WeVote

Bill

Bill

HR 9917

AI Kill Switch Act

119th Congress Introduced by Ted Lieu and 1 co-sponsor

Requires high-cost AI operators to maintain shutdown/throttle capabilities and follow a risk-based framework, including emergency orders and penalties.

Referred to the Subcommittee on Cybersecurity and Infrastructure Protection.
0
WeVote Research Nonpartisan
Bill Summary · HR 9917

Overview

  • Bill: HR 9917, the AI Kill Switch Act
  • Session: 119th Congress (introduced July 23, 2026)
  • Purpose: Amend the Homeland Security Act of 2002 to require certain entities that manage advanced AI technologies to maintain a technical capability to shut down or throttle those technologies, with a graduated framework for deployment and corrective actions. Includes emergency authorities, penalties, and definitions.

Main purpose and intent

  • Establish a regulatory framework to ensure that entities operating high-impact AI systems have the capacity to halt or limit use of those systems in response to risks, incidents, or security concerns.
  • Create a structured, rule-based process for deploying shutdown and throttling measures as needed to protect national security, public safety, and critical infrastructure.

Key provisions and changes

  • New Section 2220F added to the Homeland Security Act (Subtitle A of Title XXII):
    • Shutdown-capability standard and graduated deployment-corrections framework for certain technology.

(a) Rulemaking for covered entities and technologies

  • The Secretary, via the Director, must update definitions for:
    • Covered entity
    • Covered technology
  • Annual or more frequent updates, within 90 days of enactment for initial rule and annually thereafter.
  • Factors for defining coverage include: burden on small businesses, national security relevance, cybersecurity and CBRN capabilities, and availability of model weights and deployment details.
  • Exemption: Entities that provide covered technology only for personal, academic, or non-commercial use are not covered.

(b) Shutdown capability requirements

  • Within 90 days of enactment and annually thereafter:
    • Covered entities must maintain a technical capability to:
    • Stop inference of the technology
    • Terminate user access
    • Suspend access for accounts/users/patterns posing risk or violating law/terms
    • Shut down the technology
    • Report any covered incident within 15 days of awareness to the Secretary.
    • Consider a graduated deployment-corrections framework, including throttling, disabling/restricting capabilities, suspending, shutting down, or transitioning to backup/earlier versions, calibrated to risk severity and immediacy.
    • Assess risk to critical infrastructure when selecting measures.
    • Publish voluntary standards for shutting down covered technology within 180 days.

(c) Emergency authority

  • The Secretary, with the Director and in consultation with the Secretary of Commerce and DNI, can order a covered entity to take proportionate action during a covered incident (may include shutdown actions).
  • After an order:
    • The entity must preserve model weights and telemetry and inform operators/users affected, as practicable.
    • The entity must confirm compliance; the Secretary can audit and verify.
    • Congress must receive a report detailing the incident, actions ordered, and the entity involved.
    • An appeal process allows reconsideration within 48 hours (no stay on the order); a 5-day determination window; judicial review in the D.C. Circuit within 60 days.

(d) Enforcement and penalties

  • Civil penalties for violations:
    • Up to $2,000,000 per day for general violations.
    • Up to $20,000,000 per day for violations of emergency orders.
  • Penalty factors include gravity, culpability, history, voluntary disclosures, and other justice considerations.
  • Authority to pursue civil action in federal court if violations occur or are imminent.
  • Compliance and minor violations: de minimis violations fixed within 30 days after discovery are not counted as violations.
  • Non-disclosure protections for nonpublic information submitted to the Secretary.

(e) Compliance clarifications

  • Minor violations that are corrected promptly are not counted as violations.

(f) Non-disclosure

  • Nonpublic information submitted to the Secretary is exempt from disclosure laws and FOIA-like requirements.

(g) Definitions (selected)

  • Covered technology: AI systems with computing power cost exceeding $100 million at current cloud prices, as determined by the Secretary.
  • Covered entity: An entity that operates the technology, provides it via APIs/hosted services, or derives at least $500 million in gross revenue from the technology (with affiliates considered).
  • Covered incident: Events such as sabotage of shutdown instructions, unintended harmful outcomes (e.g., death or economic damages meeting thresholds), concealment of capabilities, or loss-of-control scenarios.
  • Artificial intelligence system and related terms: Broad definitions aligned with national AI initiatives, including red-teaming concepts and safety/testing terms.
  • Red-teaming: Controlled, adversarial testing in a simulated environment to identify vulnerabilities.
  • Small business concern: As defined by the Small Business Act.

Who would be affected

  • Covered entities: Organizations that operate, deploy, or monetize high-cost AI technologies and their affiliates with substantial revenue derived from the technology (thresholds include $500 million revenue in the prior year).
  • Limited exemptions: Entities offering covered technology for personal, academic, or non-commercial use are not covered.
  • Potentially affected stakeholders include AI developers, platform providers, cloud service operators, researchers, and users tied to high-risk AI deployments.

Procedural and timeline aspects

  • Rulemaking cadence:
    • Initial definitions and framework to be issued within 90 days after enactment.
    • Annual updates to definitions and deployment framework.
    • Voluntary standards published within 180 days.
  • Emergency order process:
    • Secretary can issue an emergency order during a covered incident.
    • Immediate actions by the entity, verification, reporting to Congress, and a narrow appeal and judicial review pathway.
  • Reporting:
    • Incident reports due within 15 days of awareness.
    • Congressional reporting tied to emergency orders.

Potential impacts to consider

  • Heightened operational and governance requirements for large AI-equipped entities.
  • Compliance costs related to maintaining shutdown capabilities and incident reporting.
  • A framework to mitigate AI-related risks in national security, public safety, and infrastructure contexts.
  • Privacy and information-security considerations due to data retained (model weights, telemetry) and non-disclosure protections.

Note: The bill is in early stages, with House referral to the Homeland Security Committee and Subcommittee on Cybersecurity and Infrastructure Protection. Co-sponsors include Rep. Ted Lieu and Rep. Nathaniel Moran.

Compiled from official sources — confirm details with the bill’s official record.

Sign in to ask a question.