The AI Kill Switch Act is repeating the Clipper Chip’s mistakes
“Anything that can go wrong will go wrong.”
Policymakers alarmed by the recent incidents of autonomous AI agents breaking through guardrails to hack other companies seem to have Murphy’s Law on the mind – and who can blame them? When agents’ behavior becomes unpredictable, it’s easy to imagine any number of scenarios where they’re running amok.
To address this amorphous and evolving risk, Reps. Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) have proposed the AI Kill Switch Act, which would give the Cybersecurity and Infrastructure Security Agency (CISA) the power to order frontier AI labs to install the ability to throttle, suspend, or shut down their systems if needed.
Unfortunately, fixing this problem won’t be that simple. These so-called “kill switches” are just Congress’s latest attempt to push through the same fix Washington reaches for every time it panics about a new technology: a backdoor. For all intents and purposes, a backdoor is a deliberately engineered vulnerability, one that malicious actors want to exploit, and one well-intentioned defenders will have to fight to protect. And just as Murphy’s Law predicts, defenders will lose that fight more often than not, especially if Congress sets off a proverbial flare by declaring all American-made agents must be shipped weak-by-design.
The clearest example is the Clipper Chip, developed by the National Security Agency (NSA) in 1993 to encrypt voice and data communications while giving the government guaranteed access to devices through a built-in “Law Enforcement Access Field.” Despite repeated assurances about its security, researchers found a serious flaw in 1994 that let unauthorized parties exploit that same backdoor.
Of course, this analogy has its limits. The Clipper Chip compromised confidentiality by enabling unauthorized, third-party access to encrypted messages on telecommunications equipment like phones and modems. The AI Kill Switch Act instead undermines the availability of AI systems, requiring frontier labs maintain the ability to force them offline at any time. It’s the same flawed approach behind the Chip Security Act, which I critiqued here, and which is now gaining traction to be included in this year’s National Defense Authorization Act. Where that bill mandates a kill switch for the semiconductors themselves, the AI Kill Switch Act targets the agents running on them. Regardless, the issue is the same: policymakers are trying to solve one security concern by purposefully creating another, building a point of failure into technologies we depend on.
Passage of either bill would undermine America’s digital infrastructure resilience at a critical moment. As AI agents become embedded in essential systems like banking, e-commerce, power grids and water systems, these bills would effectively require frontier labs to build kill switches into the infrastructure that the entire U.S. economy depends on. This creates an obvious problem: Why deliberately weaken the very systems that need to be extremely secure?
The proposal would undercut the broader push for U.S. leadership in AI infrastructure. What foreign government will want to run American AI agents knowing frontier labs are required to keep a remote kill switch at the ready? This would also reinforce European fears that the U.S. government could shut down American technology at will. Europe is already responding by developing technology alternatives and other policy solutions to reduce reliance on U.S. companies.
If all this isn’t disqualifying enough, there are many other reasons to reject AI Kill Switch Act. It gives CISA far too much discretion to decide what counts as frontier AI risk and its use of company revenue and computing power as a measure of risk is a poor proxy for how dangerous a rogue agent actually is. Not to mention, the bill’s draft language exempts incidents that happen during “red-teaming or other structured testing,” which means it excludes the exact scenarios that prompted lawmakers to address this issue in the first place.
Instead of mandating controls that could introduce new systemic vulnerabilities into our digital infrastructure, policymakers must work to create nuanced, well-thought-out measures that actually reduce risk. That work starts with a clear understanding of the technology. Yet, we’re still not there: the Center for AI Standards and Innovation (CAISI) still hasn’t finished developing AI agent security standards. Once that foundation is in place, Congress should turn to more productive approaches like mandatory red-teaming, stronger security requirements, and clear liability frameworks, all of which would do far more to reduce real-world risk without creating new systemic vulnerabilities.
Washington learned this lesson with the Clipper Chip; it shouldn’t have to learn it again. You don’t secure a system by building a way to break into it. Congress must kill the AI Kill Switch Act.