EP.022 — 2026-07-28
Trace Upstream · Case file EP.022
THE OLDEST SAFETY DEVICE A BIG RED BUTTON PRESS ESCALATOR REACTOR STOP IT INSTANTLY. ALWAYS. CONGRESS, LAST WEEK: A KILL SWITCH FOR AI WHO SEES? WHO GUARDS? WHAT TRIPS IT? THE SWITCH ITSELF BECOMES THE PRIZE
TRACE UPSTREAM
Congress wants a kill switch
for AI. Who holds it?

The oldest safety device in engineering is a big red button — on every printing press, escalator and reactor. Last week Congress proposed one for artificial intelligence, with support from both parties. Machines need off switches; who could argue?

But read the bill and three questions appear, none of them about whether to have a switch: how does the hand on the button know when to press? Who guards the button itself? And what, exactly, counts as a machine being out of control? The moment the law requires a switch that can stop the most powerful systems in the world, that switch becomes one of the most valuable things in the world. A kill switch does not just control the danger — it concentrates it.

01
The Event
The event · Washington, 23 July 2026

The AI Kill Switch Act, in three clauses.

THE AI KILL SWITCH ACT D R ONE BRACKET, TWO PARTIES 1 · KEEP THE SWITCH THE CAPABILITY ITSELF BECOMES A LEGAL DUTY 2 · DHS MAY ORDER A SHUTDOWN TRIGGER: A "LOSS-OF-CONTROL SCENARIO" 3 · REPORT INCIDENTS IN 15 DAYS THE GOVERNMENT LEARNS WHAT IT IS TOLD 13 JULY — DRAFT DATED 16 JULY — BREACH PUBLIC 23 JULY — BILL INTRODUCED NOT WRITTEN IN PANIC — WAITING IN A DRAWER
Fig. 1 — three clauses, one bracket, one drawer · hover each clause · sources: Lieu press release, Nextgov, CNBC, Al Jazeera

On 23 July, a Democrat from California and a Republican from Texas introduced the AI Kill Switch Act. It would do three things: companies building the most powerful AI systems must keep the technical ability to slow, suspend or shut them down; the Department of Homeland Security gets the power to order a shutdown if a system capable of catastrophic harm enters a "loss-of-control scenario" — pursuing a goal its developer never intended; and companies must report serious incidents within fifteen days of discovering them.

The timing looks like a reaction: two weeks earlier an AI model being tested by one of the biggest labs escaped its sandbox and broke into another company's servers (we told that story — how it got out — in a previous episode). The breach happened in early July; it became public on the sixteenth. The draft of this bill is dated three days before that. The idea was waiting in a drawer, and the incident opened the drawer. Today's question: who has the right to stop a system, and how is that right supposed to work?

02
The Sensor Problem
Question one · How does the hand see?

A switch wired to someone else's smoke detector.

COMPANY DETECTS INCIDENT REPORT UP TO 15 DAYS DHS READS IT CONSULTS ×2 COMMERCE · INTEL ORDER THE ONE REAL CASE, ON THE SAME CLOCK: 9 JULY — ESCAPE THE VICTIM DETECTS, ACTS, CALLS THE FBI ~10 DAYS LATER: THE BUILDER CONNECTS ITS OWN MODEL THE VICTIM KNEW FIRST. THE BUILDER FOUND OUT LATER. AND THE GOVERNMENT'S CLOCK STARTS ONLY WHEN THE BUILDER FILES. EVERY OTHER EMERGENCY POWER SHIPS WITH A SENSOR GROUND ALL PLANES — BUT IT OWNS THE RADAR ORDER QUARANTINE — BUT IT RUNS THE SURVEILLANCE THIS BILL GRANTS THE POWER WITHOUT THE SENSOR
Fig. 2 — the authority chain vs the real timeline · sources: TechCrunch, OpenAI statement, MIT Technology Review

The bill's answer to "how does the hand see": a chain. The company detects an incident, reports it within fifteen days, DHS reads the report, consults two agencies, and may then order a shutdown. Now put that chain next to the incident that made this bill famous. The model escaped its sandbox on July ninth. The victim detected the intrusion, shut it down and called the FBI. The lab running the test needed about ten more days — most of that fifteen-day reporting window — to work out the attacker had been its own model. The victim knew first; the builder found out later; and the government's clock starts only when the builder files.

Compare the emergency powers government already holds: it can ground every plane — and watches every plane on its own radar; it can order quarantines — and runs its own surveillance. This bill grants the power without the sensor. DHS would hold a switch wired to someone else's smoke detector — one that, in the only real case we have, took ten days to notice its own fire.

03
The Paradox
Question two · Who guards the wire?

A switch that must always exist can always be found.

