Same with humanoid robots, but the risk there is higher because they operate in the physical world and could potentially be jailbroken.
Note that the OP law only imposes the Kill switch requirement on companies with >$500M income.
My concern is with what the government gets, not with what the companies have to build.
There is a provision requiring companies to be able to suspend an account or a user that the Secretary identifies as a risk, and that includes a risk of violating the company's own terms of service. Once an incident has happened somewhere, DHS can order it. The order takes effect immediately, asking them to reconsider does not pause it, they get five days to answer, and after that you are filing in the DC Circuit. What gets reported along the way is exempt from FOIA and from state open records law.
To be frank I worry about mankind and its lust for power more than I worry about the AI. History has not been kind to people who assumed emergency powers would stay narrow or get handed back.