The drill, as reported

The scenarios are specific: a cyberattack, enabled or caused by AI systems, that takes down financial services, internet connectivity, or power and water infrastructure. The exercises reportedly include red-teaming potential failures, assessing autonomous-agent threats, and preparing responses to government intervention. OpenAI's spokesperson was careful to frame it as contingency planning: "OpenAI conducts emergency preparedness drills to help teams discuss and simulate a range of potential scenarios. These scenarios are not viewed as inevitable events, but rather as tools to help us prepare for various possible outcomes."

Two things are worth noting about that statement. First, nobody drills for a scenario they consider impossible. Second, the insiders Axios spoke to are not talking in geological time. Six to twelve months is a planning horizon, not a prophecy.

The other audience

Here is the part of the Axios story that does more work than the drills themselves: the labs are also gaming out the political aftermath, including public backlash and regulatory demands. The real product of these exercises may be the briefing, not the playbook. Get to Congress before a crisis, and lawmakers write the rules from a draft the industry has already read.

Congress does not have to start from a blank page. Reps. Ted Lieu and Nathaniel Moran introduced the AI Kill Switch Act in July, and it is unusually specific: covered systems are those from companies with at least $500 million in annual revenue or models trained on at least $100 million of compute. The Department of Homeland Security, acting through the CISA director and consulting the Commerce Secretary and the Director of National Intelligence, could order a slowdown, suspension or full shutdown when a system goes rogue, resists a shutdown order, or causes at least ten deaths or $100 million in damage. Defying an emergency order would carry civil penalties of up to $20 million a day. The bill also demands incident reporting and forensic record-keeping, so regulators can reconstruct what happened after the fact.

That is the bill. Not the law. The House version is still working its way through committee, and a Senate counterpart was blocked by Sen. Rand Paul. Proposed legislation reads very differently in a press release than in the statute book, and this one has not made it into the latter.

The footnote that swallows the bill

Even if H.R. 9917 passed tomorrow, read what it covers. It covers centralized, commercial frontier systems — the ones with a company, an API and an off switch. It does not cover open-weight models running on hardware nobody controls.

That is not a theoretical gap. CrowdStrike's recent casework on attacks against South Korean banks found an attacker allegedly using Chinese-developed models including DeepSeek alongside Claude Code to monetize stolen data. The attack stack was already a mix of open and closed tools. A government-ordered shutdown of frontier APIs does nothing to a model that has already been downloaded. Any honest kill-switch debate has to start there: the switch only works on the systems that agreed to have one installed.

What this means in practice

If you build on frontier APIs, expect the obligations in this bill — incident reporting, forensic logging, a maintained shutdown capability — to become contractual before they become legal. Cloud and API providers will pass them down to customers. If you run open-weight models, you live entirely outside this framework, which is either freedom or exposure depending on what happens in the next six to twelve months.

The drills tell you the labs have picked a timeline. The bill tells you what they want the rules to look like when the timeline arrives.

Sources

  1. [1] Axios reporting summarized by ODSCRead source
  2. [2] Startup Fortune analysisRead source
  3. [3] Political Wire summaryRead source
  4. [4] Bill text breakdown (H.R. 9917)Read source
  5. [5] Deep dive on the kill-switch mandateRead source