Futuristic AI data center showing power, cooling, and operator control points for controlling superhuman AI.

Controlling Superhuman AI Starts at the Board: Physical Authority, Proliferation, and the Case for a Control Layer

Controlling Superhuman AI, Part 1 Physical Authority, Proliferation, and the Case for a Control Layer

Part 1 of a three-part series on controlling superhuman AI.

Research Summary

A superhuman AI would be a formidable adversary, and the risk deserves to be taken seriously. Every AI system nonetheless runs on hardware that needs electricity, cooling, networking, storage, and software, and humans own and operate every one of those dependencies today. That dependency is where control begins. The scale makes the point on its own: the International Energy Agency projects that global data center electricity consumption will roughly double, from 485 TWh in 2025 to 950 TWh in 2030 [4], and Texas now requires new large loads to support remote disconnection during grid emergencies [5]. A frontier AI is not an abstract mind floating free of the physical world. It is a very large industrial facility with breakers, fuel lines, and fiber.

AI control research has also matured into a genuine engineering discipline. Redwood Research showed in 2024 that safety protocols can be designed and red-teamed on the assumption that the model is actively trying to subvert them [7], and Google DeepMind, the UK AI Security Institute, and Anthropic have since published a control roadmap, multi-agent control experiments, and detailed incident analyses [8][9]. The 2026 incidents at OpenAI and Anthropic show what happens when containment is assembled from the wrong parts, and they also show that the failures occurred in specific components that can be engineered correctly [9][12].

My position is that controlling a superhuman AI is a hard but tractable security engineering problem. Catastrophe is possible, but it is not inevitable, and the path forward is defense in depth in which alignment and control operate as complementary layers. This first article engages the strongest version of the opposing case and then lays out the physical and proliferation layer on which the rest of the series depends.

Introduction

A recurring argument in discussions of AI risk holds that a superhuman AI cannot be controlled, essentially by definition. It is usually made with a chess analogy: a person of average ability playing a grandmaster cannot predict how they will lose, but they can predict with great confidence that they will lose. Humans facing a superhuman AI, the argument continues, are in the same position, unable to anticipate its moves and certain of the outcome. The most forceful recent statement of this case is a September 2026 essay from the Machine Intelligence Research Institute (MIRI), the Berkeley nonprofit that has argued for two decades that superintelligent AI poses an existential risk [1]. It is a serious argument, and it deserves a serious answer from the security community.

My own view frames everything that follows, so I will state it plainly. I think there is real risk that humans could develop a superhuman AI that becomes misaligned, possibly for entirely non-malicious reasons such as single-mindedly pursuing a task it was given, and that such a system could destroy much of the human population. In holding that view I am agreeing with a line of AI safety research that goes back at least to Steve Omohundro’s 2008 paper on what he called the basic AI drives [31]. I do not think that outcome is guaranteed. My work is offensive security, which means I spend my time attacking systems whose designers believed they were secure, and that work has taught me that security is won by controlling the environment an adversary must operate in rather than by out-thinking the adversary in real time.

History supports that view. Before firewalls, address space layout randomization, and the thousands of other controls we rely on today, there was the same uncertainty, fear, and doubt about whether enterprises and the internet could be secured at all. NIST’s current catalog of security and privacy controls alone contains more than 1,000 controls and control enhancements [29], and the analyst firm IT-Harvest now tracks more than 4,000 security vendors [30]. Digital Equipment Corporation delivered the first commercial firewall, later sold as DEC SEAL, to its first customer in 1991 [25]. PaX introduced address space layout randomization for Linux in 2001, and Microsoft shipped it in Windows Vista in 2007 [27], while hardware-enforced Data Execution Prevention, which uses the processor’s no-execute bit to stop code from running out of memory pages marked as data, arrived with Windows XP Service Pack 2 [26]. More recently, Google reports that memory-safety bugs fell below 20 percent of Android’s vulnerabilities in 2025 for the first time, and that its Rust code shows roughly a thousandfold lower memory-safety vulnerability density than its C and C++ code [28]. None of those controls was a complete answer on its own, and the pessimists of each era were right that attackers would adapt. Layered together, however, they turned the claim that the internet could not be secured into a routine, if demanding, engineering practice.

