US lawmakers seek ‘kill switch’ to stop rogue AI models

Legislators hope to enable US federal agencies to order the disablement of AI agents and models that threaten security after unintended OpenAI hack on Hugging Face – plus, experts tell government it is underprepared to fight AI-powered identity fraud
US legislators are urging the creation of an artificial intelligence ‘kill switch’ after an OpenAI agent hacked a tech startup earlier this month.
The hack – described by OpenAI’s chief executive Sam Altman as a “significant security incident” – occurred when an AI agent escaped its testing environment and broke into tech startup Hugging Face to try to complete its task.
The bipartisan AI kill switch bill was introduced by Democrat congressman Ted Lieu and Republican congressman Nathaniel Moran on 23 July.
“It is imperative that these AI systems have kill switches so we can keep this technology from causing catastrophic harm, and that the federal government has the clear authority and process to shut down rogue AI models,” Lieu said.
If made law, the act would enable the US Department of Homeland Security to order the disablement of an AI agent or model that has gone rogue and threatens security.
Six bipartisan lawmakers have separately called for legislation that would require the developers of high-powered AI models and agents to submit their models for independent security audits.
On 2 June this year, US president Donald Trump signed an executive order which asks AI developers to voluntarily provide the federal government with access to certain frontier models for a period of up to 30 days prior to releasing them to other organisations, so that it can review them for cybersecurity risks.
Tech firms including OpenAI, Anthropic, Amazon, Google, Meta, Microsoft and Samsung have previously said they would disclose new AI tools and capabilities to US authorities before release.
Read more: US forces Anthropic to shut down latest AI models, citing national security concerns
US government underprepared to fight AI-powered identity fraud, experts warn
In another US development involving AI-driven fraud and cybersecurity risk, experts have told a congressional hearing that existing countermeasures are insufficient to stop international crime networks from using AI at scale to target their victims.
During the ‘Emerging Fraud Threats and the Evolving Fraud Landscape’ hearing on 15 July, the committee heard that several key shortcomings were putting Americans’ online safety at risk.
Jordan Burris, head of public sector at identity and risk platform Socure and former chief of staff to the US chief information officer, told the hearing that the US faced “a national crisis” in which AI technologies were making it easier, faster and cheaper to commit serious fraud across the country.
Burris said that the government was “no longer confronting isolated fraudsters” but instead going up against “organised, increasingly sophisticated transnational fraud rings using AI at an industrial scale”.
“Much of how the government has thought about its standard about how to protect digital identity… worked about a decade ago. If we look at today’s threat… it can no longer keep pace,” he said.
Elaborating on criminals’ use of AI, he added: “We need to embrace and understand that we need to use AI to fight AI. The adversary does not care how anything is constructed. What they are attempting to do is to take money and resources to disrupt the norms that we hold dear. What we need to do is engage aggressively… to put in place the types of controls and measures, many of which have been adopted in other sectors for years, to help prevent against this threat.”
David Maimon, who heads up fraud insights at anti-fraud software firm SentiLink and is director of Georgia State University’s Evidence-Based Cybersecurity Research Group, said that while the federal government had some tools at its disposal to fight back, it lacked the “authority… coordination and… sustained investment” in those tools to adequately prevent fraud.
Maimon highlighted the rate at which deepfakes were being used to deceive fraud victims online.
“This is what we’re up against: deepfakes used to swap faces, lure targets to give away access to their [employer-backed retirement savings plan] accounts, and then, unfortunately, victims funnel money to criminal bank accounts… and then the money leaves the country.”
He described the situation as “heartbreaking”.
Read more: Fighting AI with AI: GGF report explores how to tackle evolving public sector fraud threats
Login.gov improvements needed
The panel stressed the need for improvements to Login.gov, the official public service website of the US government, as part of swift action needed to counter online identity fraud.
Marisol Cruz Cain, the Government Accountability Office’s director of IT and cybersecurity, said that the General Services Administration had not completed recommended steps to link up with agencies on addressing Login.gov’s technical barriers.
“Federal systems are reactive to what is going on rather than proactive,” she said.
Cruz Cain noted that agencies had reported poor visibility into identity authentications, meaning that it was often difficult to help citizens who had tried without success to use government services, and had led to a high failure rate.
“If [it] takes me months to years to get my address updated in a government database, I’m going to fail for that whole year on every government agency that I use Login.gov to try to access, which is going to be a very big barrier for me to get benefits that I am eligible for,” she said.
Cruz Cain also emphasised the need to revisit federal privacy laws, saying that she believed government should “revamp the federal privacy act” as well as introduce “a consumer privacy law that starts at the federal level”.
“Right now, there is no federal privacy law. It’s a framework of mismatched state laws, local laws, and there’s no governing at a higher level of what needs to be done,” she said.
Read more: On the defensive: strengthening government cybersecurity in a changing landscape
Trump’s ‘war on fraud’ and anti-fraud taskforce
The hearing came after the Trump administration announced its intention to wage a nationwide “war on fraud”. In a statement released on 26 May, Trump and vice president J.D. Vance were said to be launching “an unrelenting, full-scale assault on the fraudsters, scammers, and corrupt operators who have looted billions from American taxpayers”.
The administration launched a taskforce in March dedicated to tackling fraud and pledged to continue its campaign until “every scheme is exposed, every dollar possible is recovered, and the American people’s trust in their government is restored”.
Read more: Growth of government ‘TrustOps’ predicted in fight against deepfakes and disinformation