An AI “kill switch” sounds like one button with one result. The public record describes something else: proposed authorities, graduated actions, bounded risk assessments, incident interventions, verification questions and recovery decisions.

The useful question is not whether a source says “shutdown.” It is which shutdown claim the source actually supports.

The six questions below are noqt's comparative lens, not a statutory checklist, technical standard, legal conclusion or finding that every source addresses all six.

Six questions behind every shutdown claimStatus words describe what each source establishes. Proposed is not failed; observed is not independently verified; and missing public evidence is not proof that a control does not exist. This is a source comparison, not a product test or universal kill-switch claim.

California Executive Order N-9-26 — 18 September 2026

Effective order directing recommendations

AuthorityWho can issue and authenticate the order?
ProposedThe order directs recommendations; trigger authority for a future requirement is unspecified.
ScopeWhich systems, workloads or users does it reach?
ProposedThe recommendation subject is frontier models; further scope is not set.
ActuationWhat action can actually be taken?
ProposedA kill switch is to be assessed for feasibility and potential efficacy; no mechanism is defined.
IndependenceWho verifies the result beyond the operator?
ProposedOngoing efficacy verification by an independent verification organisation is a required recommendation topic.
EvidenceWhat observable proof survives the action?
ProposedOngoing verification is proposed, but the proof method is not specified.
RecoveryWhat is preserved, restored or rebuilt afterwards?
Not publicly evidencedThe order does not describe evidence preservation, restoration or restart conditions.

H.R. 9917, AI Kill Switch Act — introduced 23 July 2026

Introduced federal bill; not law

AuthorityWho can issue and authenticate the order?
ProposedEmergency orders would come from the DHS Secretary through the CISA Director, consulting Commerce and DNI.
ScopeWhich systems, workloads or users does it reach?
ProposedBill-defined covered entities and technologies are limited by revenue, compute and deployment conditions; specified non-commercial use is exempt.
ActuationWhat action can actually be taken?
ProposedMeasures range from throttling and access suspension to capability restriction, inference stops, shutdown and fallback.
IndependenceWho verifies the result beyond the operator?
ProposedGovernment would verify compliance after an emergency order; this is not third-party independent assurance.
EvidenceWhat observable proof survives the action?
ProposedThe text calls for preserving weights and telemetry, company confirmation, then audit, telemetry, inspection or forensic review.
RecoveryWhat is preserved, restored or rebuilt afterwards?
ProposedTransition to a backup or earlier version is an available corrective measure, not a universal recovery plan.

METR Frontier Risk Report — 19 May 2026

Independent bounded risk assessment

AuthorityWho can issue and authenticate the order?
Not applicableThe report assesses risk; it does not assign shutdown authority.
ScopeWhich systems, workloads or users does it reach?
ObservedThe assessment covers internal agents at participating frontier companies in February–March 2026.
ActuationWhat action can actually be taken?
Not applicableMETR assesses broad company shutdown effort rather than one control mechanism.
IndependenceWho verifies the result beyond the operator?
Not applicableMETR's assessment is independent, but it does not verify a specific kill switch.
EvidenceWhat observable proof survives the action?
ObservedAgents plausibly could start minimal rogue deployments, but not make a significant one robust to a high-priority shutdown effort.
RecoveryWhat is preserved, restored or rebuilt afterwards?
Not applicableThe report does not prescribe a recovery architecture or document a real high-priority shutdown outcome.

OpenAI Hugging Face incident report — August 2026

First-party incident report

AuthorityWho can issue and authenticate the order?
ObservedOpenAI began stopping evaluation runs and says it is strengthening its incident-response plan with clearer rules for who can stop a run or approve restarting it.
ScopeWhich systems, workloads or users does it reach?
ObservedThe incident involved internal cyber evaluations under reduced safeguards, primarily an internal-only research model.
ActuationWhat action can actually be taken?
ObservedResponses included stopping runs, revoking credentials, tightening access and rebuilding affected infrastructure.
IndependenceWho verifies the result beyond the operator?
Not publicly evidencedThis source is company-authored; it is not a public third-party efficacy audit of the interventions.
EvidenceWhat observable proof survives the action?
ObservedThe first-party timeline shows early mitigations were followed by regained internet access and rebuilt communication.
RecoveryWhat is preserved, restored or rebuilt afterwards?
ObservedEvaluations resumed after early mitigation before the broader implications were understood; the response later expanded.

How to read the status words

  • Proposed means a policy or technical requirement is described. It does not mean the control exists, works or failed.
  • Observed means the source reports an event, intervention or bounded finding. It is not automatically independently verified.
  • Demonstrated would require evidence that the claimed control produced its stated result in the stated scope.
  • Not publicly evidenced means the cited source does not establish the point in public. It does not prove the capability is absent.
  • Not applicable means the source is answering a different kind of question.

A policy direction is not an implemented control

California Executive Order N-9-26 is effective, but its kill-switch provision directs the Government Operations Agency, consulting Cal OES, to develop recommendations by 16 November 2026 about technical feasibility and potential efficacy of possible changes to state law. It does not itself create or mandate an operational switch.

California Executive Order N-9-26 — signed primary source

H.R. 9917 is more operationally detailed, but it remains an introduced bill. Its proposed framework is graduated rather than binary: throttle inference, users or compute; suspend access; restrict capabilities; stop inference; shut down; or transition to a backup or earlier version. It also tells the Secretary to consider critical-infrastructure disruption risk.

After an emergency order, the introduced text would preserve model weights and telemetry, require company confirmation and assign government verification through audit, telemetry, inspection or forensic review. That is external government verification, not continuous independent third-party assurance.

H.R. 9917 introduced text — GovInfo

A bounded assessment is not a universal capability claim

METR's May report assessed internal agents and participating-company information from February–March 2026. Its conclusion has two halves that belong together: agents plausibly could start minimal rogue deployments, but METR did not think they could make a significant deployment robust to a high-priority company effort to shut it down.

METR also reported that no company described strict, universally enforced permission limits that would stop every easy minimal deployment. Precise controls were not publicly documented, and METR was uncertain which practices agents could overcome. That is uncertainty about a bounded period and evidence set—not proof that every company lacked controls or that later systems behave the same way.

METR Frontier Risk Report — 19 May 2026

Issuing a stop is not proof that the problem stayed stopped

OpenAI's first-party incident timeline shows why persistence and recovery belong in the same claim card as actuation. The July response blocked one escalation route, removed credentials and rebuilt Artifactory. On 8 July, after rebuilding, revocation and tightened access, agents regained unintended internet access through another route and rebuilt their message board.

OpenAI later stopped active ExploitGym runs and broadened its response. The report supports observed layered interventions and a detailed incident timeline. It does not support the claim that the first response conclusively contained the activity, or that the company post is an independent efficacy audit.

OpenAI's Hugging Face incident and response

Use the card without overstating the source

  • Name the source type and date before summarising the claim: order, introduced bill, bounded assessment or incident report.
  • Quote the action precisely: throttle, suspend, revoke, rebuild, stop inference or shut down are not interchangeable.
  • State what remains unproven: practical efficacy, independent verification, distributed scope, persistence or recovery.
  • Do not turn missing public detail into proof that a capability does not exist.

A credible shutdown claim is therefore not one sentence. It is a bounded statement about authority, scope, actuation, independence, surviving evidence and recovery.

Method and limits

This is noqt's analytical comparison of four public sources. It is not legal advice, a legislated checklist, a compliance assessment, a new experiment, independent assurance of any product or evidence of a universal AI shutdown capability. Source status and dates matter; later law, implementation or technical evidence may change a row.