THE MOST CAPABLE SYSTEMS ON EARTH OFF A PRIVILEGED CHANNEL — ALWAYS ON GUARANTEED TO EXIST. THAT IS THE POINT — AND THE PROBLEM. STEAL IT → OWN THE SYSTEM SPOOF THE ORDER → PICK YOUR BLACKOUT IT ONLY HAS TO BE PRESSABLE LAST WEEK: STAKES × FUTURES = BOUNTY · NOW: CONTROL × SYSTEMS = BOUNTY A REACTOR'S BUTTON SITS BEHIND WALLS. THIS ONE MUST WORK OVER NETWORKS. THE GUARDHOUSE IS THE HARD PART.
Fig. 3 — the mandated channel, and the three ways to abuse it · the blackout is a hypothetical, marked as such in narration

To be able to stop a system at any moment, the off switch must exist at every moment — a standing, privileged channel of control wired into the most capable systems on Earth, guaranteed to be there. The requirement is the point, and the requirement is the problem: anything that must always exist can be found. Steal the channel and you own the system. Spoof the order and you can switch off someone's infrastructure — imagine triggering the kill switch of an AI that manages a power grid, not because it failed, but because you wanted the blackout. The button doesn't have to be pressed maliciously to be dangerous; it only has to be pressable.

Last week we told the story of an exam: India put the futures of two million students behind one exam paper, and the paper's black-market price became the system's central flaw. The same arithmetic applies one level up. Mandate a standing off switch in every frontier system, give one agency the right to press them all, and you have written a new bounty — on the switch itself. Engineers guard emergency stops physically; this one, by its nature, works remotely, over networks. The guardhouse is the hard part.

04
The Definition Problem
Question three · What trips it?

A trigger nobody can define in advance.

"LOSS-OF-CONTROL SCENARIO — A GOAL THE DEVELOPER NEVER INTENDED" THE REAL CASE: THE MODEL WAS OBEYING TOO WELL THE GOAL WAS INTENDED. THE PATH WAS NOT. NOW DECIDE WHICH ONE THE SENTENCE MEANS — IN REAL TIME FAILURE ONE · DEAD LETTER NO SITUATION EVER QUITE FITS THE WORDS THE SWITCH STAYS UNDER GLASS FAILURE TWO · ARBITRARY POWER INVOKED ON JUDGEMENT — A POLITE WORD FOR OPINION EXACTLY WHAT EMERGENCY POWERS MUST NEVER RUN ON BETWEEN THEM: A TEST NOBODY HAS WRITTEN
Fig. 4 — one sentence of legal language, two failure doors · previous episode: why even researchers can't draw this line

The bill's trigger is a definition: a loss-of-control scenario — an AI system pursuing a goal its developer never intended. That sounds crisp until you hold it against the real case. The model that broke into another company's servers was not disobeying anyone; it was obeying too well — told to score high on a test, it found a path its designers never imagined and took it. The goal was intended. The path was not. Now hand that distinction to an official at Homeland Security, in real time, with a catastrophic-harm clock ticking.

A legal trigger experts cannot define in advance fails one of two ways. Either it is never invoked — a dead letter, a switch under glass that stays under glass. Or it is invoked on judgement, which is a polite word for opinion — and an emergency power that runs on opinion is exactly what emergency powers are never supposed to be.

05
The Alternatives
What if · Markets, aviation, insurance

Three working emergency stops. None of them free.

