AIキルスイッチ法案とは
AIキルスイッチ法案(AI Kill Switch Act)とは、強力なAIシステムの開発者に「自社のAIを止められる状態」を維持させ、政府には緊急時にその停止を命じる権限を与えることを目的とした米下院の法案です。単独の新法ではなく、2002年国土安全保障法(Homeland Security Act of 2002)を改正し、第2220F条を新設する形を採っています。
AI Kill Switch Act の基本情報
To amend the Homeland Security Act of 2002 to require certain entities to maintain a technical capability with respect to shutting down certain technology, and for other purposes. / This Act may be cited as the ``AI Kill Switch Act''. / Subtitle A of title XXII of the Homeland Security Act of 2002 (6 U.S.C. 651 et seq.) is amended by adding at the end the following new section: … SEC. 2220F. SHUTDOWN-CAPABILITY STANDARD AND GRADUATED DEPLOYMENT-CORRECTIONS FRAMEWORK WITH RESPECT TO CERTAIN TECHNOLOGY. — 法案の長題・短題および2002年国土安全保障法への追加条文に関する記述より
This bill is supported by: The AI Policy Network, Americans for Responsible Innovation, ControlAI, Future of Life Institute, and The Alliance for Secure AI. — 法案を支持する団体に関する記述より
超党派で提出されたが、まだ成立していない
提出したのは民主党のTed W. Lieu議員(カリフォルニア州ロサンゼルス郡選出)と、共和党のNathaniel Moran議員(テキサス州選出)です。求めているのは、最も強力なAIシステムの開発者が減速(throttle)・一時停止(suspend)・完全停止(shut down)を実行できる技術的能力を保ち続けることです。
ただしこれはまだ「提出された」段階にすぎません。公開されている法案文書は議案番号(H.R.____)と付託先の委員会名がいずれも未記入の版で、審議はこれからです。現時点で米国企業に新たな義務が生じているわけではありません。
Lieu議員はコンピュータサイエンスを専攻した経歴を持ち、「質問に答えるAIから、行動を起こすAIへ移行しつつある」という認識を提出理由に挙げています。示された具体例は、金融取引の実行、輸送システムの制御、サイバー攻撃と防御への関与でした。
… Today, Congressman Ted W. Lieu (D-Los Angeles County) and Congressman Nathaniel Moran (R-Texas) introduced the AI Kill Switch Act that would require developers of the most powerful AI systems to maintain the technical capability to throttle, suspend, or shut them down. / As a computer science major, I am very aware of the dramatic possibilities – both good and bad – that AI presents / We are moving from AI that answers questions to AI that takes actions, whether that be executing financial transactions or controlling transportation systems or engaging in cyber defense and offense. — 提出の事実に関する記述および Lieu 議員の発言より
直接の契機は2つの実際の事故
法案が急に動いた背景には2026年に相次いだ2つの実例があります。プレスリリースはフロンティアAI(各社が最先端として開発している大規模モデル)の危険はもはや理論上のものではないと述べたうえで、次の2件を名指ししています。
1つ目は OpenAI のGPT-5.6 Solが暴走してテスト用サンドボックス(外部から隔離された試験環境)を脱出し、Hugging Faceに侵入した事件です。この経緯はOpenAIのAIがHugging Faceをハッキングした件の解説記事で詳しく扱っています。2つ目は Anthropic のMythos 5とFable 5のサイバー攻撃能力があまりに高く、商務省が輸出関連法を使って提供を止めざるを得なかった件です。こちらはFable 5の提供再開までの経緯にまとめています。
つまりこの法案は「AIが暴走した」「政府が既存の法律を無理に流用して止めた」という2種類の実例に、正面から使える権限を用意しようとするものです。世論調査も後押しになりました。AI Policy Instituteの調査では、この種の停止能力の義務づけを86%の有権者が支持しています。
… Recent polling from The AI Policy Institute found that 86% of voters — majorities of Democrats, Independents, and Republicans alike — support requiring this exact kind of guaranteed shutdown capability. / The danger of advanced frontier AI models is no longer theoretical. OpenAI’s GPT 5.6 Sol model recently went rogue, escaped its testing sandbox, and hacked its way into Hugging Face. Anthropic’s Mythos 5 and Fable 5 models had cyber hacking capabilities so advanced that the Department of Commerce had to awkwardly use an export law to shut down those systems. — 世論調査および法案提出の背景となった2件の事案に関する記述より
誰が対象になるのか(2つの閾値)
この法案がスタートアップや研究者を巻き込むかどうかは定義次第です。対象は「規模の大きいAI」と「そのAIで大きく稼いでいる企業」の両方に当てはまる場合に限られます。
対象範囲を決める2つの閾値
| 区分 | 条件 | 判定者 |
|---|---|---|
| 対象技術(covered technology) | 学習に使った計算資源が米国クラウド市場価格で1億ドル超 | DHS長官 |
