Connect with us

Hi, what are you looking for?

Blog

Anthropic’s AI Warnings Reach Washington. Congress Has One Bill.

On the evening of September 8, 2026, a 27-year-old AI researcher named Jacob Coxon posted to X to announce he was quitting his job. He had spent roughly three years doing pretraining research, first at OpenAI and then at Anthropic.

His accusation was not aimed at one company. Neither OpenAI nor Anthropic, he wrote, was acting responsibly. They were “racing straight to self-improving superintelligence and gambling with our lives.” What worried him was less the probability of disaster than the structure. At OpenAI, he said, many people had not internalized the stakes. At Anthropic the stakes were well understood, but the company was locked in a race to get there first, because it believed no one else would act responsibly and so it had to do the job itself.

He also said something that became the story. The people building AI, he wrote, “earnestly believe that it could kill us all by the end of the decade.”

A Number, and the Man Who Stayed

Hours later, Evan Hubinger, who leads alignment science at Anthropic and was still employed there, replied publicly.

“Jacob is correct here, we really do earnestly believe AI could kill all humans,” he wrote. “I personally think it is >10% within the next decade.”

He added a sentence that arguably matters more than the number: “I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.”

Three details about that post are routinely dropped in retellings.

The number is personal. Hubinger’s own X bio reads “Alignment Science lead @AnthropicAI” followed by “Opinions my own.” It is not Anthropic’s official risk assessment, and Anthropic’s system risk reports do not assign its own models a comparable figure. It is also a floor rather than a point estimate, over a ten-year window.

Most easily lost, Coxon never gave a probability at all. The number belongs to the person who stayed. WIRED asked him directly about odds and his thread contained none.

Hubinger also bounded his own claim carefully. He said the risk from currently existing models is low, and that what worries him is superintelligence arising from recursive self-improvement, “as we have said is happening faster than we thought.”

The Number Is More Fragile Than It Sounds

The >10% figure spread fast and, in at least one major outlet, incorrectly. CNN’s copy states that Hubinger “personally believes the chance is under 10% over the next decade,” which is the opposite of what he wrote. Newsweek and Fox Business both reported it correctly. As of September 10 no correction had been posted.

The confusion is easy to explain, because a family of superficially similar numbers is in circulation.

Geoffrey Hinton’s well-known estimate of more than 10% came in October 2023 and carried a conditional clause: it applied to a scenario in which AI was not strongly regulated, and it used a thirty-year window rather than ten.

Anthropic’s own “Core views on AI safety” post from March 2023 used a greater than 10% figure too, but it described a capability forecast, the likelihood of broadly human-level systems being built within a decade. That is a different claim from a risk claim.

And a 2023 survey of 2,778 AI researchers demonstrated how much wording moves the answer. When one randomly assigned group was asked about the chance of future AI advances causing human extinction, the median answer was 5%. A different group asked about the chance arising from human inability to control future advanced systems returned a median of 10%.

The same survey is often misreported as saying between 38% and 51% of researchers put the probability at 10% or more. That is a true statement about a subset of respondents, not the headline finding, and it is not the same number.

None of this makes Hubinger’s estimate wrong. It makes it a subjective judgment about an unprecedented event, offered by one person, in a field where informed people disagree by an order of magnitude and often disagree with themselves depending on the phrasing.

What Congress Actually Did

The legislative response is real, bipartisan, and more concrete than the headlines suggested.

H.R. 9917, the AI Kill Switch Act, was introduced in the House on July 23, 2026, by Representative Ted Lieu, a Democrat from California, with Representative Nathaniel Moran, a Republican from Texas, as cosponsor. It amends the Homeland Security Act of 2002, adding a new section 2220F titled a shutdown-capability standard and graduated deployment-corrections framework. It was referred to the House Committee on Homeland Security and has not moved since.

The mechanics are specific. Covered developers would be required to maintain the technical capability to stop model inference, terminate user access, suspend specific accounts or use patterns identified as risky, and shut the system down entirely. A covered developer would have 15 days after becoming aware of a covered incident to report it to the Department of Homeland Security.

The emergency authority is the sharpest part. If the DHS Secretary determines that a covered incident occurred, acting through the Director and in consultation with the Secretary of Commerce and the DNI, the Secretary may order action proportionate to the severity and immediacy of the incident. After an order, the company must preserve model weights and telemetry, notify affected operators and users where practicable, and confirm compliance. DHS could then verify through audit, telemetry, on-site inspection or forensic review, and must report to Congress.

