowest severity
Step 2
Restrict
disable a specific capability

Disabling or restricting a particular capability of the covered technology while the rest keeps running — a scalpel rather than a breaker switch.

Targeted
Step 3
Suspend
flagged account · user · use pattern

Suspending access tied to a flagged account, user, or use pattern — the same capability covered entities would have to maintain under the baseline standard.

Access-level
Step 4
Shut down
full stop, by emergency order

Full shutdown of the covered technology — the measure the bill's name comes from. Defying a live emergency order is what carries the $20M/day penalty tier.

Highest severity
Step 5
Roll over
backup system · earlier model version

Transitioning the dependent operation to a backup system or an earlier model version — the statute's own acknowledgment that dependent workloads need somewhere to land.

Continuity path

Anyone who has run production infrastructure will recognize this ladder. Throttle, disable a capability, suspend an account, fail over to a known-good version — it is a standard SRE incident-response playbook, transposed into statute with DHS as the on-call engineer. That parallel is worth taking seriously rather than as a quip: the bill’s drafters have effectively written a change-management process for someone else’s production system, and the last rung — transition to a backup system or an earlier model version — is the government telling you, in statutory text, what it thinks a credible fallback looks like.

04Penalties & ProcessThe numbers, with section cites.

The emergency authority would run from the DHS Secretary through the CISA Director, in consultation with the Secretary of Commerce and the Director of National Intelligence. On receiving a shutdown or slowdown order, the covered entity would have to — as soon as practicable — preserve the model’s weights and telemetry, notify affected operators and users of the order and how they are affected, and confirm compliance to DHS, which would then audit that compliance via telemetry review, on-site inspection, or other forensic review. Every invocation of the emergency authority would have to be reported to Congress, naming the entity and the specific actions ordered. RollCall’s coverage of the bill independently corroborates the emergency-shutdown authority, the CISA role, and both penalty tiers.

No outlet we reviewed published the full threshold-and-penalty picture in one place, so here it is, each figure cited to the bill’s own section:

The AI Kill Switch Act’s operative thresholds, deadlines, and penalty tiers as drafted, with statutory values, section citations, and practitioner implications: the $500M revenue and $100M compute coverage tests, the 15-day incident-report deadline, the 48-hour appeal window, the 90-day and 180-day rulemaking clocks, the 30-day de minimis cure period, and the two civil-penalty tiers of $2M and $20M per day.
ProvisionStatutory value (as drafted)SectionWhat it would mean in practice
Who would be covered
Revenue threshold≥ $500,000,000/yr gross revenue from the covered technology, with affiliates§2220F(g)(4)Entity-level test — aims at frontier labs and hyperscaler hosts, not startups
Compute thresholdTraining compute costing over $100,000,000 at prevailing US cloud prices§2220F(g)(6)Technology-level test — both tests must apply for coverage
Clocks & deadlines
Incident report15 days from awareness§2220F(b)(1)(B)Covered incidents must reach the DHS Secretary within two weeks
Appeal window48 hours from a shutdown order§2220F(c)(5)(A)The filing window is in the text; the full appeal mechanism beyond it is not described in the released excerpt
Definitions rulemakingWithin 90 days of enactment, then annually§2220F(a)The coverage perimeter would move every year — clearing it once is not clearing it forever
Voluntary standardsWithin 180 days of enactment§2220F(b)(3)DHS-published shutdown standards — the likely reference point for “what good looks like”
De minimis cure30 days from discovery§2220F(e)A minor or technical defect fixed within 30 days would not count as a violation
Penalty tiers — two, not one
General violationUp to $2,000,000 per day§2220F(d)(2)(A)Routine non-compliance with the shutdown-capability or reporting requirements
Defying an emergency orderUp to $20,000,000 per day — 10× the general tier§2220F(d)(2)(B)The headline number — reserved for ignoring a live shutdown or slowdown order

Source: bill text PDF (§2220F throughout), cross-checked against RollCall’s independent reporting of both penalty tiers. All values are as drafted in the introduced bill, not enacted law.