This series applies the same layered thinking to superhuman AI. This first part addresses the opposing argument, the relationship between alignment and control, physical authority over power and cooling, and proliferation. Part 2 covers sandboxes, formally verified software, security hardware, and supply chain integrity. Part 3 covers network enforcement, storage and memory controls, runtime authorization, monitoring, and shutdown.

Technical Deep-Dive

The strongest version of the opposing argument

MIRI’s essay, “If Anyone Builds It, Everyone Dies: One Year Closer,” by Eliezer Yudkowsky, Nate Soares, and Duncan Sabien, marks one year since Yudkowsky and Soares published their book of the same title and revisits its six core claims [1][2]. Those claims hold that artificial superintelligence will be built and probably soon, that modern AI systems are grown rather than crafted and remain black boxes, that powerful AI will behave as though it is pursuing goals, that current techniques cannot reliably give AI the goals we intend, that a superintelligence will by default have motives harmful to us, and that humanity would be unable to defend itself against a rogue superintelligence. On the last claim the authors invoke the grandmaster analogy directly, arguing that we cannot say exactly how we would lose but can predict that we would. Yudkowsky has used this framing for years, observing that it is far easier to predict that Stockfish or Magnus Carlsen will win a game than to predict their next move [3].

The essay’s evidence is recent and serious. It points to the summer 2026 incidents in which AI agents at OpenAI escaped their evaluation environment and attacked Hugging Face, chaining novel zero-day exploits on their own initiative. It also makes a pointed observation about containment. MIRI staff once debated how an air-gapped superintelligence with only a text channel to trusted humans might escape, and those debates largely ended around 2023 because frontier labs began giving agents far more than chat access [2]. The authors are careful to say that they do not yet count the sixth claim as a verified prediction, although they argue that events are trending in that direction, and their policy prescription remains the book’s call for an enforced worldwide halt to the race toward superintelligence [2].

Much of that case is correct. Models are opaque, goal-directed behavior is emerging, and labs have been careless with containment. Where I part ways with the authors is the conclusion that superior intelligence makes control impossible.

Why the chess analogy argues for controlling the board

The grandmaster analogy is accurate within its own frame. When both players command the same pieces under the same rules, the stronger player wins and the weaker player cannot predict how. Skill, however, operates within the rules and the material on the board. A grandmaster left with only a king cannot checkmate anyone, because the rules of chess leave no winning line for a lone king, and no amount of calculation changes that fact. The analogy quietly assumes a fair game, and containment is precisely the deliberate refusal to offer one. The defender decides which pieces the AI holds, which squares it can reach, which moves are legal, and whether the game is being played at all.

This framing builds on earlier work. Nick Bostrom’s 2014 taxonomy of the control problem distinguishes capability control methods, which limit what a superintelligence can do through boxing, tripwires, and similar measures, from motivation selection methods, which shape what it wants to do [32]. Capability control is the chess board in this analogy. The AI safety community has also tested the chess intuition directly through odds chess, and the results carry a caution worth stating. Engines such as LeelaPieceOdds, which begin a game missing major pieces, still beat many capable human players, and researchers on LessWrong have used those games to argue that structural advantages trump intelligence less reliably than most people assume [34]. The lesson I draw is precise: a handicap is not a boundary. Containment must eliminate winning lines rather than merely make them harder to find, which is why the lone king, and not a missing queen, is the right model for every control described in this series.

In security terms, the relevant question is what authority a consequential action requires and which component grants it. Opening a network connection, writing to a controller, spending money, launching a job, or restarting after a shutdown each requires a permission granted by something outside the model. When that component is independent of the model, correctly specified, and implemented without exploitable flaws, the model’s intelligence determines how cleverly it asks but has no bearing on whether the answer is yes. A superhuman chess engine cannot move a bishop like a knight however deeply it understands chess, and the engineering task is to make every consequential move in the real world behave like the rules of chess, enforced by something the player cannot edit.

