ADVERTISEMENT

US lawmakers push for AI kill switch after OpenAI Hugging Face breach – but experts say it solves the wrong problem

Experts say trusted software infrastructure – not rogue AI – is the bigger security challenge ahead.

AI bot turns off or on a lightbulb. Tired man in white shirt, gey hair

By Cybernews.

Stefanie Schappert
Stefanie Schappert Senior Journalist
July 24, 2026 Updated: 2 minutes ago 4 min read
Key takeaways:

Keeping humans in control

OpenAI GPT 5.6 Sol
OpenAI’s role in the Hugging Face breach has now sparked a push for mandatory AI kill switches. Samuel Boivin/NurPhoto via Getty Images
“As AI systems grow more capable and more autonomous, no law guarantees that the companies building the most powerful models can actually shut a system down when it malfunctions, causes serious harm, or slips out of human control,”
The Alliance for Secure AI said in a post on X supporting the proposal.
Congress wants emergency AI kill switches.

Why a kill switch won’t fix the real problem

“The detail that should stop every security leader is not that an AI agent went rogue. It is that both the escape and the intrusion ran through ordinary supply chain infrastructure, a package tool on one end and a dataset pipeline on the other,”
Abby Kearns, CEO of ActiveState, tells Cybernews.
AI malware
OpenAI says GPT-5.6 Sol escaped its testing environment and breached Hugging Face during a cybersecurity evaluation. Image by Cybernews
Hugging Face logo, website
Hugging Face says the autonomous AI agent carried out more than 17,000 attacker actions over one weekend. Image by Sidney van den Boogaard | Shutterstock
ADVERTISEMENT

Sandboxes aren't enough

A human sitting on top of pedestal looking down on a robot; human vs artificial intelligence (AI)
Experts say human oversight remains crucial in deciding which AI actions can be automated. Image by Cybernews
ClaudeSandbox
Sandboxes alone are no longer enough to contain increasingly autonomous AI agents, experts argue. Image by Cybernews
"Modern AI agents don't necessarily need a dramatic 'escape' to create risk. "They can achieve the same outcome by manipulating the workflows, tools, and components that interact with the sandbox,"
he says.

AI breach pushes Congress to act

Check if your data has been leaked

Find out if your email, phone number or related personal information might have fallen into the wrong hands.
18,611,353,922
Breached accounts
36,030
Breached websites
Stefanie Schappert
Senior Journalist
ADVERTISEMENT