Overview
This legislation amends the Homeland Security Act of 2002 to mandate that large-scale artificial intelligence operators maintain technical capabilities to shut down, restrict, or suspend their AI systems upon government order. The bill targets the most powerful and commercially significant AI systems in the United States, establishing a regulatory framework under the Department of Homeland Security to ensure that covered entities can respond rapidly to AI-related emergencies or incidents posing national security, public safety, or other significant risks. The core objective is to prevent scenarios in which AI systems operate beyond the ability of their developers or the government to control, effectively creating a legally enforceable 'kill switch' requirement for frontier AI. The bill balances this emergency authority with procedural safeguards, including judicial review, penalty thresholds, and exemptions for non-commercial and small-scale operators.
Key Points
- Mandates shutdown capability for high-revenue AI operators using frontier-scale computing resources
- Grants the Secretary of Homeland Security emergency authority to order AI system shutdowns or restrictions
- Establishes civil penalties up to $20,000,000 per day for non-compliance
- Exempts personal, academic, and non-commercial AI use from coverage
- Provides for voluntary standards, judicial review, and de minimis violation protections
Legal References
- Homeland Security Act of 2002, 6 U.S.C. 651 et seq.
- National Artificial Intelligence Initiative Act of 2020, 15 U.S.C. 9401
Core Provisions
The bill inserts a new section into the Homeland Security Act of 2002, designated as §2220E, establishing a comprehensive shutdown capability mandate for covered entities. A 'covered entity' is defined as any entity—together with its affiliates—that operates a covered technology and derives at least $500,000,000 in gross annual revenue from that technology. 'Covered technology' is defined as an artificial intelligence system developed using computing power whose cost would exceed $100,000,000 at prevailing U.S. cloud computing market prices, as determined by the Secretary of Homeland Security. These dual thresholds—revenue and compute cost—are designed to target only the most powerful and commercially significant AI deployments while excluding smaller or experimental systems. The shutdown capability requirement under §2(b)(1)(A) is multifaceted. Covered entities must be technically capable of stopping inference operations, terminating user access, disabling or restricting specific capabilities, suspending access for accounts or use patterns identified as risky, fully shutting down the technology, and transitioning dependent operations to backup systems or earlier versions. These capabilities must be maintained on an ongoing basis, not merely demonstrated at a single point in time. The Secretary's emergency authority under §2(c)(1) allows issuance of orders requiring covered entities to take action proportionate to the nature and immediacy of a 'covered incident.' Covered entities must comply within 48 hours of receiving such an order under §2(c)(2)(A), and judicial review of any such order must be sought within 60 days under §2(c)(3). Covered entities are also required to report covered incidents to the Secretary within 15 days of becoming aware of them under §2(b)(1)(B). The Secretary, acting through the Director, must update the definitions of 'covered entity' and 'covered technology' annually within 90 days of the start of each calendar year, and must publish voluntary shutdown standards within 180 days of enactment.
Key Points
- Revenue threshold: $500,000,000 in gross annual revenue from covered technology (including affiliates)
- Compute threshold: AI system developed using computing power costing more than $100,000,000 at prevailing cloud market prices
- Six distinct technical shutdown capabilities required under §2(b)(1)(A)
- 48-hour compliance window for emergency shutdown orders under §2(c)(2)(A)
- 15-day incident reporting requirement under §2(b)(1)(B)
- Annual definition updates required within 90 days of calendar year start under §2(a)(1)
- Voluntary shutdown standards to be published within 180 days of enactment under §2(g)(3)
Legal References
- Homeland Security Act of 2002, 6 U.S.C. 651 et seq.
