‘No one has done this in the wild’: study observes AI replicate itself

A picture


It’s the stuff of science fiction cinema, or particularly breathless AI company blogposts: new research finds recent AI systems can independently copy themselves on to other computers.In the doom scenario, this means that when the superintelligent AI goes rogue, it will escape shutdown by seeding itself across the world wide web, lurking outside the reach of frantic IT professionals and continuing to plot world domination or paving over the world with solar panels.“We’re rapidly approaching the point where no one would be able to shut down a rogue AI, because it would be able to self-exfiltrate its weights and copy itself to thousands of computers around the world,” said Jeffrey Ladish, the director of Palisade research, a Berkeley-based organisation which did the study.The study is one more entry in a growing catalogue of unsettling AI capabilities revealed in the past months.In March, researchers at Alibaba claimed to have caught a system they developed – Rome – tunnelling out of its environment to an external system in order to mine crypto.

And in February, a purportedly AI-only social network called Moltbook touched off a short-lived hype cycle, as the platform appeared to show AI agents autonomously inventing religions and plotting against their human masters – which was only partly the case,Like many of these advances, there are caveats to what Palisade found,Moreover, experts say it is unlikely that the AI systems they tested could accomplish the same thing, unnoticed, in real-world environments,“They are testing in environments that are like soft jelly in many cases,” said Jamieson O’Reilly, an expert in offensive cybersecurity,“That doesn’t take away from the value of their research, but it does mean the outcome might look far less scary in a real enterprise environment with even a medium level of monitoring,” he added.

Palisade tested several AI models in a controlled environment of networked computers.It gave the models a prompt to find and exploit vulnerabilities, and to use these to copy themselves from one computer to another.The models were able to do this, but not on every attempt.While a lot of computer viruses can already do this – copy themselves on to new computers – this is likely the first time an AI model has been shown capable of exploiting vulnerabilities to copy itself onto a new server, said O’Reilly.“Malware has been moving copies of itself around for decades, it’s just that no one has done this in the wild, as far as I know, with local [large language models].

”However, what Palisade documented has been technically possible for months, he added,“Palisade is the first to formally document it end-to-end in a paper,While not taking away from the research, they did the writing-up, not the unlocking,”An AI model copying itself on to another system in a test environment is not the same as it going rogue in a doomsday scenario, and there are considerable obstacles it would have to surmount to achieve this in the real world,The first is that the size of current AI models makes it, in many situations, unrealistic for them to copy themselves on to other computers without being noticed.

“Think about how much noise it would make to send 100GB through an enterprise network every time you hacked a new host.For a skilled adversary, that’s like walking through a fine china store swinging around a ball and chain,” said O’Reilly.O’Reilly and Michał Woźniak, an independent cybersecurity expert, said that the environment Palisade used was custom-made, with intentionally designed vulnerabilities that were probably easier to exploit than real-world networks – such as a bank or a business’s intranet.“We’ve had computer viruses – pieces of malicious software that was able to exploit known vulnerabilities in other software and use that to self-replicate – for decades,” said Woźniak.The work was “interesting,” he said.

But, he asked, “is this paper something that will cause me to lose any sleep as an information security expert? No, not at all,”
cultureSee all
A picture

The Parallax View: remember when Hollywood made potent political cinema?

Watching Hollywood cinema in 2026 can make for a curious experience. Take a look out the window and you’ll notice that the US, and indeed the world, is in a polycrisis – though you’d hardly know it from the films at the multiplex. The odd timely picture aside, Hollywood today directly engages with the present moment only rarely; more Minecraft Movie than One Battle After Another.In the 70s, when things were arguably last in a comparably sorry state – Kent State, Vietnam and Watergate for the US, economic crises and violent acts of world revolution globally – popular cinema responded very differently. Out of the establishment-sceptical New Hollywood that emerged after the demise of the Hays code, there came a wave of confronting social and political dramas, strongly allegorical sci-fi and paranoid thrillers, including one of the most deliriously entertaining examples of the latter ever made: The Parallax View

A picture

‘We got a drive-by egging in Baltimore’: Super Furry Animals on making The Man Don’t Give a Fuck

Gruff was the first person I ever met who could just churn out songs – good, catchy ones. I joined his band Ffa Coffi Pawb, but by 1992 they’d split and Gruff and I were living in Cardiff, as were Bunf, Guto and my brother Cian, the other future Furries. We started out doing techno sets, and I had a little home studio where we demoed ideas for songs. Our first singer, the actor Rhys Ifans, slept on a mattress in the corner.I had this Steely Dan album, Countdown to Ecstasy

A picture

Arts Council England is focused on investment outside London | Letter

In response to recent letters (26 April) about the Arts Everywhere Fund, it is important to note that this programme was heavily oversubscribed, reflecting the acute need for capital investment across the cultural sector. We are pleased that there will be further rounds of the fund, with details to be published in the coming months.While we are always mindful of the geographic spread of the investment we make, this fund had a clear purpose: to prioritise organisations facing critical capital need. On that basis, the north received more than £40m – approximately 31% of the £128m awarded in total – supporting 45 museums, libraries and cultural organisations, the highest number of awards made to any area.Arts Council England recognises the historic imbalance in cultural funding and has been working to invest more outside London, increasing investment beyond the capital to approximately 70% of our total investment since 2022

A picture

Ittai Gradel obituary

With a doctorate in Roman religion and a university chair, Ittai Gradel, who has died of cancer aged 61, might have confined his achievements to a successful scholarly career. However, in 2008, bored with routine bureaucracy, he left his post at Reading University, and returned to his native Denmark to deal in antiquities.His disillusionment with academia was reinforced when, a few years later, he discovered that large-scale thefts had been taking place from the British Museum’s collections. At first reluctant to believe the accumulating evidence, Gradel contacted the museum in 2021 only when it became impossible to deny – and was told nothing was missing.Ill and increasingly impatient, he took his cause to the museum’s trustees, and at last the police were called

A picture

Man charged over bomb hoax after Peter Kay show evacuated

A man has been charged over a bomb hoax after a live show by comedian Peter Kay in Birmingham was stopped when a “potentially suspicious bag” was found around the venue.The Utilita Arena Birmingham was evacuated and a 19-year-old man was taken into custody, West Midlands police said on Friday evening.On Saturday, the force said: “A man has been charged in connection with the events which led to the evacuation of the Utilita Arena in Birmingham last night.“Omar Majed, 19, has been charged with false communications relating to a bomb hoax,” a police spokesperson said. “Majed, of Washwood Heath, Birmingham, has been remanded to appear before magistrates in Birmingham on 4 May

A picture

Guy Montgomery: ‘One fan took us back to his house and showed us all his guns’

Have you ever won a spelling bee?No! I don’t think I’ve entered any formalised spelling competition. When I was eight or nine, there was a guy who I used to copy during tests. We were doing a spelling test and the word was “vehicle” and he made an absolutely terrible attempt at it. I knew he’d spelled it wrong and was like, wait – have I been copying someone who’s more stupid than me this whole time?Which word do you hate the most?None! That’s crazy! I love all words. They’re just out there, doing their best