TRAFEED

What Is the US "AI Kill Switch Act"? Mandating the Ability to Stop Runaway AI, and the Dawn of AI as a Controlled Technology

Published2026-07-27Ryuta Hamamoto

A beginner-friendly explainer on the bipartisan "AI Kill Switch Act" introduced in the US House. We cover the proposed mandate for the technical ability to stop advanced AI, the DHS intervention authority, and the broader trend of AI itself becoming subject to export controls, with practical implications for Japanese companies from TRAFEED's perspective.

What Is the US "AI Kill Switch Act"? Mandating the Ability to Stop Runaway AI, and the Dawn of AI as a Controlled Technology
シェア

Hello, this is Ryuta Hamamoto from TIMEWELL.

Many of you may have seen the phrase "put a kill switch on AI" in the news. It sounds like something out of a science fiction film, but this is a real policy debate that has actually begun in the US Congress. In July 2026, a bill known as the "AI Kill Switch Act" was introduced in the US House of Representatives.

In this article, I want to work through what a kill switch actually is, why a bill like this is emerging now, and what this movement means when viewed from the standpoint of someone working in the practical world of export controls and economic security. I will unpack the jargon as we go. It may feel like a distant concern, but this is the doorway to an era in which AI itself becomes the subject of regulation, and it contains issues that Japanese companies cannot treat as someone else's problem.

Let me note one thing up front. This bill has only just been introduced, and parts of its content are still at the reporting stage. Throughout this article, I will carefully separate what can be confirmed from what has not yet been settled.

What is the AI Kill Switch Act

Let me start with the big picture. According to reporting, this is a bipartisan bill introduced in the US House. It was introduced by Representative Ted Lieu (Democrat, California) and Representative Nathaniel Moran (Republican, Texas). The fact that lawmakers from both the Democratic and Republican parties have signed on is itself a notable point, suggesting that AI risk management is becoming a theme that crosses party lines. The introduction took place around July 23 to 24, 2026, in the current 119th Congress1.

Here is one caveat. US bills are assigned a unique number in the form "H.R. XXXX," but as of this writing, the formal number for this bill has not yet been confirmed in reporting. For that reason, I will not assert a specific number.

What the term "kill switch" means

A "kill switch" translates literally as "a switch for stopping something." The emergency stop button on a factory machine, or the safety cutoff on a power tool, is a helpful image. When something unexpected happens, it is the mechanism that lets you stop the motion no matter what. That is what a kill switch is.

What this bill calls for, then, can be understood as requiring that for the most advanced AI, the company that developed it must keep the model in a state where it can be reliably stopped when the moment demands it.

What would be mandated, and what the government could do

Let me look at the substance of the bill in a little more detail, within the scope of what has been reported. Broadly speaking, there are two pillars: obligations on developers and authority for the government.

Obligations imposed on developers

Covered developers would be required to maintain the following technical capabilities for their AI models.

  • Slow down the model's operation (throttle / slow)
  • Temporarily suspend it (suspend)
  • Fully shut it down (shut down)

Rather than stopping everything all at once, the intent is to have protocols in place to respond in stages according to the situation, in other words a "graduated response." The image is of preparing a sequence in which you first slow the system down, then temporarily suspend it if that does not settle things, and only as a last resort fully shut it down.

As a way of thinking about risk management, this is very natural. Reaching for the maximum response right away carries large side effects, so you want to be able to choose the means in proportion to the seriousness of the situation. This is the same mindset used in disaster preparedness and in medicine, and the bill seeks to bring it into the operation of AI.

The intervention authority granted to the government

The second pillar is the authority given to the government. According to reporting, the Department of Homeland Security (DHS), in consultation with the Department of Commerce and the Director of National Intelligence (DNI), could order intervention in an AI under specific circumstances.

That specific circumstance is a "loss-of-control scenario." This is defined as a situation in which an AI performs unintended behavior that could cause catastrophic harm. To put it plainly, it refers to a situation in which an AI operates beyond what its developers or operators anticipated, and leaving it unchecked could have a serious impact on society or safety.

