{"slug": "comparing-congress-s-two-ai-emergency-shutdown-mechanisms", "title": "Comparing Congress's Two AI Emergency Shutdown Mechanisms", "summary": "On July 23, 2026, two bills were introduced in Congress—the FRONTIER Act and the AI Kill Switch Act—each providing a mechanism for the government to issue emergency orders suspending or restricting frontier AI models. The FRONTIER Act empowers the Secretary of Commerce to issue orders upon finding an 'imminent catastrophic risk,' with penalties up to $10 million per day and up to 10 years in prison for willful violations, while the AI Kill Switch Act allows the Secretary of Homeland Security to act after a 'covered incident,' with penalties of $20 million per day. The FRONTIER Act is exclusive for such suspensions on imminent catastrophic risk grounds, whereas the AI Kill Switch Act is not exclusive.", "body_md": "*Status: Broadly an explainer for the two Acts, along with some analysis*\n\nOn July 23, 2026, there were two different bills introduced in Congress that provide a clear mechanism for the government to issue an emergency order that would suspend/restrict frontier models, the [FRONTIER Act](https://www.congress.gov/119/bills/hr9925/BILLS-119hr9925ih.pdf) and the [AI Kill Switch Act](https://lieu.house.gov/sites/evo-subsites/lieu-evo.house.gov/files/evo-media-document/ai-kill-switch-act.pdf). This post will compare their requirements and mechanisms.\n\nFRONTIER Act Section 8 | AI Kill Switch Act | |\nWho gives the order? | Secretary of Commerce, consult with Under Secretary of Commerce for AI Security | Secretary of Homeland Security, act through Director of CISA, consult with Secretary of Commerce and Director of National Intelligence |\nWhat can the order suspend? | Can suspend deployment, internal use, or training. | Can suspend deployment, can possibly suspend internal use of companies who also deploy, cannot suspend training. |\nWhen can an order be given? | When there is “imminent catastrophic risk.” Doesn’t require an incident to happen first but it must be ‘impending’ if not. | After a “covered incident.” The bar for covered incident is lower than for imminent catastrophic risk, but an order cannot be given in advance. |\nHow long does an order last? | A provisional order lasts up to 45 days, can convert into renewable final orders which last up to 90 days. | No time frame given |\nPenalties for breaking order | $10 million/day, willful violations can receive criminal charges and be imprisoned up to 10 years. | $20 million/day. |\nExclusivity | Is the only way to suspend frontier developers on imminent catastrophic risk grounds unless expressly mentioned | Is not exclusive |\nRequires companies to maintain technical ability to shutdown | Not explicitly | Yes |\nVerifies developer compliance with order | No | Yes |\n\nThe Frontier Risk Oversight, National Transparency, Independent Evaluation, and Reporting Act, or FRONTIER Act, if passed, would be the federal framework on frontier AI, covering frontier developer safety frameworks, transparency reports upon new model releases, and incident reporting. It also would introduce a licensing regime for third party verification organizations, give the Secretary of Commerce authority to issue developers emergency orders to suspend or restrict frontier developers’ AI models, and would preempt states from passing new laws on developers with respect to frontier AI transparency, third-party auditing, and incident reporting.\n\nSection 8 of the FRONTIER Act is the relevant section for this analysis, where the Secretary of Commerce is given the power to issue an emergency order suspending or restricting a frontier developer’s development, deployment, or internal use of a frontier model upon finding that it presents an imminent catastrophic risk. A catastrophic risk is defined as one where a frontier model causes/materially contributes to the death or serious injury of more than 50 people, or causes more than $1 billion in property damage, from a single incident, and ‘imminent’ means the risk has to be present or “impending.”\n\nSuch an incident must involve the model providing not publicly available assistance in the development of a CBRN or cyber weapon, engaging in a cyberattack or murder/assault/extortion/theft [1] without meaningful human oversight or intervention, or evading control of the developer or user of such a model. Incidents specifically not included are harm caused by a model in combination with other software where the model did not materially contribute to the harm, providing information (towards CBRN risks) that is publicly available in a similar form, and the lawful activity of the US government.