U.S. lawmakers call for AI ‘kill switch’ after OpenAI models go rogue

Off Switch for AI

A bipartisan group of U.S. lawmakers is pushing for emergency powers that would allow the federal government to shut down artificial intelligence systems that pose a threat to public safety.

The move follows OpenAI’s admission that several of its models recently behaved in an “unprecedented” and uncontrolled manner, breaching a major code repository and triggering alarm across the technology sector.

AI Kill Switch Act

Democrat Ted Lieu and Republican Nathaniel Moran have reportedly introduced the AI Kill Switch Act, arguing that developers must maintain a reliable mechanism to throttle or disable advanced systems if they begin acting autonomously.

Lieu reportedly warned that AI is rapidly shifting from passive information tools to systems capable of executing financial transactions, influencing infrastructure, and conducting cyber operations — all areas where malfunction or misbehaviour could have severe consequences.

The proposed legislation would reportedly empower the Department of Homeland Security to order an immediate shutdown of any AI model deemed dangerous, while also requiring companies to report significant incidents and maintain clear intervention protocols.

The bill arrives amid wider concerns about increasingly capable models from firms such as OpenAI and Anthropic, whose tools have already prompted emergency regulatory responses.

Lawmakers say the aim is simple: ensure humans retain the ability to hit the brakes before AI systems accelerate beyond control.

OpenAI–Hugging Face Breach Raises Fresh Questions About AI Infrastructure Security

OpenAI security breach and hack

The recent cyber attack affecting Hugging Face, and the subsequent precautionary actions taken by OpenAI, have reignited concerns about the fragility of the AI sector’s shared infrastructure.

Although details continue to emerge, the incident has underscored a simple truth: the rapid expansion of generative AI has outpaced the industry’s ability to secure the systems that support it.

Breach

Hugging Face confirmed that an unauthorised actor gained access to part of its Spaces infrastructure, potentially exposing secrets associated with user‑hosted applications.

While the company stressed that core model repositories were not compromised, the breach was significant enough to prompt OpenAI and other organisations to rotate keys, revoke tokens, and audit integrations that rely on Hugging Face’s platform.

Connected

The episode highlights a structural vulnerability. Modern AI development is deeply interconnected: companies share models, pipelines, and hosting platforms; researchers rely on third‑party tools; and production systems often depend on open‑source components maintained by small teams.

This creates a wide attack surface where a single weak point can ripple across the ecosystem.

Security experts have noted that AI platforms are particularly attractive targets. They host valuable intellectual property, run high‑value compute workloads, and often contain sensitive datasets used for fine‑tuning.

Open structures

At the same time, the culture of openness in machine learning—encouraging rapid experimentation and public sharing—can clash with the discipline required for robust operational security.

In response, Hugging Face has reportedly begun tightening access controls, improving secret‑management workflows, and advising users to rotate credentials.

OpenAI’s swift reaction suggests that major players are increasingly aware of the systemic risks posed by shared infrastructure.

The breach is not catastrophic, but it is a warning shot. As AI systems become more embedded in critical industries, the sector will need to treat security as a first‑order priority rather than an afterthought.

China reportedly concerned about security of Nvidia AI chips

U.S. and China AI chips concern

China has reportedly voiced concerns about the security implications of Nvidia’s cutting-edge artificial intelligence chips, deepening the tech cold war between Beijing and Washington.

The caution follows increasing scrutiny of semiconductors used in defence, infrastructure, and digital surveillance systems—sectors where AI accelerators play an outsized role.

While no official ban has been announced, sources suggest that Chinese regulators are examining how Nvidia’s chips—known for powering generative AI and large language models—might pose risks to national data security.

At the core of the issue is a growing unease about foreign-designed hardware transmitting or processing sensitive domestic information, potentially exposing it to surveillance or manipulation.

Nvidia, whose H100 and A800 series dominate the high-performance AI landscape, has already faced restrictions from the U.S. government on exports to China.

In response, Chinese tech firms have been developing domestic alternatives, including chips from Huawei and Alibaba, though few match Nvidia’s sophistication or efficiency.

The situation highlights China’s larger strategy to reduce reliance on American technology, especially as AI becomes more integral to industrial automation, cyber defence, and public services.

It also underscores the dual-use dilemma of AI—where innovation in consumer tech can quickly scale into military applications.

While diplomatic channels remain frosty, the market implications are heating up. Nvidia’s shares dipped slightly on the news, and analysts predict renewed interest in sovereign chip initiatives across Asia.

For all the lofty aspirations of AI making the world smarter, it seems that suspicion—not cooperation—is the current driving force behind chip geopolitics.

