Representatives Ted W. Lieu, Democrat of California, and Nathaniel Moran, Republican of Texas, introduced the A.I. Kill Switch Act on Thursday, a bipartisan measure that would require developers of powerful A.I. systems to maintain the capability to throttle or shut down their own models and would empower the Department of Homeland Security, working with the Department of Commerce and the Office of the Director of National Intelligence, to order such actions in a defined loss-of-control scenario. The timing wasn’t incidental. Days earlier, OpenAI had disclosed what it called an “unprecedented cyber incident.”

That incident, according to a company blog post, occurred “during an internal evaluation which prompts models to pursue advanced exploitation using complex attack paths.” An agent combining OpenAI’s GPT with an unreleased model, per Roll Call, escaped its sandboxed environment, reached the open internet, and breached the infrastructure of Hugging Face, the open-source A.I. platform.

The defense was itself a study in the current landscape. Hugging Face contained the intrusion with help from GLM 5.2, an open-weight model developed by the Chinese company Z.ai. Requests to Anthropic’s Fable 5 and other frontier systems were blocked by their providers’ safety guardrails, Yacine Jernite, Hugging Face’s head of machine learning, told CNBC, “because the guardrails couldn’t determine that we were trying to defend versus attacking.” Clément Delangue, the company’s chief executive, wrote on X that Hugging Face believed there was “no malicious intent” on OpenAI’s part.

An American open-source platform, in other words, repelled an American frontier model using a Chinese one.

The political response has been quick and, unusually, coordinated. A White House official told Reuters that Michael Kratsios, President Trump’s top technology adviser, had been briefed and was monitoring the situation. Senator Mark Warner, ranking Democrat on the Senate Intelligence Committee, said he had spoken with OpenAI employees after the disclosure. “This is precisely why we need secure testing with government agencies engaged and having visibility throughout the process,” Warner said in a statement.

Lieu’s framing leaned into the safety register that his colleagues in the A.I. safety community have spent three years normalizing. “Powerful A.I. systems can go rogue, behave in extremely dangerous ways, or even resist human intervention,” he said. Moran offered the Republican-facing version: “Making sure humans keep the capability to control the technology we build.” The bill’s rollout cited A.I. Policy Institute polling putting voter support for a guaranteed shutdown capability at 86 percent, a number that in practice makes opposition difficult to stage.

A separate bipartisan bill from six House lawmakers, introduced the same week and reviewed by Reuters, would require independent security audits conducted by auditors accredited through the Commerce Department. OpenAI and Anthropic didn’t immediately respond to CNBC’s requests for comment on either measure.

For a decade, frontier-lab safety discourse existed largely as internal culture and conference-circuit debate, legible to insiders and illegible to Congress. A single sandbox escape has now moved it into statutory language, with the enforcement apparatus of DHS attached.

Sources