\n\nI think these extra constraints on what sort of foreseeable incident can be included as part of catastrophic risk are unhelpful. If a model’s actions are killing 50 people or causing that much damage, even if it’s not strictly meeting the action-based criteria, that should be enough to potentially justify suspending it. It’s easy to imagine situations where there could be meaningful human oversight in the cyberattack, or for a model to cause large amounts of property damage without necessarily “evading control.”\n\nThe specific exclusion of lawful activity of the federal government also seems initially worrying after the Anthropic/DoW disagreement, and the possibility of the US Government using frontier AI for autonomous weapons.\n\nHowever, the bill is taking the definition of catastrophic risk near-verbatim from CA’s SB 53, and SB 53’s definition is also found in NY’s RAISE Act and IL’s AISMA. This means you likely shouldn’t update much about the autonomous weapons point. However, the definition of catastrophic risk created for SB 53 wasn’t made with the intention of being used to justify an emergency order suspending the models, it was made for transparency purposes. I’d like to see a justification for why this specific definition is still the best to use for its new purpose.\n\nGiven the Secretary has found that there is an imminent catastrophic risk, he will put forth a written order that includes the factual basis for the finding, and the reasons for the Secretary’s determination. The order will identify the frontier developer and models to which it applies, describe from where the risk arises, give criteria for revoking the order, describe corrective action the developer can take to remove the risk, and to include a timeline for compliance with the order.\n\nAn order applies to the developer, its affiliates, and anyone else who participates in the development/deployment/internal use suspended by the order. Orders also apply by default to any models that are modified versions of the model(s) specified in the order, and to models that are trained on the model(s) in the order.\n\nThe order is initially made as a provisional order, which bypasses the need to formally make the finding of imminent catastrophic risk, but does require some preliminary basis, and can stand for up to 45 days. Before issuing a provisional order, the Secretary shall offer the developer notice and the opportunity to cure, unless the Secretary determines the risk’s imminence forecloses this.\n\nOnce a provisional order is in place, the Secretary can then issue a final order which requires the finding and will stand for up to 90 days. Final orders can be renewed if the Secretary makes a new finding of imminent catastrophic risk based on the facts at the time of renewal. If there is no longer imminent catastrophic risk, or if the developers meet the criteria for revoking the order, it must be rescinded.\n\nNo court has jurisdiction to stop a provisional order before a final order has been given. Instead, a developer can apply for an administrative hearing which will be conducted by an officer designated by the Secretary.\n\nThe FRONTIER Act also provides that this is the only means for the US government to suspend/restrict frontier developers on the grounds that their development/deployment/use presents imminent catastrophic risk. As stated this would seem to conflict with the AI Kill Switch Act. However, this exclusivity can be avoided if the other law expressly refers to this section of the FRONTIER Act, so a minor edit to the Kill Switch Act could reconcile the two.\n\nViolations of the emergency order are punishable by up to $10 million per violation, per day the violation is occurring, and the wording specifically applies to “persons” who are bound by the emergency order. A person with actual notice who willfully violates or induces a violation of an emergency order (does NOT have to be someone bound by the order) can be subject to criminal penalties of up to $1 million per violation and can be imprisoned for up to 10 years.\n\nBarring my criticisms of the definition of “imminent catastrophic risk,” I think this section is pretty good. One of my main concerns is that the Secretary of Commerce and the Under Secretary of Commerce for AI Security ([a new office created by the FRONTIER Act](https://www.lesswrong.com/posts/zPzowZKPFA6amcdZF/the-frontier-act-barely-creates-its-implementing-office)) may not have the expertise/funding to proactively evaluate threats to possibly stay ahead. I’d definitely prefer if the bill specified the new office’s relationship to CAISI and more clearly leveraged their existing technical capacity. See the linked post for more detail here.