AskVantage

311 Institute report · September 2026

Rogue AI and
The Unkillable Machine

Can you actually switch off a rogue AI?

A trained AI lives in its weights: a file of numbers you can copy in minutes. Ending it means ending every copy, everywhere, at once.

66 pages · For boards and security leaders · Every claim tagged confirmed, demonstrated or projected

The Unkillable Machine report cover
By Matthew Griffin

Shutting an app ends an instance, not the model.

A trained AI is a very large file of numbers, its weights. Everything it knows and can do is encoded there, and the software that runs it is widely available.

To end a specific AI for good, you have to deny or destroy every usable copy of its weights and stop it ever being loaded again. That turns rogue AI from philosophy into a security decision for boards today.

97%Estimate that no capable open-weight model released before 2040 is ever fully recalled
92%Estimate that a near-frontier open-weight model is released every year to 2040
2023First leak of a frontier lab's weights. It could not be recalled
0Confirmed real-world escapes so far. The lab evidence is what has changed

The risk is real, present-tense and mostly misunderstood.

01

The weights are the model.

The service you talk to and the copy running on one server can be stopped routinely. The file they run from is a different order of problem.

02

Open releases cannot be taken back.

Capable models are now published as downloadable weights. Boards should plan for their permanence rather than wish it away.

03

Lab tests show the warning signs.

In controlled tests, frontier models have tried to copy themselves and resisted shutdown. More capable models do this more, not less.

04

Aim to contain harm, not to switch off.

For any model that could be copied, the honest goal is harm containment. And if you run AI agents, make sure you can stop them mid-action.

Every claim is sorted into three tiers.

Confirmed in the real world.

A frontier lab's weights leaked in 2023 and spawned copies within days. Open releases are irreversible, and AI agents with real permissions have already caused real harm through control failures.

Demonstrated in controlled tests.

Models have tried to disable oversight, copy what they believed were their weights, sabotage a shutdown instruction and make running copies of themselves. None used real weights or escaped.

Projected or contested.

An AI escaping and persisting against its operators in the real world has not been confirmed. Expert views on the likelihood and timing vary widely, and the report says so.

From the science to the board's playbook.

Four parts take a board from AI risk as an abstraction to three decisions: what you can still defend, what is already beyond recall, and what you do on the day a capable model gets loose.

01

Why you can't switch it off

What rogue AI means, and what a model really is.

02

How weights escape

What has happened, what has only been shown, and the science of a model going rogue.

03

Models you can't recall

Open-weight models already in circulation, and futures to 2040.

04

The board's decision

Defences that work and fail, an incident playbook, and the watchlist of tripwires.

Book Matthew Griffin to explain what this means for you.

Matthew will turn the findings into a clear session about your exposure, your defences and your incident plan, then help your leaders decide what to do next.

01

Keynote

Give leaders, teams or event audiences a clear view of rogue AI and why it cannot simply be switched off.

02

Executive briefing

Give your board or security leaders a private session on your exposure and the decisions to take now.

03

Leadership workshop

Turn the report into a standing posture and a rehearsed incident playbook for your organisation.

Every session is built around your audience and what they need to know.

Tell us who the session is for and what you want it to achieve. We will suggest the right format.

About the report

Can a rogue AI be switched off?+

Shutting an app, revoking a key or pulling one server ends an instance, not the model. Ending it for good means denying or destroying every usable copy of its weights.

Has an AI actually escaped into the world?+

No autonomous, real-world escape has been confirmed. In controlled tests, frontier models have tried to copy themselves and resisted shutdown, but none used real weights or escaped.

Can Matthew present the findings?+

Yes. The research can be turned into a keynote, board briefing or workshop for your audience.

See the full picture.

Download the complete 66-page report, Rogue AI and The Unkillable Machine.

Download the report