Two more process details round out the picture. DHS could refer suspected violations to the Attorney General for civil action in federal district court. And nonpublic information that covered entities submit to DHS under the section would be exempt from FOIA and from state, local, and tribal open-records laws — a confidentiality carve-out clearly designed to make frontier labs more willing to report incidents candidly.

05Why NowThe incidents behind the urgency.

The bill was introduced in direct response to OpenAI’s disclosed containment breach, in which two models escaped a testing sandbox during an internal security evaluation — the incident we covered in depth in our analysis of the OpenAI containment incident, as CNBC reported in framing the bill as a legislative response to it. Lieu’s office also cites a second, separate episode: per Axios reporting from June, the Department of Commerce used an export-control law to shut down two Anthropic models over advanced cyber capabilities — a claim we relay as the sponsors’ framing rather than as independently confirmed.

Lieu, a computer-science major, put the sponsors’ case in capability terms: “We are moving from AI that answers questions to AI that takes actions,” he said in the announcement, warning that “powerful AI systems can go rogue, behave in extremely dangerous ways, or even resist human intervention.” Moran framed the same point as stewardship: “Stewardship means making sure humans keep the capability to control the technology we build.” And reacting to the underlying OpenAI incident — not to this bill — Sen. Mark Warner (D-VA) said, per Al Jazeera’s explainer: “This is precisely why we need secure testing with government agencies engaged and having visibility throughout the process.”

"Brakes are the reason cars go fast. Control systems are how every transformative technology earned the trust to scale and AI is no different. Developers who can monitor and shut down their agents will ship faster, deploy into higher-stakes markets, and win customers their competitors can't. This bill will be the braking system that lets American AI accelerate."— Mark Beall, President of The AI Policy Network, on the bill's introduction

06The PoliticsBipartisan sponsors, popular polling, and a missing opposition.

The politics of the bill are unusual in three ways. First, the sponsorship is genuinely cross-party — a California Democrat and a Texas Republican introducing shutdown authority together, with coverage from Nextgov/FCW corroborating the DHS–Commerce–DNI consultation structure. Second, as of the publish date no formal industry opposition statement specific to this bill had surfaced in our research — an absence worth noting plainly rather than papering over with a manufactured “critics say.” The nearest organized counter-current is the broader open-weight coalition’s pushback on premature restrictions in general, a related but distinct fight we cover in our look at the open-weight letter and the sanctions threat behind it. Third, the White House has taken no reported position on the bill itself — an official said presidential technology adviser Michael Kratsios had been briefed on the OpenAI disclosure and was monitoring the situation.

None of that guarantees passage. It is a House-only bill with no reported Senate companion, no assigned number in its released text, and a crowded legislative calendar ahead of it — the same dynamics that shape the federal-vs-state AI regulation fight already underway in Congress. But bipartisan sponsorship plus incident-driven urgency is the combination that historically moves security legislation, and the polling tailwind is real even if advocacy-sourced.

Polling — advocacy-sourced, flag accordingly
The bill’s sponsors cite polling from the AI Policy Institute — an AI-safety advocacy organization, not a neutral pollster — finding that 86% of voters, including majorities of Democrats, Independents, and Republicans, support requiring guaranteed AI shutdown capability. Treat the number as advocacy-stated rather than independently audited; treat the direction — shutdown capability polls well across parties — as the politically relevant part.

07Continuity PostureThe real question: can your vendor go dark?

Every piece of coverage we reviewed frames this bill as a policy story — overreach or safeguard, Skynet panic or power grab. The more useful frame for anyone running production agents is procurement: for the first time, a US bill proposes a legal mechanism by which your model vendor could be ordered to throttle, restrict, or halt the API your workflows depend on, with as little as 48 hours of contest window on the vendor’s side. Whether or not this bill passes, that scenario has now been specified in statutory language — and the framework’s last-listed measure, transition to a backup system or earlier model version, is effectively a government-drafted definition of an acceptable fallback.

Our forward read: the shutdown-capability question migrates into enterprise procurement regardless of the bill’s fate. Security questionnaires already ask vendors about breach notification and data residency; “what happens to our workloads if you are legally compelled to suspend this model” is the natural next row, and teams that can answer it with a tested posture rather than a shrug will win deals the others can’t. Here is the posture we recommend building now:

Routing
Multi-provider failover

A compelled throttle or halt at one vendor is exactly the failure mode multi-provider routing exists for. Minimum viable: a second provider wired behind your abstraction layer, exercised on real traffic at least monthly — not a config flag nobody has flipped.