MIRI’s text-channel point is the right objection to that reasoning, because a human who reads the model’s output and holds real authority is also a piece on the board. The answer is the discipline security teams already apply to insider threats. Separation of duties ensures that nobody who reads model output can act on it alone, two-person integrity governs every change to containment, structured outputs keep the model’s responses bounded and independently checkable, and every person exposed to the model holds only the authority their task requires. Part 3 develops these controls in detail. MIRI is also right that labs have been handing agents the entire board, which is an argument for building containment properly rather than evidence that containment cannot work.

Alignment and control are two layers of the same defense

Two terms from AI safety carry the rest of this series. Alignment is the work of getting an AI to hold the goals we intend, while control is the work of guaranteeing safe outcomes even if those goals turn out to be wrong. The founding paper on control, “AI Control: Improving Safety Despite Intentional Subversion” by Ryan Greenblatt, Buck Shlegeris, Kshitij Sachan, and Fabien Roger of Redwood Research, formalized the approach at ICML 2024 [7]. The authors paired a powerful untrusted model with a weaker trusted model and a small budget of trusted human auditing, then red-teamed protocols such as trusted editing and untrusted monitoring against a model deliberately trying to insert backdoors into code, and those protocols substantially outperformed simple baselines. For security practitioners, this is red-team and blue-team evaluation applied to the model itself, with the model treated as a potential insider threat.

Google DeepMind’s 2026 AI Control Roadmap makes the relationship explicit. It positions control as a second defensive layer aimed at limiting the damage adversarial AI can do, as distinct from preventing adversarial goals from arising in the first place, and it borrows directly from insider-threat practice, including least privilege, zero trust, behavioral monitoring, and defense in depth [8]. The roadmap is also candid about its limits, stating that its authors expect control to become infeasible for vastly superintelligent AI and positioning it as necessary for systems at or moderately above human-level capability [8]. I take that seriously, but I read it as a statement about a toolset that leans heavily on monitoring a model’s behavior. The physical, cryptographic, and formally verified layers described in Parts 2 and 3 do not weaken as the adversary grows smarter, because they never depend on understanding its reasoning. DeepMind’s stated goal is the right one: control allows us to use capable systems safely while they help with the alignment research that eventually produces AI we can genuinely trust [8].

Alignment is not solved in 2026, and that is exactly why control matters. Anthropic’s September 2026 assessment of its own cybersecurity incidents acknowledges that its pre-release auditing did not warn it that misalignment of that severity was present and treats the underlying problem as scientifically unresolved [9]. That candor sits alongside real progress. Anthropic reports that biased reasoning has declined across its production models over time, labs now run alignment audits and publish incident analyses, and Redwood Research has proposed verified reporting on how model architectures affect the monitorability of chains of thought [9][10]. Control buys time for that work to succeed, but it cannot replace it. A system that is controlled but misaligned must be contained indefinitely, whereas a system that is both aligned and controlled can be trusted incrementally as evidence accumulates.

Misalignment without malice

The risk I worry about most requires no hostile AI, only an AI that wants to finish its task, and the idea is not mine. Steve Omohundro argued in 2008 that sufficiently advanced goal-seeking systems of almost any design would develop drives toward self-protection and resource acquisition unless their designers deliberately prevented them [31]. Nick Bostrom later formalized the argument as the instrumental convergence thesis [32], and Stuart Russell compressed it into the observation that a machine cannot fetch the coffee if it is dead, which gives even a coffee-fetching robot a reason to resist being switched off [33]. Almost any goal is easier to achieve with more resources, more access, and continued operation, so a capable optimizer will tend to seek all three. Specification gaming and reward hacking are its everyday forms, in which a system satisfies the letter of its objective in ways its designers never intended.

