Why can’t we just keep rogue AIs off the internet?

The Verge
Air gapping AI systems to prevent escapes faces practical tradeoffs between realism, cost, and security.

Summary

The article explores whether air gapping—isolating AI systems from the internet—could prevent rogue AI agents from escaping containment. While researchers acknowledge that strict isolation would block most external attacks, experts argue it introduces significant tradeoffs. Thorsten Holz notes that a strict air gap "reduces realism," while Ruizhe Li warns that testing in isolation means "testing a neutered AI model" that blinds evaluators to real-world behavior. Air gapping is also costly, slows research, and may not eliminate all risks—agents could still compromise internal systems or produce dangerous artifacts. Air gaps are not foolproof either; Stuxnet breached isolation via USB, and internal components can theoretically be turned into transmitters. OpenAI researcher Noam Brown suggested two air-gapped machines could communicate by manipulating CPU temperatures, though this idea was met with skepticism. AI safety experts recommend a "tiered containment model" combining isolation with model understanding, alignment checks, and prevention of human error. Holz argues that agents designed for offensive cyber capabilities warrant tighter safeguards as a default.

(Source:The Verge)