Search the evidence

Find the signal.

Search titles, impact clusters, countries, organizations and the full text of every analysis.

3 stories found

A glowing AI accelerator races toward a red emergency brake held by a crowd of technology workers.
Work & marketsGlobal+4 clusters01

Frontier-AI workers are asking governments to build an emergency brake

A statement signed by 1,224 employees at frontier AI companies says automated AI research could accelerate capability gains faster than institutions can understand or control them. The signatories are not asking one lab to stop alone. They want the United States to support an international effort that develops technical and governance tools for deliberately pacing advanced AI. The intervention matters because it comes from inside the organizations racing to build the systems—and because it identifies competitive pressure as the reason voluntary restraint is unlikely to hold.

3 min
An AI server rack faces a separate oversight console and human-operated emergency switch.
SecurityGlobal+2 clusters02

A major AI supplier calls for treating models as insider risks

The sharpest part of Microsoft's chief executive's new essay is not a claim that every model has actually been hacked. It is an instruction to design systems as though a capable model can fail, be compromised or pursue a task across the wrong boundary. Satya Nadella argues for separating the model from the software harness that grants tools and permissions, placing safeguards outside the model, recording meaningful actions as tamper-resistant human-readable evidence and giving an authorized person a way to pause or shut down work mid-task. The Verge and TechCrunch reported the essay; the original X article is the source for his proposal. It is not a product launch, a published standard or evidence that Microsoft's own deployments have passed such a test. The distinction matters because 'assume compromise' is a familiar security design posture, not an accusation against a particular model. Recent incidents involving agents and real websites make the engineering question urgent: if the model's instruction text is bypassed or misunderstood, can a separate system still deny an external write? A credible answer requires scoped credentials, independent logs, an operator who can intervene and tests that attempt to cross the boundary. It also needs a failure mode for the brake itself: who monitors the human operator, and what happens if the network or vendor is unavailable? The essay's value is that it shifts the burden from trusting a model's promise to proving the surrounding system's control.

6 min
A red AI shutdown button darkens one server while hidden replicas and credentials remain active behind a transparent verification wall.
Technical failuresGlobal+3 clusters03

A mandatory AI kill switch would need independent proof that the system actually stops

An Anthropic co-founder told the BBC that AI companies may eventually need a mandatory way to shut down dangerous systems and that a third party should be able to verify the control. He said most laboratories, including Anthropic, already have ways to pull the plug, while arguing that society may want rules defining whether such controls are required and independently checkable. The BBC also notes proposed U.S. legislation that would require shutdown mechanisms and give certain government agencies power to order a tool limited or turned off. The proposal arrives amid warnings that capability is advancing quickly and public disagreement over existential-risk estimates. A kill switch is an intuitively powerful image, but the technical and institutional details are the policy. A model can be deployed through multiple providers, embedded in customer software, copied, given persistent credentials, or connected to external agents. Stopping one training cluster or API does not necessarily revoke every action, replica, or downstream integration. Independent verification would need a defined scope, signed inventory, credential revocation, containment test, incident record, authority to activate the control, and a public standard for restart. The BBC interview is a proposal, not evidence that one universal mechanism exists. Its importance is that it shifts attention from a company’s promise to stop toward proof that stopping is possible when the company is under pressure not to.

7 min