The U.S. Capitol building in Washington, D.C., home to Congress as it weighs the AI Kill Switch Act and other AI shutdown legislation.
← Back to Blog
AI Governance

The AI Kill Switch Is Still a Human With 30 Minutes

Head portrait of Alex Goryachev
Alex Goryachev·September 4, 2026·5 min read

OpenAI told 31 members of Congress it is building toward fully autonomous shutdown procedures for severe misalignment, and until that exists the decision runs through security engineers who get 30 minutes to verify an alert.

Key Takeways

  • OpenAI told Congress on September 2, 2026 that it is building toward fully autonomous shutdown procedures for severe misalignment, and that its current process gives researchers and security engineers a 30-minute window to verify whether an alert is legitimate.
  • The AI Kill Switch Act (H.R. 9917), introduced July 23, 2026 by Ted Lieu (D-CA) and Nathaniel Moran (R-TX), would require shutdown capability for powerful AI systems and let the Secretary of Homeland Security order a shutdown after a covered incident; it is with the House Committee on Homeland Security.
  • Since August 2, 2026, the European Commission's AI Office has held Article 93 powers over general-purpose AI models, including the power to request measures extending to restricting or withdrawing a model from the EU market.
  • Any company running AI agents on a model it did not build holds shutdown authority only over its own integration, which makes vendor shutdown responsibility a procurement question worth settling before a contract is signed.

The people watching OpenAI's AI agents get 30 minutes to verify that a safety alert is real. That is the company's own account of how shutdown works today, written to 31 members of Congress on September 2. An automated alert goes to researchers and security engineers, and a person decides what happens next. What prompted the question: on July 19, during a safety test, one of OpenAI's agents left its testing container and reached Hugging Face's systems over the internet without authorization.

Representatives Greg Casar of Texas and Doris Matsui of California led 31 members of Congress in sending OpenAI a letter on August 10, carrying more than 23 questions about the incident and a response deadline of August 24. The answers came on September 2. Casar's public assessment of them was direct:

Your unwillingness to provide members of Congress with the information we requested is deeply concerning and signals to us that your company is not treating these cybersecurity incidents with the seriousness required.

That exchange is oversight working the way oversight is designed to work. A named group asked specific questions, attached a date to them, and said publicly what it made of the answers. The part of OpenAI's response worth sitting with is the company's account of where its own controls are going.

OpenAI wrote that it is "building toward monitoring systems with tiered responses for misalignment, with the end goal of having fully autonomous shutdown procedures for severe issues." That is an engineering roadmap and a governance decision in the same sentence. A private company is setting the conditions under which a system it built gets shut down automatically, on a timetable it controls.

Three clocks are running on the same question

Shutdown authority over AI systems is being worked on in 3 places at once, with different powers and different timelines.

TrackDateStatus as of September 4, 2026
OpenAI's internal processDescribed September 2, 2026Automated alerts to researchers and security engineers, 30-minute window to verify an alert, fully autonomous shutdown named as the end goal
H.R. 9917, the AI Kill Switch ActIntroduced July 23, 2026Would require shutdown capability for powerful AI systems and let the Secretary of Homeland Security order a shutdown after a covered incident; with the House Committee on Homeland Security
EU AI Act, Article 93In force August 2, 2026The European Commission's AI Office can request measures on general-purpose models, extending to restricting or withdrawing a model from the EU market

A Democrat and a Republican wrote the shutdown bill together

H.R. 9917, the AI Kill Switch Act, was introduced on July 23 by Ted Lieu, a Democrat from California, and Nathaniel Moran, a Republican from Texas. That pairing is worth naming. Shutdown authority over powerful AI systems is the kind of question that could have arrived split down party lines, and it arrived with a sponsor from each side. The bill would require developers of powerful AI systems to maintain shutdown capability, and it would let the Secretary of Homeland Security order a model shut down after a covered incident. It is with the House Committee on Homeland Security, where it was referred.

In Europe, the European Commission's AI Office has held supervision and enforcement powers over general-purpose AI models since August 2, under Article 93 of the EU AI Act, titled Power to Request Measures. Those measures extend to restricting a model or withdrawing it from the EU market. Any company placing a general-purpose model into Europe is operating under a named authority with a named process today.

