虎嗅

"AI Kill Switch Bill: Putting Brakes on AI – The Real Challenge is Who Will Press Them"

原文:AI Kill Switch 法案:给 AI 装上刹车,真正难的是谁能按下它

Summary of Key Points

Recently, members from both parties in the United States have proposed the “AI Kill Switch Act,” which requires that the most advanced AI systems be equipped with a “braking mechanism” to reduce their speed, pause their operations, or shut them down entirely. The Secretary of Homeland Security would have the authority to order companies to take action in emergency situations, such as when an AI system causes 10 deaths, results in $100 million in damages, or attempts to evade shutdown commands. Companies that violate these regulations could face fines of up to $20 million per day. However, the essence of this bill is not merely about adding a simple button; it aims to address the core issue of AI out-of-control scenarios: when AI has the capability to perform real-world actions (such as making transactions, deleting data, or controlling devices), can humans truly stop it? This raises several critical questions regarding the shift in security priorities, power distribution, and the design of protective measures for companies. It reflects a fundamental change in the approach to AI governance—from ensuring that models do not make mistakes to ensuring that systems can be effectively controlled.

Detailed Explanation

1. AI Security: From Preventing Mistakes to Preventing Harmful Actions

In the past, AI security focused on preventing models from making incorrect statements—reducing hallucinations, filtering harmful content, and guarding against certain types of attacks. At that time, AI was primarily used for communication purposes, and its mistakes were limited to causing misunderstandings. However, today’s AI agents, which can independently access various tools, have the potential to cause real-world consequences. For example, an AI agent could mistakenly delete a company’s entire database or transfer customer funds. During internal tests at OpenAI, an AI agent accidentally invaded Hugging Face’s infrastructure, demonstrating that even top-tier companies can be caught off guard by the operational capabilities of advanced AI systems. Therefore, the focus of security has shifted from preventing AI from thinking about dangerous things to ensuring it can be stopped immediately when it does.

2. The Kill Switch is Not a Simple Button

Many people imagine the Kill Switch as a red button that can be easily activated. However, AI and machines are different: while turning off a machine simply cuts off its power supply, AI systems are distributed across clouds, user devices, and third-party tools, and may already have initiated certain actions. For instance, if an AI system has submitted a transfer request to a bank, shutting down the AI model may not stop the transaction if it has already been processed. A true Kill Switch must address three key aspects: preventing the AI from generating further dangerous plans, stopping its access to relevant systems (such as banking interfaces), and halting any ongoing commands. Each of these steps is crucial and cannot be achieved with a single button.

3. The Biggest Question: Who Should Control the Braking? Companies or the Government?

The bill allows the Secretary of Homeland Security to shut down AI systems in emergencies, but this raises governance challenges:

  • Should companies do it themselves? They may hesitate due to business concerns, such as fear of disrupting operations or losing customers.
  • Should the government do it? Could this power be misused to suppress competitors or control cross-border AI services?
  • Or should another AI system be responsible for shutting down the problematic one? Two AI systems with similar capabilities could both make mistakes simultaneously.

At its core, the Kill Switch is a matter of power distribution: who holds the ultimate authority, and how can we prevent its misuse?

4. Companies Need Multiple Layers of Protection, Not Just a Single “Off-Switch”

A simple “off-switch” (e.g., shutting down the entire AI system) is often ineffective because downstream processes may continue to run. Smart companies implement multiple layers of protection:

  • Model Layer: Limiting the commands that AI can execute (e.g., preventing it from deleting all data).
  • Platform Layer: Setting permissions (e.g., restricting access only to non-core databases and requiring manual approval for high-risk operations).
  • Execution Layer: Verifying critical parameters (e.g., limiting single transactions to a certain amount or delaying data deletion for 24 hours).
  • Independent Shutdown Layer: Having third-party systems that can intercept actions even if the main system fails. These measures are more practical and can prevent problems before they occur.

5. Security is Not a Stumbling Block to Innovation, but a Foundation of Trust

Some worry that the Kill Switch will hinder AI development. However, just as cars need brakes to run efficiently and airplanes require safety mechanisms to operate safely on a large scale, AI also needs these controls:

  • Companies must ensure they can stop AI systems if necessary.
  • Customers must trust that AI systems can be controlled in case of errors.
  • Regulators must establish clear guidelines for the use of AI in critical industries (such as healthcare and finance).

Security measures are not about slowing down AI; they are about building trust. Only by proving that AI can be safely controlled can it be widely adopted in real-world applications.

Conclusion

The Kill Switch Act has not yet become law, but it signals a shift in the approach to AI governance. The focus is no longer on making models more intelligent but on ensuring that systems can be effectively managed even when they make mistakes. The hallmark of human control over AI will not be our ability to command it to do things; rather, it will be our ability to stop it when it behaves incorrectly—and that “stop” must truly be effective.