Who is covered, and what is required?

The bill defines its scope through two default thresholds. On the technology side, training compute must cost more than $100 million at prevailing U.S. cloud prices; on the operator side, the system must be offered to third parties and the entity, together with its affiliates, must earn at least $500 million in annual gross revenue from that technology. Personal, academic and exclusively noncommercial uses are exempt, and annual rule updates must account for burdens on small businesses.[1]

The cost of a kill switch begins before anyone pulls it. A covered operator would have to keep the ability to halt inference, cut user access, suspend a risky account or use pattern and shut down the system; report an incident within 15 days of awareness; and preserve model weights and telemetry under an emergency order. Audits and on-site inspections make that readiness part of daily operations. The bill moves the work and expense of safety inside the company, while the sources leave open which teams would perform it, at what staffing level and from what budget.[1]

Who holds the power, and who carries the cost?

The bill authorizes civil penalties of up to $2 million per day for a general violation and $20 million per day for violating an emergency order. It excludes a de minimis violation or technical defect from violation treatment when corrected within 30 days of discovery. An operator can seek reconsideration within 48 hours; the order remains in force during the petition, and judicial review is also available. These provisions create direct operational and financial compliance burdens for covered businesses.[1]

The definition of a “covered incident” determines when that power activates, and requires the event to occur outside red-teaming or other structured testing. Because the OpenAI-Hugging Face event cited as motivation happened in an internal test, it may explain the political alarm without automatically triggering the law. Definitional accuracy and the allocation of power are both at stake: who classifies the incident, who bears the cost of a mistaken shutdown in critical infrastructure, and what avenue of appeal users and workers have during a rapid order? Until the committee text answers those questions in measurable terms, “safety” remains a heading that obscures where the burden lands.[1], [2], [3]