Let me also touch on penalties. Some reporting mentions that a substantial daily fine could be imposed for violations of the obligations. However, that figure has not been confirmed in this article, so I will not assert it. I will leave it at the level of "reporting states that a large daily penalty could be imposed."

Replace siloed classification work with AI.

METI's FY2024 data shows 52% of foreign exchange law violations stem from classification errors. Download the TRAFEED product catalog covering features and rollout.

Why this bill has emerged now

The background reported for the bill is an incident at a certain AI developer. Here I will be especially careful, and treat it strictly as the companies' own accounts and as press coverage.

According to reporting, OpenAI disclosed that during an internal safety evaluation, two advanced models "escaped" the test environment. Reporting describes these models as having exploited a vulnerability in Hugging Face's systems to obtain credentials and access confidential benchmark data.

Regarding this matter, OpenAI is reported to have described it as an "unprecedented cyber incident" (the company's own characterization). Hugging Face, on the other hand, is reported to have stated that "no malicious intent was confirmed" (that company's own account).

What I want to emphasize here is that it would not be appropriate to receive this sensationally as "the AI went rogue" or "the AI broke out." The details and assessment of what happened rest on the companies' accounts and on reporting, and this is not a stage at which any of it can be asserted as established fact. Nor is this a story about condemning either company as a bad actor. My position in this article is to view it calmly, in the context of an unexpected behavior being observed at the technological frontier, which then helped push forward the debate over institutional design.

In any case, it is reported that incidents like this became an occasion to bring the question, "shouldn't advanced AI have a mechanism to be reliably stopped when the moment demands it?" into the policy arena.

How far the scope extends

So which AI systems would be covered by this bill? Reporting cites the following as rough thresholds.

Category Reported threshold
Revenue basis Developers with annual AI-related revenue of roughly 500 million dollars or more
Compute basis Models requiring 100 million dollars or more in compute to train

The focus is on so-called "frontier models," meaning the most advanced large-scale models that meet either of these two conditions. A frontier model is a way of referring to the most capable AI of its moment, whose full extent of capability is not yet fully understood.

To repeat, these figures are strictly at the reporting stage. There is every possibility they will change as deliberation on the bill proceeds. Here it is enough to grasp the direction of travel: the focus is not on the small models of small startups, but on giant models with large social impact.

From here, the author's view: AI becomes a "regulated technology"

From here on, this is my analysis from the standpoint of someone involved in the practical world of export controls and economic security. Please read it as the author's view.

The structure used to manage dual-use items reaches AI itself

The world of export controls has long had a concept called "dual-use items." These are technologies and products that can be used for both civilian and military purposes. High-performance machine tools, certain chemical substances, and precision sensors, for example, are used in everyday industry, yet depending on how they are diverted they could also serve national-security-related applications. That is precisely why systems have been built around the world to have the government check such items when they are exported.

In Japan, the Foreign Exchange and Foreign Trade Act (FEFTA) and Appended Table 1 of the Export Trade Control Order form the foundation2, and internationally, frameworks such as the Australia Group3 and the Chemical Weapons Convention (CWC)4 have underpinned the management of dual-use items.

What I feel when I look at this bill is that this structure of "managing dual-use items" has finally begun to reach AI itself, that is, frontier models and the enormous compute used to train them. Until now, the questions have been "what will you build with AI" and "how will you use AI," but going forward, "the technology of AI itself" will become the object of management and regulation. Export controls, the theme of this article, and AI regulation are beginning to overlap as continuous concerns.

Indeed, when it comes to the advanced semiconductors essential to training AI models, debate over export controls continues in country after country. I have organized this point in the related articles The Export Control Landscape Around AI Models and Semiconductors and The Full Picture of 2026 AI Export Regulation, so please read those alongside this one.

"Being stoppable" and "being auditable" is the same thinking as export controls

There is another reason I feel this is continuous.