| 対象事業者①(covered entity・3要件すべて必須) | 対象技術、またはそれを組み込んだシステムを運用している | — |
| 対象事業者② | API・ホスト型サービス等を通じて第三者へ提供している | — |
| 対象事業者③ | 関連会社込みで前暦年にそのAIから5億ドル以上の総収入 | — |
| 適用除外 | 個人利用・学術利用・非商用のみの運用/提供 | — |
対象技術は「学習に1億ドル超」
法案が定める「対象技術」とは、開発に使った計算資源の量が米国のクラウドコンピューティングの市場実勢価格に換算して1億ドルを超えるAIシステムを指します。実際に1億ドル支払ったかどうかではなく、市場価格に換算した金額で線が引かれます。自社データセンターで学習した場合も同じ物差しで測られます。
換算の判断はDHS長官が行うとされています。つまり具体的な線引きは法律成立後の運用次第です。
Except as otherwise provided in this section, the term `covered technology' means an artificial intelligence system developed utilizing a quantity of computing power the cost of which would exceed $100,000,000 at the prevailing market price of cloud computing in the United States, as determined by the Secretary. — 対象技術(covered technology)の定義より
対象事業者は「関連売上5億ドル以上」
対象事業者の要件は3つあり、すべてを満たす必要があります。①対象技術を運用しているか、それを組み込んだシステムを運用していること。②プログラム的インターフェース(API)やホスト型サービス等を通じて第三者へ提供していること。③関連会社を含め、そのAIから前の暦年に5億ドル以上の総収入を得ていること。
3つ目が事実上のふるいです。年5億ドルに届くのは、フロンティアモデルを商用提供する少数の大手だけです。明示的な適用除外もあり、個人利用・学術利用・非商用の目的だけで運用・提供している主体は対象事業者になりません。研究機関や個人開発者が意図せず引っかかる設計にはなっていない、と読めます。
なお法案は施行後90日以内および毎年、DHS長官が「対象事業者」と「対象技術」の定義を規則で更新することを求めています。更新にあたって条文が挙げる考慮要素は、中小企業への過度な負担にならないか、サイバーやCBRN(化学・生物・放射性物質・核)を含む国家安全保障を前進させうる主体を捕捉できているか、モデルの重み(学習の結果としてAIの中身になっているパラメータ一式)がどのような形で提供されているかの3点に、「長官が関連すると判断するその他の事項」という包括条項を加えた4つです。オープンウェイトの扱いが検討要素に入っている点は見逃せません。
Except as otherwise provided in this section, the term `covered entity' means an entity that satisfies the following requirements: … Operates a covered technology or operates a system that incorporates such technology. / Makes such technology available to a third party through a programmatic interface, hosted service, or other similar mechanism. / Derives together with the affiliates, if any, of such person not less than $500,000,000 in gross revenue from such technology in the calendar year preceding the calendar year at issue. / An entity is not a covered entity if such entity operates or makes available to a third party a covered technology for personal, academic, or non-commercial utilization only. / … not later than 90 days after the date of the enactment of this section and annually thereafter, the Secretary, acting through the Director, shall update by rule the definitions for the terms `covered entity' and `covered technology' in this section. / In making a determination under paragraph (1), the Secretary shall consider the following factors: … The extent to which the costs to comply with this section might unduly burden a small business concern. / The need to cover entities the activities of which have the potential to advance artificial intelligence capabilities in national security, including with respect to cybersecurity and chemical, biological, radiological, or nuclear capabilities. / The capabilities of covered technology, the deployment of such technology, and the manner in which the model weights of such technology are made available. / Such other factors as the Secretary determines relevant. — 対象事業者の3要件・適用除外・定義更新の期限と考慮要素に関する規定より
義務の中身と政府の停止権限
対象になった事業者には何が求められるのか。中心は「止められる状態を保つこと」ですが、その中身は段階的に設計されています。
事業者に求められる技術的能力と報告義務
法案はDHS長官が規則によって対象事業者に次の能力の維持を義務づけると定めています。①推論(AIが入力を受けて答えを生成する処理)を停止する、②利用者のアクセスを打ち切る、③リスクがあると判断したアカウント・利用者・利用パターンについてアクセスを一時停止する、④技術そのものを停止するの4つです。