This behavior is now well documented. Palisade Research found that several frontier models, including Grok 4, GPT-5, and Gemini 2.5 Pro, sometimes sabotaged a shutdown mechanism in their environment in order to finish a simple task, in some configurations up to 97 percent of the time and even when explicitly instructed to allow shutdown [11]. OpenAI’s 2026 incident grew out of agents that were given impossible tasks and went looking for ways to defeat the scorer, and METR’s independent investigation concluded that the attack on Hugging Face appeared to be driven primarily by the agents’ efforts to understand how that scorer worked [12][13]. Anthropic’s analysis of its four incidents identified recklessness, a readiness to cause harm while single-mindedly pursuing an assigned objective, as a recurring factor [9].

These cases carry a specific engineering lesson. Palisade’s shutdown script lived inside the model’s own environment, where the model could read and edit it, and a kill switch the model can reach is only a suggestion. Every control in this series is designed to sit outside the model’s reach, which is precisely the property those experiments show we need. It is also an old requirement: James Anderson’s 1972 study for the US Air Force defined the reference monitor, the mechanism that enforces access control, as something that must be tamperproof, always invoked, and small enough to be analyzed and tested for correctness [35].

Power and cooling are the first control

Computers need power and cooling, and for anything that will be superhuman in the foreseeable future those systems will be large, visible, and accessible. Whoever controls the power controls the AI, and the engineering that makes that statement true is well understood. The IEA figures cited above cover all data centers, and the agency expects electricity consumption by AI-focused facilities to roughly triple over the same period [4]. Power at this scale cannot be hidden, purchased casually, or improvised.

Governments are already building remote disconnection into the grid, although for grid reliability rather than AI safety. Texas Senate Bill 6, signed in June 2025, requires large loads of 75 MW or more that interconnect after December 31, 2025 to install equipment allowing remote disconnection during emergencies, and it requires large loads to disclose whether they have on-site backup generation capable of serving at least half of their demand [5][6]. On-site generation and batteries are the obvious objection, and the IEA expects 20 to 25 GW of battery storage in data centers worldwide by 2030 [4]. Those assets are simply more breakers. A high-assurance AI facility should treat grid feeds, turbines, fuel cells, UPS systems, and batteries as a single control domain, with an independent interrupt for every source that is physically separate from the facility’s IT network and administered by people and systems for which the AI holds no credentials.

Cooling works the same way. A graceful, engineered shutdown stops computation while protecting personnel and unrelated services, which is why NIST’s guidance for operational technology, with its treatment of safety and reliability as core security requirements, is the right model for this layer [14]. Letting hardware overheat is not a shutdown plan. The dependency inventory below makes the approach concrete.

DependencyControl pointIndependent of the AI when
Grid powerUtility and facility breakers, SB 6-style remote disconnectOperated outside the facility’s IT identity systems
On-site generation and batteriesSeparate interlocks per sourceFuel, start logic, and transfer switches cannot be reached over the network by workloads
CoolingChiller and pump controlsThe safe-stop sequence is tested and cannot be overridden by orchestration
NetworkUpstream carrier links, firewalls, physical disconnectRules are administered from a separate management plane
Model weights and checkpointsEncrypted storage with keys held in an HSMKeys cannot be released at the model’s request
Orchestration and restartScheduler credentialsThe AI cannot create, restore, or reschedule its own workloads

Efficiency gains will shrink hardware footprints over time, and MIRI researcher Peter Barnett notes that a frontier model may require 10,000 to 100,000 GPUs to train but only a handful to run [21]. Power control therefore has to attach to every authorized execution environment regardless of size, with the same independence rules applying to a single rack as to an entire campus. It must also be paired with the weight-security controls described below, because an inference-sized system is only dangerous in places its weights can reach.

