Sato Hub
← Back to blogAndrew Yang Wants an AI Kill Switch. Onchain Agents Already Have One.

Andrew Yang Wants an AI Kill Switch. Onchain Agents Already Have One.

The federal proposal targets frontier models. The practical version of it already lives in the wallet layer.

2026-09-19 · 4 min read

Andrew Yang told CNBC on September 17 that Congress needs three things it doesn't have: authority to throttle or shut down frontier AI systems, liability rules that make companies answer for the harm their models cause, and mandatory waiting periods before the most powerful models ship. His pitch line: open a hot dog stand and you'll comply with "hundreds of regs." Ship a frontier model and you comply with none.

That's a clean soundbite about paperwork. The part that actually matters for anyone building onchain agents isn't the hot dog stand — it's the kill switch.

What Yang is actually asking for

Per the report, Yang's ask breaks into three pieces:

  • A kill switch — federal authority to shut down or throttle frontier AI systems.
  • Liability rules — companies on the hook for AI-caused harm, not shielded by "the model did it."
  • Waiting periods — a mandatory gap between a powerful model being ready and a powerful model shipping.

Yang says the concern is bipartisan and cited researchers who want guardrails because they "don't want to work on something that I think might cause" serious damage. He also pointed to an unnamed lab head's warning about self-replicating code planted across the internet by AI systems — a cyber-risk framing, not a chatbot-says-something-dumb framing. The proposal isn't uncontested: Musk-aligned voices including David Sacks have dismissed the safety-alarm framing as a "psyop," per the same report.

The category this is actually about

A model that writes a bad paragraph is a support ticket. A model that keeps signing transactions after something has gone wrong is a different problem entirely — and it's the one a "kill switch" is really aimed at, whether the word "agent" shows up in the CNBC segment or not. Self-replicating code and labor displacement are the headline fears, but the mechanism under both is the same: something is now acting with standing authority to do things, unattended, at machine speed. That's the whole premise of an onchain agent — a wallet, a set of permissions, and a loop that doesn't wait for a human to click "confirm" every time.

Which means the interesting question isn't whether Congress gets a kill switch for GPT-scale training runs. It's whether anything Congress builds actually reaches down to the layer where an agent's authority to *do* something lives — because that layer isn't the model. It's the wallet.

The kill switch that already ships

Here's the part frontier-model debates keep skipping: the agent economy already has a working, revocable, checkable kill switch, and it predates this news cycle by years. It's not a federal power — it's a permission grant. Session-key standards like ERC-7715 let a wallet hand an agent a scoped, time-boxed, spend-limited authority instead of a blank check, and revoking that grant is one onchain action, not an act of Congress. A policy that caps what an agent can spend, which counterparties it can touch, and how long its authority lasts is a kill switch you can point at a block explorer and verify — not a promise from a lab about what its next model will refuse to do.

That's a meaningfully different kind of accountability than "the company says it built in safeguards." A spend limit either held or it didn't. A permission grant is either still live or it was revoked. It's the same instinct behind the Trust Rule this site runs on: self-reported isn't verified, and "we added safety features" isn't the same claim as "here's the onchain record of the limit that stopped it."

None of this makes Yang's proposal irrelevant — model-level throttling and liability rules are aimed at a different failure mode (a frontier lab's training run, not a single agent's wallet), and the two aren't substitutes for each other. But if the next version of this debate wants to actually reach the agents doing things with money onchain, permissioned wallets and session-key standards are the layer it needs to engage with, not just the model weights.

What to watch

Watch whether any bill that comes out of this cycle — reporting already references an "AI Kill Switch Act" — engages with agent permissions and wallet-level controls at all, or stays entirely model-focused and leaves the part of the stack that actually moves funds unregulated by default. And watch adoption of session-key and spend-limit patterns in the meantime: while Congress debates a kill switch for models, the practical one for agents is already something builders can check today, not something they have to wait for.

Sources

  • [Andrew Yang Calls for AI Kill Switch as Safety Fears Mount](https://decrypt.co/378522/andrew-yang-ai-kill-switch-safety-fears) — Decrypt, September 17, 2026

Sources

Join the Sato Hub Briefing

One email a week — the agents, tools, and infrastructure that actually shipped, and why they matter.