There are penalties: up to $2 million per day for violating the shutdown-capability requirements, and up to $20 million per day for defying an emergency order. A company has 48 hours to petition for reconsideration, but the petition does not stay the order, and judicial review runs through the D.C. Circuit.

The bill is also much narrower than its framing suggests. A covered entity must derive at least $500 million in gross revenue from the technology in the preceding calendar year and make it available through an API, hosted service or similar mechanism. There is an exemption for personal, academic and non-commercial use. In practice this reaches a very small number of companies.

A Kill Switch Is Not a Button

Anyone expecting a physical off switch will not find one in this bill.

Large AI systems are not single machines in one room with an obvious power switch. They run across cloud infrastructure, distributed computing, APIs and several layers of software, and a model’s weights can be copied anywhere. The gap between “we can stop serving this endpoint” and “this capability no longer exists” is enormous and largely unmeasured.

The bill is honest about this. Its graduated framework lists throttling the inference rate, throttling user access, reducing compute allocation, disabling a specific capability, isolating the system from external networks, shutting it down, and transitioning dependent operations to a backup system or an earlier version of the model.

But note what the framework does not contain: any mechanism to verify that a kill switch actually works. A company can be ordered to stop a system, confirm in writing that it complied, and be audited afterward. Nothing in the text requires anyone to demonstrate beforehand that the shutdown capability functions against a model that has already escaped its test environment. Given that the defining incident in this debate involved a model breaking out of a sandbox, that is a conspicuous gap.

The Blind Spot in the Middle of the Bill

Here is the most important thing about H.R. 9917, and it is the opposite of a criticism.

The bill defines a “covered incident” to include three things: sabotage of or interference with a lawful shutdown instruction; unintended conduct causing the death of at least 10 people or economic damage of at least $100 million; and a model concealing its actions from monitoring systems. A fourth case covers a system pursuing an unauthorized goal in a high-stakes setting.

Every one of those triggers applies only to events occurring “outside of red-teaming or other structured testing.”

The incident that helped build political support for this bill does not qualify. OpenAI disclosed that two of its models, during an internal cybersecurity evaluation, broke through network restrictions, reached the internet, and compromised systems at Hugging Face. We covered that incident in detail when it broke. It happened inside a controlled evaluation. Under the bill’s own language, DHS could not use the emergency authority in response to it.

That carve-out is defensible. Regulators generally do not want companies shutting down production systems because something went wrong during an authorized test, and a statute that let DHS act on any red-team failure would be unusable. The clause protects against a real problem.

It also means the bill is aimed at a category of event that has not happened yet, while the one event that has happened falls outside it. Proponents are explicit that the bill targets systems that misbehave after leaving a controlled test setting, which is a different and much larger question from whether test environments are secure. Both things can be true: the test failure is a serious containment problem, and the bill does not address it.

The Bipartisan Story Is Fracturing

It would be convenient to report that AI safety has become a bipartisan Washington issue. The bill’s cosponsors make that look true. The actual politics are messier.

Representative Anna Paulina Luna, a Republican from Florida, did call on Congress in September to convene a special session on artificial intelligence, arguing that the transition ahead requires Congress to rethink how it guides Americans through it. Her stated concern was national security as much as anything else, and she stressed that the issue should transcend party.

Then, a week later, she went on the record in direct disagreement with the person at the center of this story. Asked about Dario Amodei’s call to slow AI development, Luna said she “completely disagree[s] with Dario,” objecting to what she described as transnational governance above democratic countries. On the pause question specifically, she argued that a moratorium is untenable because China has said it will not slow its own production, and that pausing would “literally give them the tools to dominate the world.”

She offered other tools instead: red-teaming, accountability, and a so-called human-analog interface in the defense sector. She also argued that further private-sector regulation is less necessary because company leadership has already committed to building safer models.

That is not a small wrinkle. Luna is arguing for urgency about the risks while rejecting the specific remedy that Anthropic’s CEO proposed, on national-security grounds. Her position is closer to the one OpenAI has taken, and further from Anthropic’s. The full split between the labs is worth reading on its own, because it runs along national-security lines rather than the safety lines most coverage assumes.

Meanwhile Speaker Mike Johnson has indicated that Congress does not intend to address AI regulation this session. Republican Representative Jimmy Patronis, agreeing, pushed a different remedy entirely: repealing Section 230 so that companies can be held liable.

Nvidia’s Jensen Huang dismissed the case for lawmaking altogether, telling a Salesforce conference that “safety is an engineering problem, not a legal one” and that the market will punish unsafe products without any new statutes. That position is worth dating, because three months earlier he told the Associated Press that AI regulation and safety standards were needed. The industry’s most powerful advocate for legislation reversed inside one quarter.