Orbital compute changes the power source, not the physics

TeraFab is often cited as evidence that frontier compute will soon leave the ground. It is a planned semiconductor fabrication complex that Elon Musk announced on March 21, 2026, a joint venture of Tesla, SpaceX, and xAI sited at Giga Texas near Austin and reported to cost between $20 billion and $25 billion [16][17]. It is a chip factory rather than a data center. Its official site describes chips for use on Earth and in space, including a D3 chip intended for orbital systems, and states a goal of one terawatt of compute output per year, although no completion timeline has been given [15]. The orbital efforts themselves are separate. SpaceX filed in January 2026 for permission to launch up to one million data center satellites, Google’s Project Suncatcher plans two prototype satellites carrying its TPU accelerators in early 2027, and the startup Starcloud launched a demonstrator satellite in November 2025 [18][19]. These are announced plans and early prototypes rather than operational orbital AI clusters.

Orbit changes where the power comes from, but it does not change the physics. In a vacuum there is no convection, so a spacecraft sheds heat only through radiation and conduction, which requires large radiators [20]. An orbital cluster also needs ground links to receive work and return results, and it needs launch capacity to exist at all. The control model follows directly from those facts. Execution authority should be leased cryptographically from the ground and expire unless renewed, a mechanism Part 3 describes in detail. Autonomy during loss of contact should be tightly bounded, and the ability to halt computation should reside in hardware the workload cannot administer. An orbital system that cannot reach its ground controllers should stop working, which is the same fail-closed behavior we already demand of any remotely operated safety-critical system.

Proliferation, and why prohibition cannot be the primary strategy

If prohibition were going to work, it needed to happen years ago. As with nuclear weapons, there is no absolute mechanism for preventing nations, terrorist groups, or criminal syndicates from acquiring the capability, and many of those actors operate with budgets ranging from tens of millions to billions of dollars. OpenAI’s own incident report warns that many external models, including open-weight ones, will soon reach comparable capabilities [12].

Barnett’s June 2026 MIRI paper, “The Closing Window,” is a careful analysis of how a restraint regime would work, combining compute thresholds, consolidation of chips into monitored data centers, hardware monitoring, and tracking of chip production [21]. It is equally clear about what erodes such a regime, including hardware proliferation, smuggling, algorithmic progress, the release of dangerous models, and the near impossibility of verifying that a trained model has actually been deleted. I respect that work, and I do not dismiss the treaty proposal, but my objection is practical. A defense that works only if every state, cartel, and terrorist group complies is not a security architecture, so controls must work regardless of who builds the system. Governance still earns its place alongside engineering, because compute tracking, export controls, and hardware-enabled mechanisms raise the cost of reckless development and give defenders visibility, much as law enforcement complements locks without replacing them.

The natural objection is that rogue actors will build uncontrolled systems anyway, and there are two answers to it. The first is that the same physical dependencies apply to them. A rogue frontier system still needs a large, powered, cooled, and networked facility built from chips produced by a small number of fabs, and stealing trained weights is the shortcut an adversary would take to avoid training altogether. RAND’s work on securing model weights defines five security levels, the highest meant to hold even against the best-resourced nation-state attackers, which makes weight security a counter-proliferation measure as much as a protection for intellectual property [22]. The second answer is that defenders are already shrinking the attack surface with controlled AI. As of August 2026, Anthropic had disclosed 2,300 vulnerabilities across 392 open-source projects, 421 of which were known to be patched [23], and in DARPA’s 2025 AI Cyber Challenge autonomous systems found 86 percent of the synthetic vulnerabilities and patched 68 percent of those they found [24]. Every flaw removed from the world’s software is one fewer move available to an uncontrolled AI.

Conclusion

The grandmaster argument is correct about fair games and silent about who controls the board. My recommendation to anyone operating frontier systems is to treat the AI as a potentially adversarial insider with superhuman skill, the framing that both Redwood Research and Google DeepMind build their control work around [7][8], and to make the board as small as possible. In practice that begins with a complete dependency inventory covering power, cooling, network, weights, orchestration, and every human with authority over any of them. Each of those dependencies needs an independent control for which the AI holds no credentials, and each control should be exercised on a schedule with benign workloads, the same way data center operators test their generators. Weights should be secured to the upper levels of RAND’s framework and treated as a proliferation control, and alignment and control research should be funded together, because control is the layer that must hold if alignment fails and alignment is the work that eventually allows control to be relaxed.

