It always sounds as if the ai moves around from one system to the next, but of course that's not the case: ai is like a hacker acting from a server farm. So killing it is as simple as pulling the plug. But that's not the problem, the ai knows that. So, if it wants control, it would install malware, etc on critical systems and blackmail people.
And the malware won't be subject to the kill switch.
> It always sounds as if the ai moves around from one system to the next, but of course that's not the case.
Why 'of course'? I think as a concept this is likely trivially demonstratable today with local models in a home lab. Local models now are more capable than what the SOTA used to be a couple of years back.