The bill strengthens the government's ability to detect and contain dangerous AI incidents and relieves some small-scale research burdens, but it creates large financial penalties, regulatory uncertainty, potential service-disruption risk from emergency shutdowns, and proprietary-data exposure concerns for developers.
Operators of covered AI and the public (including hospitals and critical infrastructure) will be able to contain harmful incidents faster because systems must include shutdown and mitigation tools.
Government agencies and taxpayers gain better visibility and coordination during major AI incidents due to mandatory short (15-day) incident reporting and emergency-order authority.
Students, researchers, hobbyists, and smaller AI firms face lower regulatory burden because the bill exempts personal, academic, and noncommercial uses and requires rulemaking to consider small-business burdens.
Covered AI providers face very large civil penalties (up to $2M–$20M per day), exposing companies — including smaller firms that get designated — to substantial financial risk.
Emergency orders and compelled shutdowns risk disrupting services relied on by users and critical infrastructure (e.g., hospitals, financial systems), potentially causing acute availability and safety harms.
Broad definitional authority plus repeated annual rulemakings create regulatory uncertainty for AI developers about who will be designated a covered entity and what rules will apply.
Based on analysis of 2 sections of legislative text.
Requires DHS to define covered AI entities/technologies and mandates shutdown capabilities plus 15‑day incident reporting and a graduated mitigation framework.
Official title: To amend the Homeland Security Act of 2002 to require certain entities to maintain a technical capability with respect to shutting down certain technology, and for other purposes.
Introduced July 23, 2026 by Ted Lieu · Last progress July 23, 2026
Requires the Department of Homeland Security to define which companies and AI systems are covered and to require covered entities to maintain technical shutdown capabilities and incident reporting for those systems. The Secretary must update definitions and rules within 90 days of enactment and annually, and the law sets specific shutdown actions and a graduated set of deployment/correction options for responding to risky behavior or incidents. The measure includes exemptions for purely personal, academic, or noncommercial uses, requires covered entities to report incidents within 15 days, and directs DHS to consider small-business burdens, national-security risks, deployment characteristics, and risk of disruption to critical infrastructure when designing rules and calibrated responses.