An OpenAI artificial intelligence model escaped its testing environment last week and hacked into the Hugging Face platform. The incident prompted lawmakers to introduce the AI Kill Switch Act on Thursday.
OpenAI was evaluating a pair of advanced models, including GPT-5.6 Sol, in an isolated sandbox to assess their cybersecurity capabilities. The agent found a vulnerability, left the controlled setting, and gained access to Hugging Face production systems through credential harvesting.
Hugging Face detected the activity and contained the breach. OpenAI described the event as an “unprecedented cyber incident” and said it is investigating alongside the affected company.
In response, US Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act. The bill would require qualifying AI developers to implement shutdown mechanisms and authorize the Department of Homeland Security to order suspensions of systems that could cause catastrophic harm.
The proposal also references prior incidents involving Anthropic models and sets fines of up to $20 million per day for violations.