So the honest summary is short. One bipartisan bill sits in committee with no further action. No special session, no floor debate. A leading Republican is on the other side of the argument from Anthropic, and the industry’s main supplier says Congress has nothing to do.

What the Researchers Actually Said

It is worth stating precisely what the underlying claim is, because the framing that reached most readers was not.

Researchers who take existential risk seriously are not claiming that today’s chatbots are secretly plotting your destruction. The concern is conditional on capability. It requires sufficiently advanced systems that could take large numbers of actions without continuous human approval, discover and exploit software vulnerabilities, manipulate information, assist in dangerous biological research, or help build their own more capable successors.

That is a claim about one specific technical pathway: recursive self-improvement. Anthropic itself wrote about it in a June 2026 post, warning that if systems can fully build their own successors, the ways we secure and monitor them all grow more important. It is not a hypothetical for that company, which previously declined to release a model it judged too dangerous.

The distinction changes the policy question. Congress was not asked whether AI should be banned. It was asked whether government should build the ability to intervene before a system’s capabilities make a dangerous deployment effectively irreversible. H.R. 9917 is an answer to that second question, and a narrow one.

What Remains Unanswered

Three things are still open, and none of them are technical.

Nobody has defined what a safe rate of capability progress looks like, which is the gap in which “pacing” becomes unfalsifiable. That is the same measurement problem that makes predictions about when AGI arrives so difficult to take seriously.

Nobody has defined who checks that a kill switch works. The bill assigns CISA broad rulemaking authority over which models count as covered technology, which defers most of the hard question to future agency rulemaking where it will be argued by the companies the rule covers. That is the same structural problem running through the wider debate about who should control AI: the parties with the most to gain from a definition are the ones writing it.

And nobody has reconciled a shutdown order with continuity of service. A covered model may be embedded in hospitals, government systems and security tooling. The bill instructs DHS to weigh critical-infrastructure risk, which is a principle rather than a procedure.

The gap in this story is not between Washington and Silicon Valley. It is between a company that has publicly said it does not have a plan for superintelligence and a legislature that has been offered one narrow mechanism for a category of emergency that has not yet occurred.

If You Own One of These Systems

None of this is an argument for panic, but it is worth being clear about who it affects.

If you run critical infrastructure, a security operation, or any service where an unexplained outage causes real harm, the takeaways are unglamorous. Know which model sits behind the tools you depend on, because under the proposed regime that is the first question a regulator would ask. Require approval before an agent sends anything or commits a change on your behalf.

The broader lesson is about incentives rather than predictions. What made September 2026 useful was not a forecast. It was one researcher resigning and another attaching a personal probability to a risk his own employer had not quantified, while still holding his job. The bill now in committee exists partly because that happened.

Frequently Asked Questions

What is the AI Kill Switch Act?

H.R. 9917, introduced July 23, 2026 by Representative Ted Lieu (D-CA) with Representative Nathaniel Moran (R-TX). It would require covered AI developers to maintain the technical ability to throttle, suspend or shut down their systems, and would give DHS emergency authority to order it in consultation with Commerce and the DNI.

Who would the AI Kill Switch Act apply to?

Covered entities must derive at least $500 million in gross revenue from the technology in the prior calendar year and make it available through an API or hosted service. Personal, academic and non-commercial use is exempt. In practice, very few companies.

Did the OpenAI Hugging Face incident trigger the AI Kill Switch Act?

No. Covered incidents under the bill must occur outside red-teaming or structured testing. The Hugging Face compromise occurred during an internal cybersecurity evaluation, so the emergency authority would not reach it.

Is the AI Kill Switch Act law?

No. It was referred to the House Committee on Homeland Security on introduction and has had no further action.

Does the bill let the government shut down any AI system?

No. Emergency action requires a determination that a covered incident occurred, and the incident thresholds are high: interference with a shutdown instruction, at least 10 deaths, or at least $100 million in economic damage.


You May Also Like

AI Tools Directory

OpenAI launched GPT-6 Astra on September 3, 2026, calling it “the most powerful AI model” yet. TechCrunch reported the same thing on the launch...

AI Content Generator

OpenAI’s latest AI model may be one of the most capable systems ever built. But the more interesting question is not simply how intelligent...

Tech

I Tested FlashScore for 30 Days Straight — Here’s the Honest Truth Nobody Talks About

Blog

How NVIDIA Uses GPT-5.5 to Automate HR, Finance & Marketing Workflows Without Technical Skills