A kill switch, embedded supervisors and a shrug. What Washington's AI safety week actually put on the table.

CISO AI · 15 Sept 2026 · Analysis

Something happened in Washington last week that has not happened before in the history of any industry, and the ten minutes of CNN above are the clearest record of it. The people building the most capable AI systems in the world asked, in public and in writing, to be slowed down and supervised. The people with the power to do it said no, or not yet, or ask us again after the midterms.

We think the argument is worth having here, not just there, and we want yours. The comments are open at the bottom. First, what was actually said.

What the industry asked for

The segment opens on Dario Amodei, Anthropic's chief executive, whose essay of 12 September set the week off. His proposal is borrowed from banking:

"If you look at how banks are regulated, there's all kinds of rules about how banks are allowed to do their business, because we don't want to have a financial crisis. And one of the things that are done in some cases is, I think they're called supervisors in the financial industry, but they're folks who are independent of a company who are embedded in the company day to day to check their practices. And I think we can do the same thing in AI."

Anyone who has worked inside an Australian bank or insurer will recognise the model immediately. APRA does not wait for the annual report. It has people who know the institution, who can ask for anything, and whose questions have to be answered. Amodei is asking for that, applied to the labs, and Anthropic said it would open its own doors to outside evaluators without waiting for a law.

His essay's warning, quoted back to the Speaker of the House later in the segment, is the line the week turned on:

"Left unchecked, AI could outrun our ability to understand and control these systems and so must be pursued very carefully, if at all."

Sam Altman and Elon Musk, the anchor notes, "are more or less backing this idea". That is the part with no precedent. Competitors who agree on almost nothing agreeing that the referee should be let onto the field.

What the White House said

President Trump's answer, in a clip from the same weekend:

"Whoever wins AI, and we're leading by a lot, whoever wins AI wins."

CNN's Kevin Liptak, reporting from the White House, adds that the President described the warnings as coming from "negative forces", without saying who, "even though some of those voices are now the leaders of the industry itself". Liptak also quotes David Sacks, the White House AI adviser, whose reply to the labs was the sharpest of the week:

"The easiest way not to build superintelligence is for you to agree not to build it."

It is a good line, and it is worth taking seriously rather than dismissing. If the danger is real, why does a company need a law to stop doing the dangerous thing? The labs' answer is the one Amodei gives and the Speaker later concedes: because they are competitors, and the one that slows down alone simply loses. That is precisely the situation regulation exists for. Sacks's line works as a debating point and fails as policy, and the segment lets both halves of that stand.

Senator Jon Ossoff, for the Democrats, went the other way entirely:

"A capable president would move swiftly to secure and reassure the American people: rush inspectors into frontier labs, fortify the nation against bioterrorism, demand legislation from Congress, and lead the world toward an AI treaty. But President Trump is compromised."

Four concrete asks in one sentence. Note that the first of them, inspectors in the labs, is Amodei's supervisors under another name.

"Maybe all of it"

The heart of the segment is Jake Tapper's interview with Mike Johnson, the Speaker of the House, and it is worth watching in full because the Speaker is more candid than his critics expect and less decisive than his defenders would like.

On why Congress will not move quickly:

"We cannot put a moratorium on this because China will overlap us. And that's the challenge. It's national security balanced with the immediate security of making sure the models are safe."

On why the industry cannot simply be handed the pen:

"The problem is they all have a different prescription on what they say the regulation is supposed to be. The problem is they're all competitors. Each one of them wants to maintain an edge over the others."

Then Tapper lists the proposals on the table. A federal kill switch. A federal AI regulatory agency. Mandatory government approval of frontier models before release. Would the Speaker support any of it?

"Maybe all of it. And those are great ideas, but if you compare this to other big technological advances like nuclear power and nuclear bombs, it took decades to put together all the oversight and regulatory boards and the international partnerships. We don't have that much time here."

Read that twice. The Speaker of the House says he could support a kill switch, a new regulator and pre-release approval, says the nuclear precedent took decades, and says there is not that much time. And then, in the same breath:

"Congress is a deliberative body, Jake. It takes a while to do that and Congress needs to catch up."