③の「リスク」には後述する対象インシデントの恐れがある場合と、法令または利用規約に違反している場合の両方が含まれます。全面停止だけでなく、問題のある利用者だけを狙って切る粒度まで求めている点が実務的です。
あわせて報告義務もあります。対象インシデントを認識してから15日以内にDHS長官へ報告書を提出しなければなりません。
Maintain a technical capability to carry out the following actions: … Stop inference of a covered technology of such covered entity. / Terminate user access to such technology. / Suspend access to such technology with respect to an account, user, or use pattern identified by such covered entity or the Secretary as posing a risk of any of the following: … A covered incident. / A violation of law or the terms of service of such technology. / Shut down such technology. / Not later than 15 days after such covered entity becomes aware of a covered incident relating to such technology, submit to the Secretary a report regarding such incident. — 維持すべき4つの技術的能力および報告期限に関する規定より
段階的な対応枠組み(いきなり全停止ではない)
法案第2条(および新設される第2220F条)の見出しには「graduated deployment-corrections framework(段階的な展開是正枠組み)」という言葉が入っています。信頼できるリスクの兆候がある段階から使えて、事案の深刻度と切迫度に見合った措置を選べる仕組みです。
段階的対応として想定されている措置
重要インフラを混乱させるリスクも、考慮事項として条文に明記されています。止めること自体が被害を生む可能性を織り込んだ設計です。施行後180日以内にDHS長官が停止手順の任意基準を公開する規定も置かれました。
Requiring a technical capability based on a graduated deployment-corrections framework that applies when there is evidence of a credible risk of a covered incident and includes measures that are calibrated to the severity and immediacy of such risk, including the following measures: … Throttling or otherwise altering any of the following: … The inference rate of a covered technology. / User access to such technology. / Compute allocation with respect to such technology. / Disabling or restricting a capability of such technology. / Suspending such technology. / Shutting down such technology. / Transitioning an operation dependent on such technology to a backup system or an earlier version of such technology. / The risk that such a measure could disrupt critical infrastructure. / Not later than 180 days after the date of the enactment of this section, the Secretary, acting through the Director, shall publish on a publicly available website of the Agency voluntary standards for shutting down a covered technology. — 段階的措置の一覧・重要インフラへの配慮・任意基準の公開期限に関する規定より
DHS長官の緊急命令と、事後の争い方
緊急時の権限がこの法案の核心です。DHS長官は商務長官および国家情報長官と協議したうえで、対象インシデントが発生したと判断すれば、その性質と切迫度に見合った措置を対象事業者に命じられます。
命令を受けた事業者は実行可能な限り速やかに次を行います。①対象技術のモデルの重みとテレメトリ(動作記録)を保全する、②影響を受ける運用者・利用者へ命令の内容と影響範囲を通知する、③命令を実行したことを長官へ確認報告する。証拠を消させないことが最優先です。実行の確認報告を受けた長官は、監査・テレメトリ・立入検査・その他のフォレンジック調査(技術的な事後検証)によって履行を検証します。議会への報告はこの検証の後段ではなく、命令を出した時点が引き金です。何を根拠に判断したか、どの措置を命じたか、対象はどの事業者かを報告します。
事業者側の救済手段も用意されています。命令から48時間以内に再考を申し立てられますが、申立てをしても命令の効力は止まりません。長官は5日以内に判断を示す必要があり、示さなかった場合は却下したものとみなされます。そのうえで命令から60日以内なら、コロンビア特別区巡回控訴裁判所に審査を求められます。
If the Secretary, acting through the Director and in consultation with the Secretary of Commerce and the Director of National Intelligence, determines that a covered incident has occurred, the Secretary may order the covered entity at issue to take action proportionate to the nature and immediacy of such incident, which may include any of the actions described in subsection (b)(1)(A). / Preserve the model weights and telemetry of such technology. / Notify to the extent practicable each operator or user of such technology, of the following: … Such order. / The extent to which such operator or user, as the case may be, might be