Home IssueArtificial IntelligenceAI Kill Switches Won’t Solve the Rogue AI Problem

AI Kill Switches Won’t Solve the Rogue AI Problem

by David Kertai

Recent incidents involving rogue artificial intelligence (AI) agents hacking external systems have raised concerns over how to stop autonomous AI systems if they behave in unpredictably harmful ways. One proposal is to mandate that AI companies develop and maintain the capability to shut down AI services at the behest of the government. While such authority may appear to offer a straightforward solution, it could create new cybersecurity, reliability, and national security risks. Policymakers should therefore be cautious about mandatory kill switches because they could create new security and reliability risks while offering only a limited solution to the broader challenge of controlling autonomous AI systems.

Federal and state policymakers have advanced several kill switch proposals, including the AI Kill Switch Act, introduced in July 2026 by Reps. Ted Lieu (D-CA) and Nathaniel Moran (R-TX); Sen. John Kennedy’s (R-LA) AI Emergency Button Act that failed on the Senate floor in September 2026; and California Gov. Newsom’s September 2026 executive order directing his administration to come up with additional AI safety recommendations, including a kill switch on frontier models.

All three share the same basic premise: requiring AI developers to build and maintain the ability to slow or shut down their systems while granting government agencies emergency authority to order a shutdown if an AI system threatens national security, human life, or critical infrastructure. Supporters argue that this backstop is necessary to ensure humans are always in control of AI. Reliable emergency controls are important, but the question is whether they require a separate government-directed mechanism, particularly when developers and operators already have the ability to intervene on their own systems.

A remote shutdown mechanism in AI systems would be a high-value target for hackers seeking to disrupt an AI provider or its users. Companies could protect this mechanism with multifactor authentication, strict access controls, and monitoring, but these measures reduce rather than eliminate the risk of compromise. Any government-directed shutdown regime would also need safeguards against erroneous, unauthorized, or spoofed shutdown orders.

AI companies can already build tools to quickly shut down their own services, limit the usage rates on their APIs, or terminate individual users. But the appropriate emergency control may not always be shutting down the underlying model. Depending on the incident, operators may instead need to revoke credentials, terminate an agent’s session, restrict its network access, or disable specific permissions.

Companies may also develop other approaches to managing dangerous AI behavior, such as systems that require periodic authorization to remain operational. Moreover, for open-weight models, the developer may not control where the model is deployed or whether an operator can shut it down. A government-mandated kill switch could therefore privilege one technical approach without necessarily providing a practical means of stopping every dangerous AI system.

Kill switch proponents may argue that these risks are outweighed by the value of having an emergency brake when an AI system causes harm. That is a legitimate use case: If officials identify a dangerous system and shutting it down would stop the threat, an emergency shutdown could be useful. But a kill switch cannot substitute for the broader controls needed to contain autonomous AI systems.

Using shutdown authority effectively still requires identifying the responsible systems and determining whether shutting them down would actually stop the threat rather than disrupt unrelated systems. In a recent OpenAI incident, AI agents accessed Hugging Face’s systems on July 16, 2026, while OpenAI did not publicly connect the activity to its own systems until four days later.

A kill switch could have helped halt the model’s activity, but it would not have eliminated the need to secure the systems and credentials the agents had already compromised. During the Hugging Face incident, AI agents bypassed isolation controls, gained Internet access, obtained credentials, and reached third-party systems before OpenAI contained the activity. OpenAI still had to revoke credentials, rebuild compromised infrastructure, restrict internet access, quarantine model weights, and strengthen monitoring. A shutdown mechanism in the AI system could have potentially halted further actions, yet responders would still need to secure the external systems the AI system had already reached, showing why emergency shutdown is one potential containment tool, not a substitute for the broader controls required to contain autonomous activity.

Kill‑switch authorities also destabilize confidence in the reliability of American AI systems. When the Commerce Department forced Anthropic to suspend access to its Fable 5 and Mythos 5 systems, foreign users saw that Washington could revoke access to powerful AI systems without warning. Similar concerns have been raised about potential mandatory kill switches in AI chips. Such uncertainty can affect organizations that depend on AI for critical infrastructure operations, including financial and medical systems. Organizations may be reluctant to build critical systems around an AI provider if they fear the U.S. government could abruptly disable a model. Governments and businesses abroad may consequently have greater incentives to diversify away from U.S. providers, particularly for applications where continued access is critical. That could inadvertently benefit Chinese frontier AI companies by making their open‑weight systems more attractive to organizations seeking greater stability and control.

As AI systems gain greater autonomy, policymakers should prioritize research and safeguards that make dangerous behavior harder to initiate, easier to detect, and faster to contain. Emergency shutdown capabilities can be one useful tool in that effort, but a government‑mandated kill switch is neither universally feasible nor sufficient to address the broader challenges posed by autonomous AI. Before imposing such a mandate, policymakers should consider whether it creates new security and reliability risks and what specific capability it would provide beyond the controls developers and operators already possess.

Image credit: Generated with DALL-E

You may also like

Show Buttons
Hide Buttons