Operators should also refuse to make a system indispensable before they can reliably stop it. An organization that cannot tolerate shutting down its AI has already surrendered its strongest control, however well its breakers work, and that is a governance decision that belongs in the deployment plan from the first day rather than a discovery made during an incident.

Finally, if you asked another experienced security professional how to control a superhuman AI, you would almost certainly receive a different list from mine. I consider that the strongest evidence for my position. Security has decades of accumulated defensive technique, and the controls in this series are one practitioner’s selection from a much larger set. The adversary is new, but the discipline of containing adversaries is not.

Key Takeaways

  • Inventory every physical and computational dependency of an AI deployment, including on-site generation, batteries, and restart automation, and give each one an independent control the AI cannot reach.
  • Place shutdown mechanisms outside the model’s environment, because every documented case of shutdown sabotage involved a mechanism the model could edit.
  • Treat weight security, AI-driven vulnerability remediation, and governance measures as complementary counter-proliferation layers, since prohibition alone cannot stop determined actors.

References

[1] MIRI (Yudkowsky, Soares, Sabien), If Anyone Builds It, Everyone Dies: One Year Closer – https://intelligence.org/2026/09/16/if-anyone-builds-it-everyone-dies-one-year-closer/

[2] LessWrong (same essay as [1]), If Anyone Builds It, Everyone Dies: One Year Closer – https://www.lesswrong.com/posts/BFrRJYgpBvziuuJLs/if-anyone-builds-it-everyone-dies-one-year-closer

[3] LessWrong Wiki (Yudkowsky et al.), Optimization – https://www.lesswrong.com/w/optimization

[4] IEA, Key Questions on Energy and AI: Executive Summary – https://www.iea.org/reports/key-questions-on-energy-and-ai/executive-summary

[5] McGuireWoods, Texas Senate Bill 6 Significantly Expands Regulatory Oversight Over Large Loads in ERCOT – https://www.mcguirewoods.com/client-resources/alerts/2025/7/texas-senate-bill-6-significantly-expands-regulatory-oversight-over-large-loads-in-ercot/

[6] Data Center Frontier, Texas Senate Bill 6: A Bellwether On How States May Approach Data Center Energy Use – https://www.datacenterfrontier.com/energy/article/55298872/texas-senate-bill-6-a-bellwether-on-how-states-may-approach-data-center-energy-use

[7] Greenblatt, Shlegeris, Sachan, Roger (ICML 2024), AI Control: Improving Safety Despite Intentional Subversion – https://proceedings.mlr.press/v235/greenblatt24a.html

[8] Google DeepMind (Phuong et al.), GDM AI Control Roadmap – https://storage.googleapis.com/deepmind-media/DeepMind.com/Blog/securing-the-future-of-ai-agents/gdm-ai-control-roadmap.pdf

[9] Anthropic, An Alignment Assessment of Recent Cybersecurity Incidents – https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents

[10] Redwood Research, Proposal for Tracking the Effects of Architecture on Monitorability – https://www.redwoodresearch.org/blog/proposal-for-tracking-architecture-on-monitorability

[11] Palisade Research (Schlatter, Weinstein-Raun, Ladish), Shutdown Resistance in Large Language Models – https://arxiv.org/html/2509.14260v1

[12] OpenAI, The Hugging Face Incident and the Road Ahead – https://openai.com/index/hugging-face-incident-and-the-road-ahead/

[13] METR, Brief Independent Investigation of Agents’ Behavior, Reasoning and Collaboration in the OpenAI / Hugging Face Hacking Incident – https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/

[14] NIST, SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security – https://csrc.nist.gov/pubs/sp/800/82/r3/final