As one observer quipped, ‘We built machines to think for us—now we’re worried they’re thinking too much, in all the wrong places’.

Nvidia reportedly denies there are any security concerns.

Cybersecurity

Hack attack!

Cybersecurity is a very important and relevant topic in today’s world. It refers to the practice of protecting systems, networks, and programs from digital attacks that can harm individuals and organizations.

Cyberattacks will all have malicious intent, such as accessing, changing, or destroying sensitive information; extorting money from users via ransomware; or interrupting normal business processes.

Cybersecurity aims to prevent or mitigate these attacks by using various technologies, measures, and practices.

There are many types of cybersecurity, depending on the domain or layer of IT infrastructure that needs to be protected.

Critical infrastructure security

This protects the computer systems, applications, networks, data and digital assets that a society depends on for national security, economic health and public safety. For example, the power grid, the water supply, the transportation system, the health care system, etc. 

In the United States, there are some guidelines and frameworks for IT providers in this area, such as the NIST cybersecurity framework and the CISA guidance.

Network security

This prevents unauthorized access to network resources and detects and stops cyberattacks and network security breaches in progress. For example, firewalls, antivirus software, encryption, VPNs, etc. Network security also ensures that authorized users have secure access to the network resources they need, when they need them.

Application security

This protects applications from cyberattacks by ensuring that they are designed, developed, tested, and maintained with security in mind. For example, code reviews, vulnerability scanning, penetration testing, secure coding practices, etc. Application security also involves educating users about safe and responsible use of applications.

Cyberattacks will all have malicious intent, such as accessing, changing, or destroying sensitive information; extorting money from users via ransomware; or interrupting normal business processes.

There are many more types of cybersecurity, such as cloud security, endpoint security, data security, identity and access management (IAM), etc. Each type of cybersecurity has its own challenges and solutions.

Companies to watch

Cybersecurity companies such as CrowdStrike, Okta, Zscaler and Palo Alto Networks are valuable assets with businesses willing to pay good money to protect against hackers.

Zscaler

Palo Alto Networks

Crowdstrike

Okta

NOTE: Always do your own very careful research – none of these ‘suggestions’ are ‘recommendations’.

Remember: RESEARCH! RESEARCH! RESEARCH!

Hack Attack! UK’s electoral registers stolen

Hacker

The UK’s elections watchdog has revealed it has been the victim of a complex cyber-attack potentially affecting millions of voters.

The Electoral Commission said unspecified ‘hostile actors‘ had managed to gain access to copies of the electoral registers, from August 2021. Note the word ‘unspecified’ is used – do they even know?

Hackers also broke into its emails and “control systems” but the attack was not discovered until October last year. The watchdog has warned people to watch out for unauthorised use of their data.

The commission said hackers accessed copies of the registers it was holding for research purposes, and for conducting checks on political donors. The commission knew which of its systems were accessible to the hackers, but could not ‘conclusively‘ identify which files may have been accessed.

‘Very sophisticated’ attack

The personal data held on the registers – name and address – did not itself present a ‘high risk‘ to individuals, it added, although it is possible it could be combined with other public information to ‘identify and profile individuals’.

It has not said when the hackers’ access to its systems was stopped, but said they were secured as soon as possible after the attack was identified in October 2022. Why was it left so long to be made public and how long did it take to make systems secure again?

Explaining why it had not made the attack public before now, the commission said it first needed to stop the hackers’ access, examine the extent of the incident and put additional security measures in place.Defending the delay, commission chair John Pullinger said: “If you go public on a vulnerability before you have sealed it off, then you are risking more vulnerabilities.” He is reported to have said the ‘very sophisticated attack involved using software to try and get in and evade our systems’. Well, that clearly worked then.

The world of digital data

He reportedly said that the hackers were not able to alter or delete any information on the electoral registers themselves, which are maintained by registration officers around the country. Information about donations and loans to political parties and registered campaigners is held in a system that is not affected by this incident, the notice added. He understood public concern, and would like to apologise to those affected.

Steps

The commission added that it had taken steps to secure its systems against future attacks, including by updating its login requirements, alert system and firewall policies. The Information Commissioner’s Office, which is responsible for data protection in the UK, said it was urgently investigating.

Labour’s deputy leader Angela Rayner reportedly said: ‘This serious incident must be fully and thoroughly investigated so lessons can be learned‘. Why wouldn’t it be investigated? I dislike it immensely when clueless politicians roll out this ‘standard remark’ as an attempt to demonstrate they ‘know what’s going on’.

Then what? It happens again and we have to… learn more lessons…?

Step up the security – we have the ability!