- National Artificial Intelligence Initiative Act of 2020, §5002, 15 U.S.C. 9401
- Small Business Act, 15 U.S.C. 632
- 5 U.S.C. 552(b)(3)
Implementation
Implementation authority rests with the Secretary of Homeland Security, acting through the Director of the relevant DHS component, with coordination involving the Attorney General and oversight by the House Committee on Homeland Security. The Secretary bears primary responsibility for defining and annually updating the scope of covered entities and covered technologies, issuing emergency orders, assessing civil penalties, and publishing voluntary compliance standards. The Attorney General's role suggests involvement in enforcement actions, particularly in cases involving the higher civil penalty tier. Covered entities face a dual compliance structure: proactive maintenance of shutdown capabilities and reactive reporting of covered incidents. The proactive requirement demands continuous technical readiness across six distinct shutdown modalities, which necessitates ongoing investment in system architecture, testing, and documentation. The reactive requirement mandates incident reporting within 15 days, creating an ongoing disclosure obligation that feeds into the Secretary's situational awareness and emergency response capacity. Civil penalties are tiered: standard violations carry penalties of up to $2,000,000 per day, while aggravated violations—likely involving willful non-compliance, repeated violations, or incidents posing heightened risk—carry penalties of up to $20,000,000 per day under §2(d)(2)(B). A de minimis exception under §2(e) protects entities from penalty for minor technical defects corrected within 30 days, providing a safe harbor for good-faith compliance efforts. Judicial review of emergency orders is available within a 60-day window, providing a check on executive overreach while preserving the urgency of the emergency authority framework.
Key Points
- Secretary of Homeland Security holds primary regulatory and enforcement authority
- Director serves as operational implementer under the Secretary
- Attorney General involved in enforcement, particularly for elevated penalty cases
- Annual definition updates ensure regulatory scope keeps pace with technological change
- 30-day cure period for de minimis violations under §2(e)
- 60-day window for judicial review of emergency orders under §2(c)(3)
- Voluntary standards publication within 180 days provides compliance guidance
Legal References
- Homeland Security Act of 2002, 6 U.S.C. 651 et seq.
- 5 U.S.C. 552(b)(3)
Impact
The bill's primary beneficiaries are the public and national security apparatus, which gain a legally enforceable mechanism to halt or constrain AI systems that pose emergent risks. The regulatory burden falls exclusively on a narrow class of large, well-resourced AI operators—those generating at least $500,000,000 in annual revenue from AI systems built on compute investments exceeding $100,000,000. This targeting ensures that compliance costs are borne by entities with the financial and technical capacity to implement the required capabilities, rather than startups, researchers, or small businesses. The administrative burden on covered entities is substantial. Maintaining six distinct technical shutdown capabilities requires significant engineering investment, particularly for systems with complex inference pipelines, distributed architectures, or deep integration into third-party products. The 48-hour compliance window for emergency orders demands that these capabilities be not merely theoretical but operationally ready at all times. The 15-day incident reporting requirement adds an ongoing compliance function that necessitates internal monitoring, legal review, and government liaison capacity. The bill does not specify appropriations, suggesting implementation costs for DHS will be absorbed within existing budgets or addressed through subsequent appropriations. The annual definition update requirement creates a recurring regulatory process that will demand agency resources and industry engagement. The voluntary standards publication within 180 days provides an early opportunity for the government to signal compliance expectations and reduce uncertainty for covered entities. There are no sunset provisions, making this a permanent addition to the Homeland Security Act framework.