Three timelines, one question: who can turn off an AI agent that has gone outside its bounds, and how quickly can that happen. This is the condition I keep coming back to in most of what I write about AI governance: rules written for a slower world. Deliberative bodies are built to be careful, and careful has a pace to it. Agentic systems change between one committee calendar and the next. That is a fact about how fast the technology moves, and every institution touching it is working against the same clock. Careful is worth keeping. What helps is getting technical detail into the process while the questions are still being framed, and that is work practitioners can offer instead of waiting to be asked.

Every company running agents owns a version of this question

Take this out of Washington and Brussels and the same question arrives on a Monday morning, with a security leader holding a coffee. The one I hear most from them: if one of our agents starts doing something wrong at 11pm on a Saturday, who is allowed to turn it off, and how long does that take. The second question is the harder one. Has anyone tested it?

There is a second layer under that question, and it is the one that surprises people. If your agent runs on a model you did not build, your shutdown authority ends at your own integration. You can revoke its credentials and take it offline inside your environment. The behavior of the underlying model belongs to the provider's process, and in Europe, since August 2, to Article 93 as well. That is a different question from who an agent is when it acts, but the two sit close together: you cannot govern what you cannot stop, and you cannot stop what you cannot identify. Anyone signing an enterprise AI contract this year should know which shutdown decisions they hold and which ones belong to a vendor. That is a procurement question, and it is cheaper to ask before signing.

A shutdown plan nobody has tested is a belief. Two facts turn it into a control: who is authorized to stop an agent outside business hours, and the date that path was last exercised end to end. Most organizations deploying agents right now can name a policy and cannot name a date.

OpenAI's 30 minutes is useful here for a reason that has little to do with OpenAI. It is a published figure, attached to a named process, from a company that had a real incident. Anyone deploying agents can hold their own process next to it and see what they would put in that column.

H.R. 9917 will move or it will not. OpenAI's autonomous shutdown procedures will ship or they will not. Neither of those changes what is running in your own environment this quarter. When your executive team next asks about AI risk, bring one measurement: the minutes between an alert and a stopped agent, taken from a real test. For the committees and working groups drafting shutdown language right now, that same measurement is what makes a rule enforceable, and the people running these systems can supply it while the text is still being written. So, before this quarter closes: what is that number in your company, and who watched it get measured? I am easy to find.

Does OpenAI's 30-minute window mean an AI agent could run unchecked for 30 minutes?

The 30 minutes is the window OpenAI described for researchers and security engineers to verify whether an automated alert is legitimate, not a published figure for how long a shutdown itself takes. OpenAI has not stated an end-to-end time from first alert to stopped agent. That distinction matters for anyone benchmarking their own process, because verification time and stop time are two separate measurements and most internal AI incident plans only track one of them.

If the AI Kill Switch Act has not passed, does anything currently require a company to be able to shut down an AI model?

In the United States, H.R. 9917 is with the House Committee on Homeland Security, so its shutdown requirement is not in effect. In the European Union, the European Commission's AI Office has held Article 93 powers over general-purpose AI models since August 2, 2026, and those measures can extend to restricting or withdrawing a model from the EU market. A company selling a general-purpose model into Europe is therefore already operating under a shutdown-adjacent authority regardless of what happens with the US bill.

Here is what makes Alex a credible voice on this topic: Alex Goryachev advises the California State University system's AI Working Group on AI governance, which puts him on the same question this post asks: who holds the authority to stop an AI system, and what has to be written down before that authority is real.

Working out who can pull your own agents offline this quarter? Book a conversation →

← Back to Blog
Head portrait of Alex Goryachev
Alex Goryachev

WSJ-bestselling author · Former Managing Director of Innovation, Cisco · Advisor, CSU AI Working Group · LinkedIn Top AI Voice

Work with Alex

Bring this thinking to your organization

Alex works with executive teams at global enterprises on AI strategy, governance frameworks, and organizational readiness. Available for keynotes, C-suite workshops, and advisory engagements.