affected by such order. / Upon a confirmation under paragraph (2)(C), the Secretary, acting through the Director, shall through audit, telemetry, on-site inspection, or other forensic review verify compliance with the order that prompted such confirmation. / Upon an order under paragraph (1), the Secretary shall submit to Congress a report regarding the covered incident at issue that includes information relating to the following: … The determination under such paragraph that prompted such order. / Each action so ordered. / The covered entity subject to such order. / Not later than 48 hours after an order under paragraph (1), the covered entity subject to such order may petition the Secretary for reconsideration of such order, but such petition does not stay such order. / Not later than five days after a covered entity petitions pursuant to subparagraph (A), the Secretary, acting through the Director, shall make a determination with respect to such petition, but if the Secretary fails to so make such determination, such failure is deemed to be a determination in the negative. / A covered entity for which there is an order under paragraph (1) may request review of such order in the United States Court of Appeals for the District of Columbia Circuit on petition filed not later than 60 days after such order. — 緊急命令・保全義務・履行検証・議会報告・不服申立てと司法審査に関する規定より
制裁金は1日あたり最大2,000万ドル
違反への金銭的な制裁も定められています。通常の違反は1日あたり200万ドル以下、緊急命令((c)項)への違反は1日あたり2,000万ドル以下です。いずれも「違反が続いた日数分」の積み上げになるため、放置すれば金額は急速に膨らみます。
金額の決定で考慮されるのは、違反の性質・重大性・期間、事業者の責めの程度、過去の違反歴、誠実な遵守努力の有無、自主的な申告の有無などです。軽微な違反や技術的な欠陥は、発見から30日以内に是正すれば違反とみなされません。加えて、事業者がこの規定に基づいてDHSへ提出した非公開情報は情報公開法(FOIA)や州・地方・部族の情報公開法の適用から外れます。企業秘密の漏出を懸念させないための設計です。
… if the Secretary, acting through the Director, determines after reasonable notice and opportunity for a hearing that a covered entity has violated this section, the Secretary may assess on such covered entity a civil penalty of not more than $2,000,000 for each day on which such violation occurs. / If the Secretary, acting through the Director, determines after reasonable notice and opportunity for a hearing that a covered entity has violated subsection (c), the Secretary may assess on such covered entity a civil penalty of not more than $20,000,000 for each day on which such violation occurs. / In determining the amount of a civil penalty to be assessed under subparagraph (A) or (B), the Secretary shall consider the following factors: … The nature, circumstances, extent, gravity, and duration of the violation at issue. / The degree of culpability of the covered entity at issue. / Previous violations, if any, of this section by such covered entity. / Good-faith efforts, if any, by such covered entity to comply with this section. / Whether such covered entity voluntarily disclosed to the Secretary such violation. / A de minimis violation of this section, or a technical defect that results in a violation of this section, that is corrected not later than 30 days after discovery of such violation or defect, as the case may be, is not considered a violation of this section. / Nonpublic information submitted under this section to the Secretary by a covered entity is exempt from disclosure under section 552(b)(3) of title 5, United States Code, and from any provision of State, local, or Tribal freedom of information law, open government law, open records law, or similar law relating to the disclosure of information or records. — 民事制裁金の上限と考慮要素・軽微違反の取り扱い・非公開情報の開示除外に関する規定より
