What happens when the man warning that artificial intelligence could destroy civilisation decides that Washington’s cure may be worse than the fever?

Elon Musk, in Los Angeles on 14 September, offered a prescription: xAI, OpenAI, Anthropic, Google, Meta and a handful of leading Chinese companies should test one another’s systems before release. Four days earlier, Senate negotiators had been drafting something quite different—a legal duty to prevent catastrophic harm, backed by government auditors and the power to stop a model reaching the public.

They agree on the alarming diagnosis. Powerful AI needs slowing, testing and supervision. Their disagreement is elemental: who gets the brake pedal?

Engineers answerable to one another, or officials who must answer, eventually, to voters and courts. For Musk, back in the Los Angeles chair, the question hanging was simple: when a safety test fails, who has the authority to say no?

The Moment

The collision became difficult to dismiss on 11 September, when reports emerged that Senate negotiators John Thune, Ted Cruz and Amy Klobuchar were drafting a duty-of-care bill for the most powerful AI systems. It is an ordinary legal idea with an extraordinary application: the builder must take reasonable precautions against foreseeable harm.

The draft aims further than fines after disaster. Developers could be forced to disclose dangerous new abilities and their safeguards to the Commerce Department before release. If officials judged those precautions inadequate, the Commerce Secretary could seek a court order to halt the launch.

Simultaneously, Maria Cantwell pressed for national laboratories and security agencies, not the companies themselves, to conduct the testing.

Then, three days later, Musk offered his alternative. Leading American and Chinese labs should, he said, “work together and test each other’s models”. He proposed a shared test harness, a set of standard trials—akin to rival carmakers swapping vehicles for crash tests before customers get the keys.

That sequence matters more than any hearing-room quarrel, because no such personal confrontation has occurred. The real fight is institutional. Congress edges from voluntary promises towards an enforceable federal brake; Musk wants globally coordinated technical scrutiny that remains substantially industry-led.

Both sides want testing. Only one wants Washington able to halt the release.

Both sides want testing. Only one wants Washington able to halt the release.

What's Actually Happening

Congress has spent years producing AI proposals with the efficiency of a printer asked to work five minutes before a school deadline. By 14 September, more than 100 AI-related bills had been proposed, yet zero comprehensive federal AI safety laws had passed. The movement now isn’t from no interest to interest, but from general concern to mechanisms carrying legal force.

Consider the arc. The 20 March White House framework set seven legislative objectives, including child safety and infrastructure impacts. On 21 July, Mark Warner introduced the Secure Artificial Intelligence Development Act; it remains in committee.

In July, senators also revised a broader accountability proposal while preserving state powers.

The sharper turn arrived with September’s duty-of-care negotiations. A ‘frontier model’ here means one of the most capable systems being developed, not the chatbot answering routine questions on a shop’s support page. Senators are considering tests for whether such systems could assist nuclear or biological weapons work or sophisticated cyberattacks, paired with federal-court action when safeguards fail.

Think of the emerging regime as building control. Musk’s peer tests resemble architects checking one another’s calculations; Congress wants an inspector who can refuse the occupancy certificate. As Eleanor Voss, director of AI governance at Heisenberg Research Labs, advised during reporting, the decisive question is whether an independent party can inspect the failure threshold and enforce the consequence.

The shift is real because lawmakers are negotiating authority, liability and jurisdiction, not another ethics pledge. It is incomplete because the bill remains a draft, senators disagree over who tests, and Congress’s legislative record remains zero. Momentum is not enactment.

Washington occasionally confuses the two.

Federal AI policy moved during 2026 from broad objectives towards a draft power to stop releases.
Cutaway illustration of a nearly completed building, with architects examining structural models on one side and an independent inspector controlling the locked entrance on the other.

The emerging argument is not over whether frontier AI should be tested, but over who has the authority to keep a failed system from entering public use.

A safety test is not oversight unless an independent party can inspect the failure threshold and enforce the consequence.

— Eleanor Voss, director of AI governance, Heisenberg Research Labs

Who's Riding It

Dario Amodei arrived first at the current compromise. On 12 September, the Anthropic chief published “We Must Pace the Frontier”, proposing slower capability growth, embedded outside evaluators with broad company access and common standards developed with governments. “We must slow the pace at which we improve the capabilities of AI models,” he wrote.