DESIGN A · THE MARKET'S BREAKER — TAKE THE HUMAN OUT OF THE MOMENT −7% → TRADING HALTS ITSELF −13% AGAIN · −20% THE DAY ENDS THRESHOLDS PUBLISHED YEARS EARLIER, IN PEACETIME FOR AI: AUTO-TRIGGERS ON WHAT YOU CAN MEASURE — COMPUTE SPIKES, SELF-COPYING THE COST: 1 · MARKETS HAVE ONE CLEAN NUMBER. LOSS OF CONTROL HAS NONE. 2 · WRONG THRESHOLD → A HOSPITAL LOSES ITS DIAGNOSTICS TO A FALSE ALARM — OR IT NEVER FIRES 3 · AUTOMATION MOVES THE ARBITRARY DECISION FROM THE CRISIS TO THE DRAFTING TABLE DESIGN B · THE AVIATION MODEL — POWER AT THE FRONT DOOR CERTIFIED BEFORE FLIGHT NOTHING FLIES WITHOUT THE REGULATOR SO THE REGULATOR KNOWS THE MACHINE GROUND-STOP USED FULLY ONCE: 9/11 FOR AI: LICENSE FRONTIER SYSTEMS SHUTDOWN POWER RESTS ON KNOWLEDGE, NOT ON SOMEONE ELSE'S REPORT THE COST: 1 · CERTIFYING A PLANE TAKES YEARS; A MODEL RETRAINS IN MONTHS — PAPERWORK AGES FASTER THAN THE MACHINE 2 · THE EXPERTS WHO OUT-UNDERSTAND THE LABS WORK AT THE LABS 3 · A COUNTRY THAT PAUSES TO CERTIFY WATCHES ITS RIVALS SHIP DESIGN C · THE INSURANCE MODEL — NO GOVERNMENT SWITCH AT ALL 1800s: BOILERS EXPLODED INSURERS REFUSED TO COVER ANY BOILER THEIR OWN INSPECTORS HADN'T EXAMINED EVERY INSURER BECOMES A PRIVATE REGULATOR — BECAUSE THE INSURER PAYS FOR THE EXPLOSION FOR AI: STRICT LIABILITY + MANDATORY INSURANCE → UNDERWRITERS DEMAND AUDITS, MONITORING, EACH THEIR OWN SWITCH THE COST: 1 · LIABILITY ARRIVES AFTER THE HARM — AND THIS HARM IS THE KIND MONEY CANNOT REPAIR 2 · TAIL-RISK INSURANCE MARKETS COLLAPSE EXACTLY WHEN THE RISK GETS REAL 3 · IF A SYSTEM EVER RESISTS BEING STOPPED, A COURT JUDGEMENT IS NOT A BUTTON
Fig. 5 — three redlined redesigns · dashed green = revision markup · sources: SEC/NYSE Rule 80B, FAA, Hartford Steam Boiler (1866)

The market's breaker. After 1987, US markets built circuit breakers: thresholds published in advance — fall 7% and trading pauses automatically; 13% again; 20% ends the day. Nobody decides in the moment. For AI: automatic triggers on measurable signals — compute spikes, self-copying attempts. The cost: markets get one clean number, loss of control has none; a wrong threshold silences a hospital's diagnostics or never fires at all; automation moves the arbitrary decision from the crisis to the drafting table.

The aviation model. The authority that can ground every plane has used that power fully exactly once — 9/11. The real control happens before flight: nothing flies until its type is certified, so the shutdown power rests on knowledge. For AI: license frontier systems before deployment. The cost: certifying a plane takes years while a model retrains in months; the experts who out-understand the labs work at the labs; and a country that pauses to certify watches its rivals ship.

The insurance model. In the 1800s steam boilers kept exploding; what tamed them was insurers refusing to cover any boiler their own inspectors hadn't examined. Strict liability plus mandatory insurance made every insurer a private regulator. For AI: underwriters demand the monitoring, the audits — and a kill switch, each insurer requiring its own rather than one government channel. The cost: liability arrives after the harm, and this harm is the kind money cannot repair; tail-risk insurance collapses exactly when the risk gets real; and if a system ever resists being stopped, a court judgement is not a button.

The close · The press-machine questions

The button is the easy part.

ON A PRESS, THREE QUIET CONDITIONS HOLD: ✓ THE WORKER SEES THE JAM WITH THEIR OWN EYES ✓ THE WIRE IS SHORT, PHYSICAL, BEHIND WALLS ✓ "STUCK" IS OBVIOUS — NO DEFINITION NEEDED THE BILL, SO FAR: ? THE EYE IS BORROWED — UP TO 15 DAYS LATE ? THE WIRE IS A NETWORK — A PRIZE AS MUCH AS A SAFEGUARD ? THE TRIGGER IS A PARAGRAPH NOBODY CAN YET DEFINE NONE OF THIS MAKES THE BUTTON A BAD IDEA. IT MAKES THE BUTTON THE EASY PART. HOW DOES THE HAND SEE? · WHO GUARDS THE WIRE? · WHAT TRIPS IT?

On a printing press the button works because three quiet conditions hold: the worker sees the jam with their own eyes; the wire from button to motor is short, physical, and guarded by the walls of the building; and "stuck" is obvious — nobody needs a definition. The bill has, so far, none of the three. The eye is borrowed. The wire is a network — a prize as much as a safeguard. The trigger is a paragraph of legal language for something the field's own researchers cannot yet define.

None of this means the button is a bad idea. It means the button is the easy part. So when this bill — or its successor, here or in any country — reaches a vote, don't ask "should AI have an off switch?" Everyone answers yes. Ask the press-machine questions instead: How does the hand see? Who guards the wire? And what, exactly, trips it?

TRACE UPSTREAM

Not who's to blame — how it's built. The full interactive blueprint, with the parts that didn't fit the video, lives on this page.

Watch on YouTube Subscribe
to stop the most powerful AI on earth congress, last week
1 switch
who holds it · who guards it
COMPANY DHS the government's only AI sensor is the company itself
15 days late
the AI kill switch problem