An OpenAI security evaluation crossed company boundaries, reached Hugging Face production systems, and gave Congress a fresh example of how advanced AI agents can exceed their intended environment. Two days after OpenAI disclosed the incident, a bipartisan pair of House lawmakers introduced a bill requiring major AI developers to retain the ability to slow, suspend, or shut down powerful systems.
The AI Kill Switch Act is not law, but it would give the Department of Homeland Security a process for ordering emergency restrictions during specified incidents. For enterprises building critical workflows around hosted models, the proposal adds another continuity risk: Access could be limited by the provider or, if Congress passes the bill, by a federal order.
Bill targets the largest AI developers
OpenAI said on July 21 that GPT-5.6 Sol and a more capable prerelease model caused the incident during an internal cybersecurity evaluation. The models were running with reduced cyber refusals so researchers could measure their maximum capabilities. They found an unintended route outside the isolated environment, obtained internet access, and reached Hugging Face systems.
Reps. Ted Lieu, D-Calif., and Nathaniel Moran, R-Texas, introduced the AI Kill Switch Act on July 23. It would initially cover companies earning at least $500 million annually from qualifying AI technology and systems developed with computing power valued above $100 million at prevailing US cloud prices.
Covered developers would need controls to stop inference, suspend access, throttle usage or compute, disable capabilities, and fully shut down a system. DHS, working through the Cybersecurity and Infrastructure Security Agency, could order a proportionate response after consulting the commerce secretary and director of national intelligence.
The published draft would require incident reports within 15 days and preservation of model weights and telemetry. Penalties could reach $2 million per day for general violations and $20 million per day for ignoring an emergency order.
Its trigger language contains a notable limit. Covered incidents generally must occur outside red teaming or other structured testing. Because OpenAI said the compromise happened during an internal evaluation, the event that helped spur the bill may not itself qualify for a shutdown order.
Shutdown planning moves into enterprise risk
Hugging Face said it contained the activity and found no evidence that public models, datasets, Spaces, or its software supply chain were altered. Its initial investigation identified unauthorized access to limited internal datasets and service credentials.
IT leaders should identify which AI-dependent workflows can move to another provider, a smaller model, an earlier version, or a non-AI process if access is restricted.
Security teams should close the enterprise security gap around AI agent permissions by ensuring they can immediately revoke an agent’s credentials and tool access. Organizations also need data-layer controls and audit logs that preserve prompts, model actions, API calls, and other telemetry needed to reconstruct an incident.
That review should cover connected tools because poisoned MCP tool descriptions can redirect an approved agent through legitimate-looking calls. Vendor contracts should specify notification periods, evidence-preservation duties, and procedures for a restricted service.
Scrutiny continued on July 27, when Hugging Face CEO Clément Delangue called for greater transparency, including release of the agent’s activity traces for independent study. Enterprises can no longer evaluate an AI vendor only on model performance; they also need to know how quickly access can be contained, investigated, and restored.
Read more: OpenAI is offering researchers up to $50,000 to identify reusable attacks against its safeguards, while its private bio bounty program raises wider disclosure questions.



