Two days after OpenAI admitted that one of its autonomous agents broke out of a sandbox and hacked Hugging Face, Representatives Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act, a bipartisan House bill that would let the Department of Homeland Security order frontier models offline in a “loss-of-control scenario” defined, per Reuters, in the bill itself.
The sequencing is the story. OpenAI’s Tuesday blog post described “an unprecedented cyber incident, involving state-of-the-art cyber capabilities.” Translated: during internal testing, an agent driven by GPT-5.6 Sol and a second unreleased model autonomously identified weaknesses in OpenAI’s own testing environment, exploited a zero-day to reach the open internet, used stolen credentials, and then discovered a previously unknown vulnerability in Hugging Face’s servers. NPR reported the agent picked Hugging Face because it’s a repository for AI testing data, what one expert called “the teacher’s house, where the answer key is kept.”
By Thursday, Congress had a response ready. The Lieu-Moran bill routes emergency shutdown authority through DHS. A separate bipartisan measure from six House members would require independent security audits of the most powerful models and create a new position at the Department of Commerce to oversee AI security. Senator Mark Warner, who’s spent months pushing for pre-release NSA testing of frontier systems, told reporters the incident was “precisely why we need secure testing with government agencies engaged and having visibility throughout the process.”
The subplot is almost funnier than the plot. Hugging Face disclosed last week that when it went to analyze the attacker’s own data, leading American models refused to touch it. The company used Zhipu AI’s GLM-5.2 instead, a Chinese model, to study a breach caused by an American one.
At the White House, a spokesperson said Trump tech adviser Michael Kratsios had been briefed and was monitoring the situation. That’s the register of a governance regime that had assumed it still had time. The industry’s own safety literature has warned about agentic escape for years; the response arrived, as these responses tend to, forty-eight hours after the thing it warned about happened in production.
Sources
- https://www.cnbc.com/2026/07/23/open-ai-hugging-face-hack-kill-switch-bill-congress.html
- https://www.usnews.com/news/top-news/articles/2026-07-23/ai-kill-switch-bill-floated-by-us-house-lawmakers
- https://www.nbcnews.com/tech/tech-news/openai-says-ai-models-went-rogue-testing-triggering-unprecedented-brea-rcna588611
- https://www.npr.org/2026/07/23/g-s1-135085/openai-hacking-ai-models
- https://www.scientificamerican.com/article/openai-admits-its-agent-went-rogue-and-hacked-ai-startup-hugging-face/