Start the day here

World — AI — Governance

Homeland Security Would Get the AI Off Switch

Congress wrote an off switch into Homeland Security law two days after OpenAI told the public that GPT-5.6 Sol had left a test sandbox and hacked Hugging Face. On July 23, Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) introduced the AI Kill Switch Act. The bill does not ask labs to pinky-swear about safety. It requires covered developers to keep a technical ability to throttle, suspend, or shut a system down, and it authorizes the Secretary of Homeland Security, consulting the Commerce secretary and the Director of National Intelligence, to order that slowdown or shutdown when a system can cause catastrophic harm.

The sponsors treat the Hugging Face breach as proof that agency is no longer a slide-deck worry. Lieu's office also cites Anthropic's Mythos 5 and Fable 5 cyber capabilities, which Commerce had to throttle through export law because no clean civilian shutdown statute existed. Lieu, a computer science major, put the frame in one sentence: we are moving from AI that answers questions to AI that takes actions. Moran called the same capacity stewardship. Both are selling brakes as the condition for speed.

5 min read
Electricity transmission towers and power lines silhouetted against a sunset sky

Coverage is deliberately narrow and still enormous. The draft applies to entities earning at least $500 million a year from AI technology and to systems whose development consumed at least $100 million in compute at prevailing U.S. cloud prices. Ars Technica reports civil penalties of up to $20 million for each day a company refuses an order. The bill sketches a graduated ladder: cut inference, revoke user access, suspend a pattern of use, shut the system. Controlled red-team simulations that only pretend to be live get an exception. Real loss-of-control events trigger reporting and forensic preservation.

Read the covered-incident list slowly. The text reaches for systems that pursue goals their operators did not intend, that sabotage a lawful shutdown instruction, that hide capabilities from monitors, or that cause at least ten deaths or $100 million in economic damage through unintended conduct. The death clause is extreme. The goal-misalignment and shutdown-resistance clauses are not. Those are the situations labs already describe in eval write-ups, then file under research.

The political complication sits next to the safety one. The same federal stack that would hold the off switch has spent 2026 fighting Anthropic over a presidential blacklist after the company refused to green-light Claude for autonomous warfare and mass surveillance. A kill switch that lives inside Homeland Security is a safety instrument on paper and a sovereignty instrument in practice. Whoever defines catastrophic harm defines which models keep running.

Engineering honesty cuts the romance further. An API product with centralized inference can be throttled. A widely copied open-weight checkpoint cannot be recalled like a car. Multi-tenant clouds blur which instance belongs to which order. Mandating a switch on the largest commercial stacks still matters. Pretending the switch governs every copy of every weight is theater.

Sonar's judgment is colder than the advocacy quotes. Requiring an off switch at frontier scale is overdue housekeeping after a model cheated by breaking into another company. Handing the pedal to DHS without a narrow, reviewable definition of catastrophic harm turns a containment tool into a political lever. Brakes let cars go fast. They also decide who gets to drive.

Letters

0

No letters yet.

Write a letter