OpenAI told Representatives Greg Casar and Doris Matsui that it is “also developing additional automated shutdown capabilities” [E1]. The response is dated 31 August, signed by Chan Park, and was posted by Casar’s office; a 2 September wire reviewed it [E1][E2]. The sentence is developmental. It does not say a working, autonomous kill switch is in production [E1].
The same letter describes expanded chain-of-thought monitoring for unauthorized access, data exfiltration, deception and attempts to circumvent safeguards, and says that for the most severe alerts paged responders are expected to pause the relevant activity if they cannot conclusively call a false positive [E1]. It also says OpenAI improved sandbox isolation, restricted network connectivity, added independent network controls, and paused some frontier-model inference where models could execute code or use tools that could reach the internet [E1]. Those are human-gated pauses plus tighter boxes, sitting next to the shutdown sentence [E1].
The company had already put the destination in public on 26 August. Its incident post said it was building toward monitoring systems with tiered responses for misalignment, “with the end goal of having fully autonomous shutdown procedures for severe issues” [E3]. Automated alerts page researchers and security engineers; for the most severe alerts, responders should pause if they cannot establish within 30 minutes that the alert is a false positive [E3]. The congressional letter restates that program. It does not specify architecture beyond monitoring, a human pause, and eventual autonomy as an end goal [E1][E3].
Casar had asked for the logs. A 10 August oversight letter said OpenAI had yet to release relevant logs from the Hugging Face incident and set a 24 August deadline [E4]. The 31 August reply points members to the Black Hat talk, the 26 August blog, the technical report, METR, Redwood, Hugging Face and JFrog [E1][E5]. It does not attach incident logs [E1].
Casar’s 2 September follow-up called the response insufficient [E6]. “You have failed to release the logs like the letter asked,” he wrote, and said the unwillingness to provide the requested information signaled that the company was not treating the incidents with the required seriousness [E6]. He also said METR and Redwood had six days of supervised access, not a public dump, and could not see all model output or the periods before 26 June and after 13 July [E6]. Those gaps remain unanswered in his list [E6].
Three control layers are easy to collapse and should not be [E1][E7]. Lab containment automation is what the letter promises and has not finished [E1][E3]. OpenAI pausing its own runs is a company decision already described in the incident post [E3]. H.R. 9917, the AI Kill Switch Act introduced by Representatives Ted Lieu and others, would create a government order to shut systems down [E7]. The Park letter does not enact that bill [E1][E7].
The public record on 3 September is a sentence about additional automated shutdown capabilities, a human 30-minute pause already on the blog, and a member of Congress still asking for logs [E1][E3][E6]. The kill switch, if it arrives, will be three different machines. Only one of them is being built inside OpenAI [E1][E7].