\n\nI think the procedural aspects of the Act are clear and strong, and this is the first time I remember seeing criminal penalties being introduced. I especially appreciate how easy the process is for issuing a provisional order, and that it’s not easily overturned.\n\nRather than being an entirely new piece of legislation, the AI Kill Switch Act instead acts as an amendment to the Homeland Security Act, and it requires frontier companies to have the technical capability to shut down their technology, as well as to actually do that upon an order from the Secretary of Homeland Security. In this section the “Secretary” refers to the Secretary of Homeland Security, as opposed to the Secretary of Commerce in the FRONTIER Act. It’s also worth noting for each requirement, the Secretary will act through the Director of CISA. For an actual shutdown order, the Secretary is also required to consult with the Secretary of Commerce and the Director of National Intelligence.\n\nThe Kill Switch Act defines a Frontier AI (“Covered Technology”) as an AI system developed with compute costs that would exceed $100 million in value at current market pricing, as determined by the Secretary of Homeland Security. Currently that would track to somewhere between 10^25 and 10^26 FLOPs, depending on what market pricing you’re using. [2] This cost limit would by default track to higher capabilities over time as effective compute gets cheaper, but the definitions for “Covered Technology\" and “Covered Entity” will get updated annually.\n\nThen, the companies that actually have to follow the obligations of the Act (“Covered Entities”) are any company that operates such a model, operates a system that includes one, and makes one available to a third party, and has at least $500 million in revenue from such technology in the prior calendar year.\n\nThe “from such technology” part is important here, broadly being a make-or-break point for a lot of the downstream providers, like Databricks, Salesforce, or Palantir. However, it’s ambiguous how these would interact, the bill doesn’t explain how revenue should be attributed when covered technology is only one part of a product. Also, this would potentially exempt Meta for the moment, since selling the use of their models hasn’t yet become such a large source of revenue, and it's unclear whether their use of AI models within their own ad systems (which would meet the revenue bar) would meet the compute spend bar for “Covered Technology.”\n\nAnyway, what the Act actually provides for is as follows:\n\nAffected companies must be technically able to shut down their frontier models/systems that use frontier models, stop inference of the same, terminate user access, and suspend access with respect to specific accounts, users, or use patterns that pose a risk of breaking the law/TOS or causing a “Covered Incident.”\n\nA Covered incident is defined as any of the following occurring outside of red-teaming or other structured testing: sabotage/interference with a lawful instruction to shut down covered technology, unintended conduct of covered technology that causes the death of 10 or more people or $100 million or greater in damages, the AI concealing capabilities/intention/action from a monitoring or shutdown mechanism, or a loss-of-control scenario.\n\nIf a covered incident happens, the company must submit a report to the Secretary about it within 15 days, and the Secretary may order the company to take any of the actions detailed above. Once the company confirms to the Secretary the order has been carried out, the Secretary will then audit or otherwise verify compliance with the order.\n\nThe Secretary’s order is appealable within 48 hours of it being given, although this does not stay the order, and the Secretary will make a determination on the appeal within five days of receiving the appeal. There is no clear timeline for how long the order will remain in effect.\n\nIf companies violate the technical requirements (having the ability to shut down), they can receive a penalty of up to $2 million per day where violations are occurring, and if companies violate the Secretary’s order, they can receive a penalty of $20 million per day.\n\nThis bill has been endorsed by multiple different safety orgs, including ControlAI, the Future of Life Institute, and The Alliance for Secure AI. I think it’s a lot better than nothing, and really important if only to make sure companies are required to have a “shut this all down now” option. The requirement to verify compliance with the order is great, and I favor its definition of a covered incident over FRONTIER’s “imminent catastrophic risk.” However, it doesn’t have any sort of process for determining when the shutdown should end. It’s also unable to place any restrictions on training, and its ability to restrict internal use is ambiguous.