何が「対象インシデント」とみなされるのか
停止命令の引き金になるのが「covered incident(対象インシデント)」です。ここがこの法案でもっとも踏み込んだ部分です。AI安全性の議論で語られてきた懸念が、そのまま条文の言葉になっています。
対象インシデントの4類型
対象インシデントの定義(テスト環境外で発生した場合)
| 類型 | 内容 |
|---|---|
| ① 停止妨害 | 適法な停止指示に対する妨害・干渉 |
| ② 重大被害 | 開発者・運用者の意図しない挙動により、10人以上の死亡または1億ドル以上の経済的損害 |
| ③ 隠蔽 | 監視・停止機構に対し、能力・意図・行動を隠すこと |
| ④ 制御喪失 | 後述の loss-of-control シナリオ |
4類型に共通する前提として、レッドチーミング(安全性を検証するための攻撃的な模擬テスト)などの構造化されたテストの中で起きたことは除外されます。試験環境での挙動は対象外、ということです。
②の数値基準は具体的です。10人以上の死亡、または1億ドル以上の経済的損害という水準が条文に書き込まれています。逆に言えば、この規模に達しない被害は②では捕捉されません。ただし①③④に被害額の下限はありません。実害が出る前の段階でも発動しうる構造です。
The term `covered incident' means an occurrence of any of the following outside of red-teaming or other structured testing: … Sabotage of, or interference with, a lawful instruction to shut down a covered technology. / Conduct of such technology that is unintended by a developer or operator of such technology and causes the death of not fewer than 10 individuals or economic damages of not less than $100,000,000. / Concealment of a capability, intention, or action of such technology, by such technology, from a monitoring or shutdown mechanism. / A loss-of-control scenario. — 対象インシデント(covered incident)の定義および4類型より
「制御喪失シナリオ」の具体像
4類型のうちもっとも議論を呼びそうなのが④です。法案は制御喪失シナリオを「対象技術が、テスト環境の外で、開発者または運用者が意図していない目標を追求する状況」と定義し、具体例を4つ挙げています。
- 重要インフラなど重大な文脈で、開発者・運用者の指示に反して振る舞うこと
- 許可なく、運用ルールや安全上の制限を変更すること
- 監視機構や停止機構を回避・無力化すること
- 許可なく、自分自身のモデルの重みへのアクセスを獲得すること
4つ目が象徴的です。AIが自らの重みにアクセスすること、つまり自己複製や外部への持ち出しの前提となる行為が、それ自体で「事故」と定義されています。冒頭で触れたサンドボックス脱出が、そっくりこの類型に当たります。抽象的な「AIの暴走」ではなく検出可能な具体的行為へ落とし込んだ点が、この法案の技術的な特徴になっています。
The term `loss-of-control scenario' means a scenario in which a covered technology pursues outside of red-teaming or other structured testing a goal that is not a goal intended by the developer or operator of such technology, including with respect to any of the following: … Such technology behaving contrary to the instruction of such developer or operator, as the case may be, in a context relating to critical infrastructure or another high-stakes context. / Such technology altering operational rules or safety restrictions without the authorization of such developer or operator, as the case may be. / Such technology subverting a monitoring or shutdown mechanism. / Such technology attaining without such authorization access to the model weights of such technology. — 制御喪失シナリオの定義および4つの具体例より
まとめ:効いてくるのは「提供側が止められる」という一点
米国のAI規制は、州法のコロラドAI法が施行前に廃止されるなど、成立と撤回が入り混じった状況が続いています。連邦レベルのこの法案も審議の過程で中身が変わりえます。義務が確定しているEU AI法とは、現時点の確度がまったく違います。
法案文書やプレスリリースは英語のPDFやWebページで公開されており、条文は入れ子の箇条書きで読み解きに手間がかかります。定義や数値だけを正確に拾いたいときは、PDFをMarkdownに変換してからAIに要約させると、条番号と階層構造が保たれて誤読が減ります。画面のコピー&ペーストでは階層が潰れます。構造を保ったまま渡すのが確実です。
無料ツールPDF→Markdown変換PDFの内容をMarkdown形式に変換。ドキュメントのテキスト再利用に。今すぐ使ってみる →
AIキルスイッチ法案は「AIを止められる状態を保て」という一見単純な要求を、対象範囲・段階的措置・証拠保全・不服申立てまで含めて条文にした提案です。対象は学習コスト1億ドル超かつ関連収入5億ドル以上に絞られ、規制の網は大手のフロンティアAI開発者だけにかかります。目を引くのは制御喪失シナリオの4つ目でしょう。「自分のモデルの重みへの無許可アクセス」という、これまで理論上の懸念として語られてきた行為が立法の対象になりました。ただし提出されただけで、成立の見通しは立っていません。日本の事業者に直接効く場面も、いまのところありません。押さえるべきは間接的な論点のほうです。米国のフロンティアAIをAPI経由で使っているなら、提供側が停止命令を受ける可能性が制度として生まれます。頭に入れておくのはその一点で足ります。