Musk, Sam Altman of OpenAI and Demis Hassabis of Google DeepMind publicly backed the proposal by 14 September. That alignment serves each laboratory: it presents restraint as coordinated engineering rather than surrender to a regulator. Amodei reportedly argued that gaining an additional year or two before systems reach “critical levels” could reduce risk if the interval were spent improving safeguards.

It remains a proposal, not an audited slowdown.

Musk added the most politically awkward ingredient. Three or four leading Chinese companies should join xAI, OpenAI, Anthropic, Google and Meta in reciprocal testing. Safety failures do not respect flags, which makes the technical logic intelligible; American national-security controls make the practical arrangement considerably less cosy.

In Congress, Klobuchar works with Republicans Thune and Cruz on binding oversight. Cantwell pushes for tests run through federal laboratories and security agencies rather than company self-certification. Warner’s July bill supplies another route towards federal development standards.

The quiet beneficiary is the independent evaluator—specialists who attack a model deliberately, document what breaks and show whether fixes work. Whether employed inside laboratories, contracted externally or deployed by Commerce, that function is moving from optional reassurance towards evidence lawmakers may demand.

The Numbers

  • >100 bills — Congressional reporting counted more than 100 proposed AI-related measures by 14 September, but no comprehensive federal safety law had passed.
  • 0 laws — The same account found zero enacted comprehensive AI safety laws, the clearest measure of Washington’s delivery gap.
  • 7 objectives — The White House’s 20 March framework identified seven legislative goals, including child safety, infrastructure effects and third-party bias audits.
  • 3–4 firms — On 14 September, Musk proposed including three or four leading Chinese companies in reciprocal pre-release testing alongside major American laboratories.
Washington’s volume of activity has risen far faster than its production of binding AI safety law.
More than a hundred blank cream-coloured folders are stacked before a closed brass gate, with an empty lawbook stand visible beyond it.

Washington has generated AI proposals at scale, but not a comprehensive federal safety law.

The Hype Check

The phrase “AI kill switch” is irresistible and, at present, premature. September’s Senate language was still being negotiated; its path was described as unclear, with senators far apart over who should run tests. A court injunction is also not a red button on an official’s desk.

It requires a legal process, and companies could challenge a block in federal court.

Nor has Musk publicly attacked the Thune–Cruz–Klobuchar draft. His recorded comments concern peer testing and a coordinated slowdown, not the proposed veto power. Calling this a personal feud would mistake structural conflict for theatre—the technology business’s favourite conversion.

The industry plan deserves equal suspicion. A shared harness can reveal dangerous behaviour, but the available evidence does not establish common tests, disclosure rules, failure thresholds or penalties for ignoring results. Embedded evaluators may depend on the company paying them.

Cooperation with Chinese laboratories also raises unresolved national-security and technology-transfer problems.

Congress’s alternatives are hardly mature. The March data-centre moratorium bills, H.R. 9442 and S.4214, would freeze construction or upgrades until federal safety laws existed, but remained unpassed as of August. More than 100 proposals and zero comprehensive laws describe agitation, not governance.

The trend is the move towards enforceable brakes. The hype is pretending the brakes have been fitted.

The trend is the move towards enforceable brakes. The hype is pretending the brakes have been fitted.

How to Get Ahead of It

  • Map your release gate. Write down which dangerous capability would delay launch, who reviews the evidence and who can overrule the product team.
  • Practise red teaming. Learn to attack a system deliberately, record reproducible failures and explain the result without technical fog.
  • Test a harness. Compare the same hazardous prompts across models, preserve outputs and document whether proposed fixes survive repetition.
  • Track bill text. Watch scope, audit authority and court powers rather than reacting to the phrase “kill switch”.
  • Ask who can stop release. A safety promise without an independent decision-maker is customer service, not accountability.

The Call

By September 2027, the United States will probably have a narrower federal frontier-AI measure moving with serious bipartisan support. It will centre on mandatory disclosure, outside testing and court-backed intervention, rather than the sweeping data-centre moratorium proposed in March. Large laboratories, including xAI, will build compliance-shaped testing systems before passage because release delays are easier to plan than emergency audits.

Musk will support common tests and oppose, or seek to narrow, unilateral federal veto power. The collision will therefore become explicit even if no hearing supplies the expected fireworks.

The signal that would change this call is another year with no bill leaving committee and no published, independently verifiable cross-company testing scheme. That would reveal two rival performances rather than two governing models. For Musk, back in the Los Angeles chair, the question would remain unchanged: who can actually say no?

A brake nobody controls is decoration.