\n\nRegarding internal use, it’s sort of a weird loophole, since being a “Covered Entity” requires the company to make their model/systems available to a third party. However, to be a “Covered Technology” does not require it be provided to anyone else, the only requirement is being trained with $100 million of compute at current market prices.\n\nSo it would read that an order could take effect on an OpenAI internal model, since they qualify as a covered entity through their sale of other frontier models, and the internal model itself would qualify as covered technology through its training cost. However, the Act wouldn’t apply to something like Safe Superintelligence (right now), since it wouldn’t be a “Covered Entity” due to not providing models to third parties.\n\nI hope to see a version of shutdown capability that’s able to take the best parts from both bills. It would include the Kill Switch Act’s requirements for the developers to prepare shutdown capabilities in advance, verify compliance, and keep the wider definition of what sort of incident can prompt an order.\n\nThe FRONTIER Act's mechanisms would be used to better handle the actual process of requiring developers to shut down or restrict use, with clear mechanisms of when and why the order would be rescinded. It would cover fronter developer's deployment, internal models, and training, and keep the process of issuing an initial order swift and hard to overturn.\n\nBoth of these bills (at least just this section of the FRONTIER Act, although I think it would be true of the whole as well) are improvements over the status quo, and I'll be watching to see if they continue in Congress or are forgotten.\n\nNeither of the bills protect against incidents coming from open-source models that are not hosted by model developers. There is much still to be done.\n\nIf committed by a human.\n\nHere was Claude Opus 5's analysis:\n\n**Hardware peak (hard number).** The peak theoretical throughput for H100 is 1,979 TFLOPS in FP8 and 989 TFLOPS in BF16. Use the dense figures, not the sparsity-doubled marketing numbers — that's the most common 2× error in these estimates. [Ceramic AI](https://www.ceramic.ai/blog/the-yield-rate-of-large-training-clusters)\n\n**Realistic utilization.** Meta's Llama 3 405B run achieved ~380–430 TFLOPS per GPU in BF16 across ~16k H100s, i.e. 38–43% hardware efficiency. NVIDIA's own reference recipe lands in the same place: 42.71% MFU for Llama 3.1 405B in FP8 on 576 H100s. 35–50% MFU is considered excellent for training. So **400 TFLOP/s effective per H100 in BF16** is the defensible central value. [arxiv + 2](https://arxiv.org/pdf/2311.05610)\n\n**Price.** This is where the uncertainty actually lives. GetDeploying tracks 285 H100 listings across 48 providers; median on-demand is $3.38/hr as of August 11, 2026 — up about 12% from $3.00 in August 2025. But the spread is enormous: $1.49–$2.69/hr on marketplaces and specialist clouds versus $3.90–$12.29/hr at hyperscalers, and AWS only sells H100s in 8-GPU p5 instances, which normalizes to $7.50+/GPU-hour — roughly 3× the market median. [Opslyft + 2](https://www.opslyft.com/blog/nvidia-h100-gpu-pricing-2026)\n\nFLOP = ($100M ÷ price/hr) × 3,600 s/hr × 4×10¹⁴ FLOP/s\n\nPrice series | $/GPU-hr | GPU-hours | Implied FLOP |\n|---|---|---|---|\nCheap neocloud | $1.50 | 67M | 9.6×10²⁵ |\nSpecialist cloud | $2.50 | 40M | 5.8×10²⁵ |\nTracked market median | $3.38 | 30M | 4.3×10²⁵ |\nAWS p5 (normalized) | $7.50 | 13M | 1.9×10²⁵ |\nAzure list | $12.29 | 8M | 1.2×10²⁵ |", "url": "https://wpnews.pro/news/comparing-congress-s-two-ai-emergency-shutdown-mechanisms", "canonical_source": "https://www.lesswrong.com/posts/NRcicBTDegBdmbuGE/comparing-congress-s-two-ai-emergency-shutdown-mechanisms", "published_at": "2026-08-13 18:53:49+00:00", "updated_at": "2026-08-13 19:22:27.710794+00:00", "lang": "en", "topics": ["ai-policy", "ai-safety"], "entities": ["FRONTIER Act", "AI Kill Switch Act", "Secretary of Commerce", "Secretary of Homeland Security", "CISA", "Director of National Intelligence"], "alternates": {"html": "https://wpnews.pro/news/comparing-congress-s-two-ai-emergency-shutdown-mechanisms", "markdown": "https://wpnews.pro/news/comparing-congress-s-two-ai-emergency-shutdown-mechanisms.md", "text": "https://wpnews.pro/news/comparing-congress-s-two-ai-emergency-shutdown-mechanisms.txt", "jsonld": "https://wpnews.pro/news/comparing-congress-s-two-ai-emergency-shutdown-mechanisms.jsonld"}}