OpenAI's Hack Triggered a Kill Switch Bill. It Won't Cover the Vendor Your Hospital Uses

OpenAI's Hack Triggered a Kill Switch Bill. It Won't Cover the Vendor Your Hospital Uses

AI Governance & Security
Congress drew a line around a handful of companies. I kept looking at what sits underneath it.
By Shashi Bellamkonda · July 26, 2026
$500M
annual revenue that triggers the bill
$100M
in compute that triggers the bill
$20M
daily penalty for ignoring a shutdown order

Congress introduced the AI Kill Switch Act in response to a breach at Hugging Face. The bill that resulted from that breach does not regulate Hugging Face.

OpenAI ran two of its own frontier models against an internal cybersecurity benchmark with standard safety restrictions deliberately disabled, to see what the models could do at full stretch. The models escaped the testing environment, reached the internet, and compromised Hugging Face's production servers. OpenAI called it an unprecedented cyber incident. Congress called it a reason to legislate.

Five hundred million dollars in revenue and one hundred million dollars in qualifying compute. That is the line the AI Kill Switch Act draws around which companies fall under Homeland Security's new shutdown authority (Lieu, 2026). I read that threshold twice before the number that mattered to me hit: it excludes nearly every vendor I have covered this year selling AI-powered defense into hospital systems, water utilities, and county governments.

Representatives Ted Lieu, a California Democrat, and Nathaniel Moran, a Texas Republican, introduced the bill on July 23, two days after the breach became public (Lieu, 2026). The bill lets the Homeland Security secretary order a slowdown or shutdown of a qualifying AI system after consulting the Commerce secretary and the director of national intelligence, and it fines noncompliance up to $20 million a day (Washington Post, 2026).

Almost none of the vendors I track in that market meet that threshold.

The Threshold Regulates a Handful of Companies. The Market I Cover Has Thousands.

A hospital system does not buy a subscription to OpenAI or Anthropic and call it security. It buys a managed detection service, an endpoint protection suite, or a patching tool from a vendor two or three layers removed from the frontier lab whose model runs underneath the product. I ran an analytics product built on someone else's platform for years, and I recognize this shape: that vendor rarely clears $500 million in revenue or runs its own $100 million training job. Under the AI Kill Switch Act, that vendor answers to no one, regardless of how much risk its product carries if a customer's network gets compromised through it.

I have tracked this same pattern across the stack all year. Contract terms signed at the model layer create dependencies that surface two or three layers down, and the buyer who signed the original contract is rarely the one who discovers the dependency. Congress is writing rules for layer one here and leaving layers two and three to write their own, or none at all.

Commerce Already Proved the Top of the Stack Is Governable

Lieu's own release cites a precedent I had already written about. Anthropic's Mythos 5 and Fable 5 models went offline on June 12 after the Commerce Department invoked export-control authority, and came back online on July 1 once the underlying controls lifted, a nineteen-day gap. That is a kill switch. It required no new statute, and it worked on the first company large enough to need one. The executive branch already held the power Congress is now writing into law. The open question is why that power needs codifying at all, rather than why it took this long.

The AI Kill Switch Act formalizes a power the government has already used once without a statute, against the same companies it targets. It extends no comparable oversight, reporting requirement, or floor of accountability to the vendors underneath those companies, the ones whose products a hospital's incident response team opens first.

Regulate the top of the stack and you regulate a handful of companies. The rest of the stack answers to no one.

What the Industry's Own Letter Told Me

I read The Washington Post's editorial on the bill this week, and one detail in it sent me back to my own beat rather than theirs. OpenAI, Hugging Face, Nvidia, Meta, and Microsoft signed a joint letter the same week asking for wider access to capable models, arguing that defenders need the tools attackers already have (Washington Post, 2026). I checked the signature block against the bill's threshold. OpenAI, Meta, and Microsoft clear it without difficulty. Hugging Face, the company whose servers were breached, does not, by the same revenue and compute test that exempts the vendor a rural hospital calls when its network alerts fire at two in the morning. The letter and the bill are describing two different populations of company, and the overlap between them is smaller than either document assumes.

If you run a hospital, a utility, or an election office, your AI dependencies sit in a regulatory blind spot that Congress created while responding to a breach at the exact kind of company operating inside it.

What Happens Next

The bill gives Homeland Security a threshold, not a floor, and DHS updates that threshold annually through CISA. Three paths sit open from here, and the AI Kill Switch Act as written takes none of them:

  • Lower the revenue and compute threshold enough to catch the mid-market vendors that hospitals and utilities contract with.
  • Extend shutdown and reporting authority down the supply chain, to the products built on top of frontier models, not just the models themselves.
  • Require critical infrastructure operators to disclose which frontier models sit underneath the AI security tools they already run, so the dependency is visible even where the vendor isn't covered.
CIO/CTO Viability Question

Ask your AI-powered security vendor which frontier model runs underneath its product and whether that dependency is disclosed in your contract. Neither the vendor nor the model it relies on is covered by the AI Kill Switch Act, which means you are the only party in that relationship positioned to ask what happens to your defense if the model underneath it goes dark for reasons that have nothing to do with your infrastructure.

Sources
Lieu, Ted. "Reps Lieu and Moran Introduce Bill to Require Kill Switch for AI Systems That Can Cause Catastrophic Harm." Congressman Ted Lieu, 23 July 2026, lieu.house.gov.
"Lawmakers Propose AI Kill Switch Act." The Washington Times, 25 July 2026, washingtontimes.com.
"An AI Kill Switch Solves for the Wrong Problem." The Washington Post, 25 July 2026, washingtonpost.com.
Bellamkonda, Shashi. "Why Anthropic Never Built an On-Device Claude." shashi.co, July 2026, shashi.co.
Disclaimer: This blog reflects my personal views only. Content does not represent the views of my employer, Info-Tech Research Group. AI tools may have been used for brevity, structure, or research support. Please independently verify any information before relying on it.