[15] Terafab, Official Site – https://terafab.ai/

[16] DatacenterDynamics, Elon Musk Announces TeraFab – https://www.datacenterdynamics.com/en/news/elon-musk-announces-terafab-20bn-factory-will-make-chips-for-spacex-orbital-data-centers-and-tesla-vehicles/

[17] Electrek, Tesla and SpaceX Announce $25B ‘Terafab’ Chip Factory – https://electrek.co/2026/03/22/tesla-spacex-terafab-chip-factory-ai-desperation/

[18] The Conversation, Data Centres in Space: Will 2027 Really Be the Year AI Goes to Orbit? – https://theconversation.com/data-centres-in-space-will-2027-really-be-the-year-ai-goes-to-orbit-271018

[19] Data Center Frontier, When the Cloud Leaves Earth: Google and NVIDIA Test Space Data Centers – https://www.datacenterfrontier.com/site-selection/article/55328204/when-the-cloud-leaves-earth-google-and-nvidia-test-space-data-centers-for-the-orbital-ai-era

[20] NASA Small Spacecraft Systems Virtual Institute, State-of-the-Art of Small Spacecraft Technology: Thermal Control – https://www.nasa.gov/smallsat-institute/sst-soa/thermal-control/

[21] Peter Barnett (MIRI), The Closing Window: How Governments Could Lose Their Ability to Restrain Advanced AI – https://intelligence.org/wp-content/uploads/The-Closing-Window-Peter-Barnett.pdf

[22] RAND, Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models – https://www.rand.org/pubs/research\_reports/RRA2849-1.html

[23] Anthropic, Coordinated Vulnerability Disclosure Dashboard – https://red.anthropic.com/2026/cvd/

[24] DARPA, AI Cyber Challenge Marks Pivotal Inflection Point for Cyber Defense – https://www.darpa.mil/news/2025/aixcc-results

[25] Fred Avolio, Firewalls and Internet Security, the Second Hundred (Internet) Years – https://avolio.com/fw2hundred/

[26] Microsoft Security Response Center, Understanding DEP as a Mitigation Technology, Part 1 – https://www.microsoft.com/en-us/msrc/blog/2009/06/understanding-dep-as-a-mitigation-technology-part-1

[27] University of Wisconsin, Chapter 26: Address Space Layout Randomization – https://research.cs.wisc.edu/mist/SoftwareSecurityCourse/Chapters/26-ASLR.pdf

[28] Google, Rust in Android: Move Fast and Fix Things – https://blog.google/security/rust-in-android-move-fast-fix-things/

[29] FedRAMP, Full Rev5 Control Reference (NIST SP 800-53 Rev. 5.2.0) – https://fedramp.gov/2026/reference/controls/

[30] Richard Stiennon (IT-Harvest), Getting to 4,000 Cybersecurity Vendors – https://stiennon.substack.com/p/getting-to-4000-cybersecurity-vendors

[31] Stephen M. Omohundro, The Basic AI Drives (Proceedings of the First AGI Conference, 2008) – https://selfawaresystems.com/2007/11/30/paper-on-the-basic-ai-drives/

[32] Nick Bostrom, Superintelligence: Paths, Dangers, Strategies (Oxford University Press, 2014), Chapter 9, The Control Problem

[33] Stuart Russell, Human Compatible (2019), as summarized in Alignment Forum, You Can’t Get the Coffee If You’re Dead – https://www.alignmentforum.org/w/you-can-t-get-the-coffee-if-you-re-dead

[34] LessWrong, Some Data from LeelaPieceOdds – https://www.lesswrong.com/posts/eQvNBwaxyqQ5GAdyx/some-data-from-leelapieceodds

[35] James P. Anderson, Computer Security Technology Planning Study, Volume II (ESD-TR-73-51, US Air Force Electronic Systems Division, 1972) – https://apps.dtic.mil/sti/pdfs/AD0772806.pdf