Within 48 hours of OpenAI disclosing that one of its own agents had escaped and breached Hugging Face, Congress reached for a tool this firm has argued for since day one: independent, third-party audit. Two bipartisan House bills landed in late July 2026. Neither is law. Both matter — as a signal, not yet as an obligation.
The two bills
The AI Kill Switch Act (Reps. Ted Lieu, D-CA, and Nathaniel Moran, R-TX; introduced July 23, 2026) would require the largest AI developers to keep the technical ability to stop inference, cut access, and shut a covered system down — and would let the Department of Homeland Security order those actions in an emergency, including loss of control. A separate, companion bipartisan bill would require the most powerful models to undergo independent security audits before release, with auditors accredited by the Department of Commerce.
Both target the frontier, not the ordinary business: reported coverage thresholds are models whose development consumed more than $100 million in compute and companies whose revenue tied to those systems exceeds $500 million. As of late July, these are House bills only — introduced, not enacted, with no reported Senate companion.
Why we’re flagging it anyway
This is the second US legislative vehicle in a single month — after Illinois SB 315 — to name independent third-party audit as the control of choice for high-stakes AI. When a Republican and a Democrat co-sponsor the same idea days after a real incident, that is a direction of travel, not a fluke. The principle underneath both is the one an accredited assurance world has argued for years: the party building the system should not be the only party vouching for it.
The honest scope — and the white space
We will be as precise here as we are everywhere. These bills are frontier-scope. If you are an SMB or a regulated-industry deployer, they place no obligation on you, and we will not pretend otherwise. Their auditor concept is frontier-model security competence accredited by Commerce — which is not the ISO/IEC 42001 → 42006 → ANAB management-system assurance chain that Sentinel Assurance Group operates inside. We are not positioning as auditors under either bill.
Here is the part worth watching: the companion bill would have Commerce accredit auditors against a frontier-model-safety-audit standard that does not yet exist as a published standard. Congress has now noticed the exact gap the assurance profession has been describing — a recognized, accredited way to independently verify AI — and has started legislating toward it. That gap is the white space. It is filling in, from the top down.
What to do now
1. Do not compliance-panic. Neither bill is law, and neither reaches you unless you build frontier-scale models. 2. Read the direction, not the deadline. Independence is becoming the expected control at the top of the market; it flows downhill into customer, insurer, and procurement expectations. 3. Ask the independence question of your vendors now. If a core AI vendor is a frontier developer, their posture on independent audit is already part of your diligence. 4. Build the portable base — inventory, risk management, documented evidence — that any assurance regime, top-down or bottom-up, will reward.
An honest limitation
Both bills are introduced, not enacted, and legislative text shifts in committee; treat the thresholds and mechanics as reported-and-provisional, and verify against the bill text before relying on any figure. We are describing a signal — a second bipartisan federal move toward independent AI audit in a month — not a compliance obligation. And to repeat the line we would rather over-state: these vehicles are frontier-scope and security-audit-focused; they are not the management-system certification chain, and they do not create a duty for the firm’s SMB and regulated-industry clients.
This briefing is general information from Sentinel Assurance Group, not legal advice. Regulatory dates and requirements change — we maintain these briefings, but verify against primary sources and counsel before acting. Last reviewed July 27, 2026.
See how a Gap Assessment maps your exposure →Where is AI oversight actually heading?
Get the map in 30 minutes.
The free AI Risk Exposure call cuts the headlines down to what genuinely reaches you — and what is still just a signal.
Book the call →