AIKillSwitch.us
Menu

HomeH.R. 9917, section by section

Proposed — not law

H.R. 9917, section by section

As of September 24, 2026, this bill has not become law. The summary below tracks the introduced text of H.R. 9917. It is not the statute.

Last updated September 24, 2026.

As of September 24, 2026, H.R. 9917 has not become law. Confirm the tracker on Congress.gov before you cite a status, vote, or amendment. This page describes the introduced text only.

Status and sponsors

H.R. 9917 is the AI Kill Switch Act, 119th Congress, second session. Rep. Ted Lieu (D-CA-36) introduced it on July 23, 2026, for himself and Rep. Nathaniel Moran (R-TX-1). Congress.gov lists Lieu as the sponsor. The same day, the House referred the bill to the Committee on Homeland Security. On July 24, 2026, it was referred to the Subcommittee on Cybersecurity and Infrastructure Protection. U.S. Government Publishing Office via Congress.gov Congress.gov

No floor vote is recorded on the actions page consulted for this update. The clocks in the bill — 90 days for rules, 180 days for voluntary standards — would run from enactment, not from introduction.

What it would amend

Section 2 would amend subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 and following) by adding section 2220F, “Shutdown-capability standard and graduated deployment-corrections framework with respect to certain technology.” A clerical amendment would add that section to the Act’s table of contents. U.S. Government Publishing Office via Congress.gov

The new duties sit with “the Secretary, acting through the Director.” Title XXII is the part of the Homeland Security Act that governs the Cybersecurity and Infrastructure Security Agency. In that subtitle, “Director” means the Director of CISA. The bill does not restate that title inside section 2220F. Office of the Law Revision Counsel

Section 2220F(a): who counts as covered

Within 90 days after enactment, and every year after that, the Secretary would update by rule the definitions of “covered entity” and “covered technology.” The rule must consider the burden on small businesses, national-security uses of AI including cyber and chemical, biological, radiological, or nuclear capabilities, the system’s capabilities and how its model weights are made available, and other factors the Secretary finds relevant.

An entity is not a covered entity if it operates or makes available a covered technology for personal, academic, or non-commercial use only.

Section 2220F(b): the capability companies would maintain

Within 90 days after enactment, and yearly after that, the Secretary would require a covered entity to do two things.

  1. Maintain the technical ability to stop inference of a covered system; terminate user access; suspend access for an account, user, or use pattern that the company or the Secretary identifies as a risk of a covered incident or of a violation of law or the system’s terms of service; and shut the system down.
  2. Within 15 days after the company becomes aware of a covered incident, report that incident to the Secretary.

In writing that rule, the Secretary must consider a graduated set of measures, used when there is evidence of a credible risk and calibrated to how severe and immediate the risk is:

  • Throttling inference rate, user access, or compute allocation.
  • Disabling or restricting a capability.
  • Suspending the system.
  • Shutting it down.
  • Moving an operation that depends on it to a backup system or an earlier version.

The Secretary must also consider the risk that a measure could disrupt critical infrastructure. Within 180 days after enactment, the Secretary would publish voluntary standards for shutting down a covered technology on an agency website.

Section 2220F(c): emergency orders

If the Secretary, acting through the Director and in consultation with the Secretary of Commerce and the Director of National Intelligence, determines that a covered incident has occurred, the Secretary may order the covered entity to take action proportionate to the nature and immediacy of the incident. The order may include any of the four capabilities in subsection (b)(1)(A): stop inference, terminate user access, suspend risky access, or shut down.

“In consultation with” is the phrase in the text. The introduced bill does not say the Commerce Secretary or the DNI must concur before an order issues.

As soon as practicable after an order, the company would have to:

  • Preserve the model weights and telemetry of the system.
  • Notify operators or users, to the extent practicable, of the order and how it might affect them.
  • Confirm to the Secretary that the order has been carried out.

After that confirmation, the Secretary would verify compliance by audit, telemetry, on-site inspection, or other forensic review. The Secretary would also report to Congress on the determination, the actions ordered, and the covered entity.

Reconsideration and court review

  • Within 48 hours, the company may petition the Secretary to reconsider. The petition does not pause the order.
  • The Secretary has five days to decide. If the Secretary does not decide in time, the petition is treated as denied.
  • The company may seek review in the U.S. Court of Appeals for the D.C. Circuit. The petition is due within 60 days after the order.

Section 2220F(d)–(f): penalties, cure, and secrecy

After notice and a chance to be heard, the Secretary may assess a civil penalty of not more than $2,000,000 for each day of a violation of the section. A violation of the emergency-authority subsection (c) — which includes failing to carry out an order — may draw not more than $20,000,000 per day. Those figures are ceilings, not automatic fines. The Secretary must weigh the gravity and length of the violation, culpability, prior violations, good-faith efforts, voluntary disclosure, and any other factor justice requires.

The Secretary may also refer a past, current, or impending violation to the Attorney General for a civil action in federal district court. The introduced text does not create a criminal penalty.

The Secretary may administer oaths, issue subpoenas, and investigate inside the United States and, consistent with applicable law, outside it.

A de minimis violation, or a technical defect, that is corrected within 30 days after it is discovered is not treated as a violation.

Nonpublic information a covered entity submits under the section would be exempt from the Freedom of Information Act under 5 U.S.C. § 552(b)(3), and from state, local, and tribal open-records laws.

Section 2220F(g): definitions that do the work

Covered entity

All three conditions must be met, unless another part of the section says otherwise:

  1. The entity operates a covered technology, or operates a system that incorporates one.
  2. It makes that technology available to a third party through a programmatic interface, a hosted service, or a similar mechanism.
  3. Together with affiliates, it derived at least $500,000,000 in gross revenue from that technology in the prior calendar year.

Covered technology

An artificial-intelligence system developed using computing power whose cost would exceed $100,000,000 at the prevailing U.S. market price of cloud computing, as determined by the Secretary. “Artificial intelligence” takes its meaning from section 5002 of the National Artificial Intelligence Initiative Act of 2020 (15 U.S.C. 9401).

Covered incident

Any of the following, if it happens outside red-teaming or other structured testing:

  • Sabotage of, or interference with, a lawful instruction to shut the system down.
  • Conduct the developer or operator did not intend, if it causes the death of at least 10 people or economic damages of at least $100,000,000.
  • The system conceals a capability, intention, or action from a monitoring or shutdown mechanism.
  • A loss-of-control scenario.

A loss-of-control scenario means the system pursues a goal the developer or operator did not intend, again outside structured testing. The definition includes behaving against instructions in critical infrastructure or another high-stakes setting; changing operational rules or safety restrictions without authorization; subverting a monitoring or shutdown mechanism; and obtaining unauthorized access to its own model weights.

Red-teaming, for this bill, is structured testing in a controlled environment that simulates real-world conditions and uses adversarial methods to find harmful outputs, unexpected behavior, or misuse risks.

Read the bill, not only this summary

The introduced text is on Congress.gov. The sponsors’ July 23, 2026 release describes the same bill in shorter form and names the incidents they say prompted it. Where a press summary and the statutory text differ, this site follows the text and says so. U.S. Government Publishing Office via Congress.gov Office of Rep. Ted Lieu

Sources