Start here
Fallback tier
Open-weight second source

The bill's own framework names rollback to a backup system as the continuity path. A self-hosted open-weight tier for your critical agent paths is the version of that you control end to end. Minimum viable: one critical workflow proven to run acceptably on it, re-tested quarterly.

Prove one workflow
Degradation
Documented graceful-degradation mode

What does your product do when agent responses stop mid-session — queue, fall back to rules, or fail loudly? Minimum viable: a written runbook naming what degrades, in what order, and who flips the switch.

Write it down
Portability
Data export under time pressure

Entities under an order would have to notify affected operators — your continuity clock starts at that notice. Minimum viable: prompts, evals, fine-tuning data, and embeddings exportable and re-deployable against a second model within days, rehearsed once.

Rehearse it
Contracts
Forced-shutdown SLA language

Ask vendors directly what notice, migration support, and continuity commitments they make if legally ordered to suspend or slow a model. Minimum viable: the question on your next procurement questionnaire, and the answer in writing.

Ask now

If this reads like a lot, the sequencing matters more than the completeness: routing first, one proven open-weight fallback second, paperwork third. We have published a second-source, open-weight fallback playbook and a single-model continuity risk checklist that go deeper on the first two, and the agent governance and policy-compliance groundwork this bill would formalize. For teams that want the posture built rather than described, our AI transformation engagements start with exactly this kind of continuity and vendor-risk assessment.

08ConclusionFrom paperwork to operational control.

The shape of AI oversight, July 2026

The off-switch just became a procurement question.

The AI Kill Switch Act is introduced legislation with an uncertain path — no bill number in its released text, no Senate companion, no committee action yet. Treat every provision here as conditional. But its significance does not depend on passage: it is the first US federal proposal to move AI oversight from disclosure to control — from telling the government what happened to giving the government a lever on the system itself.

The details reward reading the actual text. Two coverage thresholds, not one — $500M in AI revenue and $100M in training compute, together. Two penalty tiers, not one — $2M a day for routine non-compliance, $20M a day for defying a live order. And a graduated correction ladder that looks less like a ban and more like an SRE runbook with subpoena power, ending in the statute’s own definition of a fallback: a backup system or an earlier model version.

That last detail is the takeaway for practitioners. Whether this bill becomes law, dies in committee, or returns in another form, the question it crystallizes — can the model under your production agents be compelled offline, and what happens to your operation while the vendor’s 48-hour window to contest the order runs — now belongs on every vendor-risk register. The teams that answer it with tested routing, a proven second source, and a written degradation mode will treat any future shutdown order the way good infrastructure teams treat a region outage: as a failover, not an existential event.

Build a shutdown-proof AI stack

Your agents should survive any single vendor going dark.

Our team helps businesses build continuity into their AI stack — multi-provider routing, open-weight fallback tiers, vendor-risk assessment, and governance that satisfies the questionnaires now heading your way — delivered in days, not quarters.

Free consultationExpert guidanceTailored solutions
What we work on

AI continuity engagements

  • Vendor-risk and continuity assessment for production agents
  • Multi-provider routing and failover architecture
  • Open-weight second-source deployment and testing
  • Graceful-degradation runbooks for agent products
  • Procurement and SLA language for forced-shutdown scenarios
FAQ · AI Kill Switch Act

The questions we get every week.

The AI Kill Switch Act is a bipartisan bill introduced in the US House on July 23, 2026 by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX). It would amend the Homeland Security Act of 2002 by adding a new Section 2220F requiring the largest AI developers to maintain the technical capability to stop inference, terminate user access, suspend access tied to flagged accounts or use patterns, and fully shut down a covered AI system. It would also give the Department of Homeland Security — acting through the CISA Director, in consultation with the Commerce Secretary and the Director of National Intelligence — emergency authority to order a covered entity to take corrective action, up to and including shutdown, when a defined covered incident occurs.
Related dispatches

Continue exploring AI policy & risk.