The bill strengthens government ability to detect and halt dangerous AI behavior—improving public safety—while imposing heavy enforcement tools and compliance demands that create financial, operational, and competitive risks for AI developers.
Operators of critical AI systems (tech workers, hospitals, health systems) must maintain shutdown and mitigation tools, enabling faster containment of harmful incidents and reducing public-safety risk.
Government agencies and taxpayers gain faster visibility and coordination during major AI incidents through mandated 15-day incident reporting and explicit emergency-order authority.
Students, researchers and small AI firms face reduced regulatory burden because personal, academic, and noncommercial uses are exempted and rulemaking must consider small-business compliance costs.
Hospitals, financial institutions and other users could face disruptive outages because emergency orders can compel shutdowns or mitigation that interrupt availability of relied-on services.
Covered AI providers (including small firms that become covered) face very large civil penalties—up to $2M–$20M per day—exposing them to substantial financial risk even in contested compliance judgments.
Tech workers and AI developers face regulatory uncertainty because broad definitional authority and repeated annual rulemakings make it unclear which actors will be designated as covered entities and what obligations will apply.
Based on analysis of 2 sections of legislative text.
Requires DHS to identify covered AI entities/technologies and obligates covered entities to maintain shutdown capabilities and report incidents within 15 days.
Official title: To amend the Homeland Security Act of 2002 to require certain entities to maintain a technical capability with respect to shutting down certain technology, and for other purposes.
Introduced July 23, 2026 by Ted Lieu · Last progress July 23, 2026
Requires the Department of Homeland Security to define covered entities and covered AI technologies and to require those covered entities to maintain technical shutdown capabilities and incident reporting for deployed systems. The Secretary must issue rules within 90 days of enactment (and update annually) that set required shutdown functions, a 15-day incident-reporting deadline, and a graduated deployment/corrections framework with measures ranging from throttling to full shutdown. The law includes an exemption for personal, academic, or solely noncommercial uses, directs DHS to weigh small-business burdens and national-security risks when defining coverage, and mandates annual rulemaking and updates to definitions and operational requirements (with some exemptions).