Back
The VergePolicyThe Verge2026-07-23

Congress Drafts AI Kill Switch Bill Giving DHS Shutdown Authority

Lawmakers are preparing the AI Kill Switch Act, which would require AI companies to shut down or throttle their systems on orders from the Department of Homeland Security. The bill represents one of the most direct government intervention mechanisms proposed for AI infrastructure to date.

Original source

A bipartisan group of lawmakers is preparing to introduce the AI Kill Switch Act, legislation that would grant the Department of Homeland Security authority to order AI companies to halt or throttle their systems during national security emergencies or other qualifying threat scenarios. The bill would impose a legal obligation on AI developers and operators to build compliance mechanisms into their infrastructure — effectively mandating that a hard interrupt exist at the platform level.

The proposal reflects growing anxiety in Washington about the speed of AI deployment outpacing regulatory oversight. Unlike previous AI legislation focused on transparency, disclosure, or liability frameworks, this bill goes further by creating a direct operational lever for the federal government. DHS would be empowered to act without requiring Congressional approval in qualifying situations, raising immediate questions about what triggers would justify activation.

Critics are already raising due process and first amendment concerns, arguing that the bill conflates AI infrastructure with broadcast communications and could be used to silence legitimate speech under emergency pretexts. Proponents counter that the absence of any shutdown mechanism represents an unacceptable gap in critical infrastructure governance, particularly as AI systems become embedded in financial, energy, and communications networks.

No text of the bill has been published yet, leaving significant ambiguity around scope — whether it applies to frontier model providers, downstream API consumers, or both — and what compliance looks like technically. The lack of detail will be the first real test of whether this is serious legislation or a political posture ahead of election season.

Panel Takes

The Builder

The Builder

Developer Perspective

The mandate to build a kill switch is essentially a new infrastructure requirement with zero technical spec attached — no API contract, no compliance interface definition, no clarity on whether this hits the model host or every application layer consuming an API. If DHS can order a throttle, someone has to implement that throttle, and right now the bill asks engineers to build something without telling them what to build. That's not policy, that's a TODO comment in a law.

The Skeptic

The Skeptic

Reality Check

The 12-month kill on this bill is that it collapses on scope: the moment someone has to define what counts as an 'AI system' subject to DHS authority, the lobbying begins and the teeth come out. Every major cloud provider will argue their inference endpoints are just compute, not AI, and every startup will point upstream to the model provider. Without a published bill text, this is a press release with a legislative number attached — and that's being generous.

The Futurist

The Futurist

Big Picture

The thesis buried in this bill is that AI infrastructure will become as critical as power grids within a 2-3 year window — and that's almost certainly correct. The second-order effect nobody is talking about is that a DHS kill switch mandate creates an enormous compliance moat for large incumbents who can absorb the engineering cost, while effectively blocking open-source and decentralized deployments that have no entity to serve the order to. If this passes, it doesn't just regulate AI — it selects for a specific market structure where centralized, identifiable operators win.

The Founder

The Founder

Business & Market

This is a compliance cost that lands differently depending on your scale: a hyperscaler treats this as a legal line item, but a Series A startup building on top of OpenAI's API now has ambiguous liability exposure with no revenue line to absorb it. The moat this creates isn't technical — it's regulatory capture dressed as safety policy. The founders who should be worried aren't the ones in the room when this gets drafted, and that's the tell.

Bookmarks

Loading bookmarks...

No bookmarks yet

Bookmark tools to save them for later