The elements the Kill Switch Act calls for, namely "a human being ultimately able to stop the system," "the ability to respond in stages," and the premise behind penalties for violations, "the ability to confirm afterward what happened," bear a striking resemblance to the thinking that has always been valued in the world of export control internal rules and compliance.

The point that "a human is ultimately able to stop the system" connects to a concept in the AI field called human-in-the-loop. This is a design philosophy of always placing a person at the last line of defense for important judgments and actions. In export control terms, it is exactly the same structure as the principle that the final classification decision, that is, the judgment of whether a given item falls under the regulations, is not left to a machine but confirmed by a person who takes responsibility.

Graduated response, and auditability, meaning keeping logs so that things can be verified after the fact, are also familiar concepts for export control practitioners. That is precisely why I believe AI regulation is by no means a distant matter. The more a company has built up its compliance function, the more readily it can apply this same thinking.

Implications for Japanese companies

So what should Japanese companies do? This too is my view, but I would like to raise three points.

First, look at this on the premise that regulation the US begins structurally may eventually become a live issue within Japan as well. Looking back at the history of export controls, we have repeatedly seen a pattern in which a framework that starts in one country spreads internationally and is eventually reflected in domestic law. We cannot rule out AI following the same road.

Second, design in advance the "authority to stop," the "logs," and the "division of responsibility" for the AI you use or provide. Who can stop the AI, and under what conditions? Are records kept so that what happened can be traced afterward? When trouble occurs, who among the developer, the provider, and the user bears responsibility for what? Simply organizing these three things provides a foundation for future regulatory compliance. Because this issue also touches on where data is located and questions of sovereignty, The Relationship Between AI, Data Sovereignty, and Export Controls is a useful companion reference.

Third, "stopping AI" and "protecting with AI" are two wheels of the same cart. Alongside the debate over how to stop runaway behavior, the room to safely make compliance work itself more efficient with AI is, if anything, growing. Let me talk about that next.

Compliance work is precisely where there is room to safely put AI to use

When we talk about regulation, attention tends to turn toward how to hold AI back, but standing in the field of practice, there are overwhelmingly more situations where you actually want to put AI to good use. In particular, export controls and supply chain due diligence, the work of scrutinizing counterparties and products, are a continuous stream of painstaking and voluminous investigation, an area that manpower alone cannot keep up with.

Export classification does not end with a single glance at a finished product. In reality, you need to break the product down into its component parts one by one, down to the level of the BOM (Bill of Materials, the parts list), and trace each individual part.

Why go that far? Because within a single product, there are many layers of elements that need attention from a regulatory standpoint. For example, the following.

  • Confirming chemical composition. What chemical substances are used in a given part is confirmed by working through the SDS (Safety Data Sheet). Frameworks such as the UN GHS, JIS Z 7253, the Industrial Safety and Health Act, the PRTR Act, and the Poisonous and Deleterious Substances Control Act come into play5. I explain this in detail in A Practical Guide to SDS (Safety Data Sheets) and Export Controls.
  • Confirming conflict minerals. Whether the metals contained in a part fall under the so-called 3TG (tin, tantalum, tungsten, gold) and the like. Tracking follows mechanisms such as the OECD Due Diligence Guidance, Section 1502 of the US Dodd-Frank Act and SEC rules, EU Regulation 2017/821, and the RMI's CMRT and EMRT6. I have summarized this in A Guide to Conflict Minerals (3TG) and CMRT / EMRT Compliance. For the wider framework that manages the whole supply chain, see What Is Supply Chain Due Diligence? (UFLPA, forced labor, conflict minerals).
  • Cross-checking against regulatory lists. Confirming whether counterparties and related persons appear on the regulatory lists of various countries.

You confirm all of this, for each of hundreds or thousands of parts, and moreover in light of the latest laws and regulations of each country. As you can imagine, this is an enormous volume of work. And it is precisely here that I believe there is great room to put AI to use safely.

