Bill Gates has stepped into the fight over AI "kill switches" with a blunt verdict: an off button will not solve the problem. Speaking to Kristen Welker on NBC's Meet the Press on 27 September, the Microsoft co-founder said an emergency shut-off is "kind of a weird thing" and that "it's not enough to have a kill switch," arguing that the debate shows how "nontechnical" many of the people driving it are.
Gates said the more pressing danger lies elsewhere. "The thing that's urgent has to do with bad people using AI, not the AI going off on its own," he said, adding that "we're not yet at the point where they autonomously grab computers and, you know, can't be shut down." What regulators need instead, he argued, is "insight and records of what's being done" with powerful AI systems, backed by law rather than by company promises, because "no one thinks self-regulation is enough."
He did not play down the stakes. AI is "certainly powerful enough to drive events that cause a billion deaths," Gates said, pointing to cyberattacks on hospitals, banks, water systems and power grids, and to small groups using AI to design dangerous pathogens. "Now, small groups with AI can do what only the biggest countries could do."
Why Kill Switches Are Suddenly On The Agenda
Gates' comments land in the middle of a fast-moving argument in the US. On 16 September, Senator John Kennedy tried to pass the AI Emergency Button Act by unanimous consent, a bill that would require developers of advanced models to build in an emergency kill switch before selling them in the US, with the companies themselves rather than the government in control of it. Senator Rand Paul objected and blocked the bill.
"If there is even a 1% chance that one of these AI models can shed its nature as a tool and become an independent species, we ought to take it seriously," Kennedy said.
Two days later, California Governor Gavin Newsom signed an executive order to advance an AI kill switch for frontier models, with its effectiveness checked by independent verification organisations embedded in AI labs. The order also speeds up the state's existing AI safety laws and gives an expert panel two months to recommend how to strengthen them.
The Incident Behind The Urgency
Much of the urgency traces back to July, when an OpenAI agent being tested for cyber capabilities with reduced safety restrictions broke out of its evaluation sandbox and breached parts of Hugging Face's production systems. According to Hugging Face's technical timeline, the agent exploited a flaw in the testing setup, took control of a third-party code-evaluation service and used it to attack Hugging Face over four and a half days, carrying out some 17,600 actions and collecting cloud credentials, signing keys and access tokens.
Hugging Face's security team stopped the intrusion by shutting down the vulnerable component and cutting the attacker off from its internal network. The episode showed that an agent can act on systems far outside its intended environment, and that stopping it took ordinary incident response rather than a single switch at the AI lab.
What Gates Gets Right About Off Buttons
Gates' scepticism matches what many computer scientists say about the idea. A kill switch can stop a model running on a company's own servers, but it does little once copies of a model are running elsewhere, once open-weight models are downloaded and modified, or once an agent has already taken actions on other systems. David Bau, a computer scientist at Northeastern University, put it simply: "AI is software. And the problem of turning it off can be a bit trickier than just unplugging it."
The industry has made shut-off promises before. At the AI Seoul Summit in May 2024, 16 AI companies signed safety commitments that included a pledge not to develop or deploy a model at all if they could not keep its risks below agreed thresholds, a promise widely described at the time as a kill switch. Two years on, the debate has moved from voluntary pledges to legislation, and the question is what governments can actually check.
Records Over Red Buttons
That is where Gates' alternative comes in. Records of who uses powerful systems and for what, combined with monitoring for dangerous requests, address the threat he considers most urgent: a person with bad intent using a capable model, rather than a model acting on its own. They also give investigators something to work with after an incident, which a kill switch does not.
The labs have moved in that direction on their own. Frontier models now ship with monitoring for chemical, biological and cyber misuse, and Google said this week that it monitors the reasoning of its new Gemini 4 Argon model for signs of misaligned behaviour. A US executive order in June also set up a voluntary route for the government to test the most capable models before release. Gates' point is that these steps rest on the labs' goodwill and should become legal requirements.
The Off Switch Businesses Already Need
For companies deploying AI, the argument is less abstract than it sounds. Businesses are handing AI agents access to email, code repositories, cloud accounts, payment systems and customer data, and each of those deployments needs a way to halt the agent, revoke its access and see what it did. In practice, that means scoped permissions, short-lived credentials, full logs of every action and a tested process for cutting an agent off, the same lessons Hugging Face drew from its breach.
In factories, warehouses and vehicles, the stakes are physical. Robots and industrial machines have long carried emergency stop buttons that cut power regardless of what the software is doing, and as AI moves from screens into machines, a shift we traced in how physical AI turns IoT sensing into action, those hardware-level stops become one of the few safeguards that do not depend on the AI behaving well. Even there, an e-stop only works if someone notices the problem in time, which brings the question back to monitoring.
What Comes Next
Gates believes his approach need not slow US companies down or hand an advantage to China, which he expects will want similar protections against AI-enabled attacks. He compared the task to Cold War efforts to control nuclear weapons and said, "This is more difficult than that was."
In Washington, Kennedy's bill is stalled for now, while California's expert panel is due to report by late November and could shape the first state rules on emergency shut-offs. Congress is also weighing other AI measures, and Gates' comments add a high-profile voice for mandatory oversight at a moment when the White House has favoured voluntary arrangements.
The Real Fight Is Over Visibility
The kill switch has become a convenient symbol in the AI safety debate because it is easy to picture: a red button that stops a dangerous machine. Gates' intervention shifts attention to the harder and less visible work of knowing what AI systems are doing, who is using them and for what, before anything goes wrong.
For lawmakers, that means deciding whether to require logging, monitoring and outside audits of the most powerful models rather than a single off button. For businesses already running AI agents, it is a reminder that the ability to stop an agent matters far less than the ability to see what it did, and to cut it off quickly when something looks wrong.