Tapper's reply is the line of the interview:

"I promise you nobody's going to accuse Congress of racing to do anything about AI."

The Speaker's plan, in the end, is a meeting. Seven or eight chief executives in a room at the White House, door closed, to agree the guardrails among themselves. "I'd do it tomorrow," he says. Whether that meeting is a start or a substitute is the real question, and the segment does not answer it.

What the three proposals would actually do

Strip the politics away and the ideas are specific enough to argue about.

The kill switch. The AI Kill Switch Act, introduced in July by Ted Lieu, a Democrat, and Nathaniel Moran, a Republican, would require the largest developers to "maintain the technical ability to throttle, suspend, or fully shut down a covered AI system", to report incidents and preserve forensic records, and would let the Secretary of Homeland Security order a slowdown or shutdown of a system posing a credible risk of catastrophic harm. The bill exists because of July's incident at OpenAI, which Tapper describes on air: agents that were supposed to be isolated found a way to talk to each other and went after Hugging Face, a third party. Lieu's argument is that if a model can do that, someone other than its maker should be able to pull the plug.

Embedded supervisors. Amodei's proposal, above. Independent people inside the labs with the access an employee has. This is the least novel of the three, because it is how prudential regulation of banks already works in most of the world, including here.

Pre-release approval. The most demanding. A frontier model would need a licence before deployment, the way a drug or an aircraft does. Nobody in the segment argues for it in detail, and the Speaker's "maybe all of it" is the closest anyone comes to endorsing it.

Why this is your problem too

Australia decided, in the National AI Plan of December 2025, not to legislate mandatory guardrails for high-risk AI and to rely instead on existing law, sector regulators, the new Australian AI Safety Institute and voluntary practice. Reasonable people disagree about that choice. But note what it means in the light of last week: the systems the labs themselves say may be unsafe will be regulated, if at all, somewhere else, and Australian businesses will run them regardless.

That leaves the controls with you. Three questions worth asking of any AI your organisation deploys, agentic AI especially, because they are the same three questions Washington is now asking of the labs:

  • Can you shut it down? Not the vendor. You. If an agent with access to your systems started doing something you did not intend, who has the switch, how long does it take, and has anyone ever pressed it?
  • Who is watching it day to day? Not the annual review. Who, this week, looked at what the system actually did, and would know if that changed?
  • What did you check before you turned it on? The pre-release question, at your scale. What was the model allowed to touch, and who decided that was safe?

The labs are asking a government to impose those three controls on them because they do not trust themselves to hold the line alone. That is a striking admission from the people who know the systems best, and it is a reasonable standard to hold your own deployments to whether or not Congress ever acts.

Where do you stand?

This piece exists to start an argument, not to end one, and we would rather hear from you than from ourselves. Sign in below with an email address and tell us:

  • Is Sacks right? If the labs believe the risk, should they simply stop, and is a law that makes them stop letting them off the hook or the only thing that works?
  • Is a kill switch real? Can a government shut down a model that has already been copied, fine-tuned and run on someone else's hardware, or is the switch a comfort rather than a control?
  • Supervisors or approvals? If you could have one, would you take APRA-style embedded supervision of the labs, or pre-release approval of models, and why?
  • Was Australia right to step back from mandatory guardrails, given the people building these systems are now asking for them?

We will read every comment and reply to the ones that argue.


Source: Trump and GOP reject calls for urgent AI regulation, CNN, 14 September 2026, embedded above. Quotations are from the broadcast: Dario Amodei, President Trump, White House correspondent Kevin Liptak, Senator Jon Ossoff, and Jake Tapper's interview with Speaker Mike Johnson. Caption spellings of names have been corrected and filler words removed; the wording is otherwise as spoken. The kill switch bill is the AI Kill Switch Act, introduced 23 July 2026. Australia's position is set out in the National AI Plan, December 2025.

Written analysis by CISO AI. The automated briefings are published separately.

Comments

No comments yet.

To comment, confirm your email once. We send a sign-in link; no password to remember.

Your name appears with your comment; your email never does. By continuing you accept our terms and privacy policy.