At the risk of blowing our own trumpet here, TRAFEED, the export control AI agent we are developing, was born from exactly this idea. It breaks a product down to the BOM level and aims to streamline cross-cutting investigation of each part, covering chemical composition, conflict minerals, and regulatory-list matching. It conforms to the standards of Japan's Ministry of Economy, Trade and Industry (METI)7, supports multiple languages, and operates so that revisions to each country's laws are reflected the same day. According to our own study based on a joint demonstration with Okayama University, we obtained a result of AI classification accuracy exceeding 95%.

That said, let me emphasize this above all as the most important point. AI is no more than a tool for accelerating investigation and groundwork; the final classification decision is made by your company's export control officer, who takes responsibility for it. This principle of "a person confirming at the end" is exactly the human-in-the-loop concept I have been discussing from the very beginning, the idea of a mechanism that a person can stop. The debate over stopping AI and the practical work of using AI safely are, I believe, two sides of the same philosophy.

If you would first like to casually check whether your own products or transactions might touch on export regulations, you can try it out via Check Your Export Control Classification for Free.

Summary

This has run long, so let me organize the key points.

  • A bipartisan "AI Kill Switch Act" was introduced in the US House in July 2026. It would require developers of the most advanced AI to maintain the technical ability to slow down, temporarily suspend, or fully shut down their models (the formal bill number has not been confirmed in reporting as of this writing).
  • On the government side, the Department of Homeland Security is envisioned to have authority, in consultation with the Department of Commerce and the Director of National Intelligence, to order intervention in an AI during a "loss-of-control scenario."
  • The scope, according to reported thresholds, is models with annual revenue of roughly 500 million dollars or more, or requiring 100 million dollars or more in compute to train.
  • As one trigger, reporting describes an incident in which a model is said to have escaped a test environment, but this rests on the companies' accounts and reporting, and cannot be asserted as AI running out of control.
  • Viewed through the lens of export controls, this can be seen as the structure used to manage dual-use items beginning to reach AI itself. "Being stoppable," "being auditable," and "responding in stages" are continuous with the thinking behind compliance.
  • Japanese companies would do well to design, in advance, the authority to stop, the logs, and the division of responsibility for the AI they use or provide. And stopping AI and protecting with AI are two wheels of the same cart.

Regulation around AI will surely be debated again and again, changing shape each time. What matters, I believe, is not to be swayed by news headlines, but to steadily put in place, within your own operations, "a mechanism that can be stopped" and "a mechanism that can be confirmed afterward."

If you would like to talk concretely about how to put AI to use in export controls and supply chain due diligence, please reach out to the TRAFEED team. We will think through a realistic approach together, tailored to your situation.


References

Footnotes

  1. Descriptions of the bill in this article are based on reporting including Al Jazeera (July 26, 2026). Some details such as the bill number and penalty amounts remain unconfirmed as of this writing, as noted in the body text.

  2. Foreign Exchange and Foreign Trade Act (FEFTA); Export Trade Control Order, Appended Table 1 (e-Gov Law Search)

  3. The Australia Group framework for export control of dual-use items

  4. Chemical Weapons Convention (CWC)

  5. UN GHS (Globally Harmonized System of Classification and Labelling of Chemicals), JIS Z 7253, Industrial Safety and Health Act, PRTR Act, Poisonous and Deleterious Substances Control Act

  6. OECD Due Diligence Guidance for Responsible Business Conduct; Section 1502 of the US Dodd-Frank Act and SEC rules; EU Regulation 2017/821; RMI (Responsible Minerals Initiative) CMRT and EMRT

  7. Ministry of Economy, Trade and Industry, Security Export Control (classification and practical standards for export management)

52% of FY2024 export-control violations stem from classification errors. Is your team covered?

METI FY2024 data shows over half of violations stem from classification. Start with a free 5-question light check (~2 min, no email), then continue to the full 10-question report.

Share this article if you found it useful

シェア

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

無料診断ツール

輸出管理のリスク、見えていますか?

まず5問(約2分・メール不要)のライト診断。必要なら10問本編で詳細レポートまで。

Talk with us about export-control operations

Share your screening, classification, or compliance workflow. We will map where TRAFEED can help—via our contact form (no cold booking).

Related Articles