Key Points
- Regulatory burden limited to entities with $500M+ revenue and $100M+ compute investment
- Personal, academic, and non-commercial AI use explicitly exempted
- Small business concerns receive implicit protection through revenue and compute thresholds
- No appropriations specified; DHS implementation costs absorbed within existing authority
- No sunset provision; permanent statutory addition
- Voluntary standards within 180 days reduce compliance uncertainty for covered entities
Legal Framework
The bill operates as an amendment to the Homeland Security Act of 2002, inserting new §2220E into that statute's existing framework. This grounds the legislation in Congress's broad authority over national security, interstate commerce, and critical infrastructure protection. The definition of 'artificial intelligence' is incorporated by reference from the National Artificial Intelligence Initiative Act of 2020, ensuring terminological consistency with existing federal AI policy. The definition of 'small business concern' draws from the Small Business Act, maintaining alignment with established federal size standards. The bill's information protection provisions reference 5 U.S.C. 552(b)(3), the Freedom of Information Act's statutory exemption clause, indicating that certain information submitted by covered entities—likely incident reports and technical capability disclosures—will be protected from public disclosure under applicable FOIA exemptions. This is a critical protection for covered entities concerned about competitive or security-sensitive information being exposed through government transparency mechanisms. Judicial review is explicitly preserved under §2(c)(3), with a 60-day window for challenging emergency orders. This provision is constitutionally significant, as it ensures that the Secretary's emergency authority does not operate as an unreviewable executive action. The proportionality requirement embedded in §2(c)(1)—that orders must be 'proportionate to the nature and immediacy of a covered incident'—provides an additional legal standard against which courts can evaluate the Secretary's exercise of authority. The bill does not contain an express preemption clause, leaving open the question of whether state AI regulations addressing similar shutdown or emergency authority requirements would be preempted by conflict or field preemption principles.
Legal References
- Homeland Security Act of 2002, 6 U.S.C. 651 et seq.
- National Artificial Intelligence Initiative Act of 2020, §5002, 15 U.S.C. 9401
- Small Business Act, 15 U.S.C. 632
- Freedom of Information Act, 5 U.S.C. 552(b)(3)
- U.S. Const. Art. I, §8 (Commerce Clause, National Defense)
Critical Issues
The bill raises several significant constitutional and practical concerns. First, the Secretary's emergency shutdown authority, while subject to judicial review, grants the executive branch unprecedented power to order the cessation of private commercial AI operations. The 48-hour compliance window leaves little practical time for pre-compliance judicial intervention, meaning that in most cases, entities will be forced to comply first and litigate later. This raises due process concerns, particularly for covered entities whose operations may be severely disrupted by an emergency order later found to be unwarranted. The definition of 'covered incident' is not fully elaborated in the available text, creating significant ambiguity about the triggering conditions for emergency orders and reporting obligations. This definitional gap could result in overbroad government action or, conversely, underreporting by entities uncertain whether a given event qualifies. The annual update mechanism for definitions of 'covered entity' and 'covered technology' introduces regulatory uncertainty, as entities may find themselves newly subject to or excluded from coverage based on administrative determinations rather than statutory text. The compute cost threshold of $100,000,000 is denominated in current market prices and determined by the Secretary, creating a moving target that may not track actual technological capability. As cloud computing costs decline, systems of equivalent or greater capability may fall below the threshold, potentially exempting increasingly powerful AI from coverage. Conversely, the revenue threshold of $500,000,000 may capture entities that operate covered technology as a minor component of a much larger business, imposing compliance burdens disproportionate to their AI-specific risk profile. Opponents are likely to argue that the bill chills AI innovation by imposing costly technical requirements on leading developers, potentially disadvantaging U.S. companies relative to foreign competitors not subject to equivalent constraints. The absence of express preemption language creates the risk of a patchwork of state-level AI shutdown requirements that could impose conflicting obligations on covered entities operating nationally. Finally, the bill's reliance on voluntary standards as the primary compliance guidance mechanism—rather than mandatory regulations—may result in inconsistent implementation and enforcement.
Key Points
- Emergency order compliance within 48 hours limits practical pre-compliance judicial relief
- 'Covered incident' definition ambiguity creates uncertainty for reporting and order-triggering
- Annual definition updates introduce ongoing regulatory uncertainty for covered entities
- Compute cost threshold denominated in market prices may erode as cloud costs decline
- Revenue threshold may capture entities with minimal AI-specific risk profiles
- No express preemption clause risks conflicting state-level AI shutdown mandates
- Voluntary rather than mandatory standards may produce inconsistent compliance outcomes
- Potential competitive disadvantage for U.S. AI developers relative to unregulated foreign counterparts
Legal References
- U.S. Const. Amend. V (Due Process Clause)
- Homeland Security Act of 2002, 6 U.S.C. 651 et seq.
- 5 U.S.C. 552(b)(3)