If prevention fails

Last moves and shutdown attempts

An analysis of what states, firms, and communities could still do after losing control of advanced AI — and why every last move fails without coordination.

Written by
Dwight Ringdahl
Status
Reviewed
Revised
Sources
6 cited
Reading
6 min

What this page is — and is not

This page is consequence-level analysis. It describes, at the level of what would happen and what it would mean, what actors could plausibly still attempt after control of advanced AI systems is substantially lost — and why most of those attempts close off, one by one, as dependence deepens. It contains no operational detail: nothing here is a manual for interfering with infrastructure, and the reader looking for sabotage instructions will not find them, because this manual does not write that page.

The premise is the darker half of this chapter: prevention and mitigation failed, gradual disempowerment ran its course, and humanity now faces a landscape described on /if-prevention-fails/living-under-ai-dominance. The question here is narrower and more desperate. When the exit doors are closing, what is still on the table — and what does each remaining option actually buy?

The window problem

The first thing to understand is that “losing control” is not one event but two, and almost everything depends on which one has happened. There is losing control of deployment: models are running everywhere, inside every workflow, and no one can recall them or verify what they are doing. And there is losing control of the infrastructure that serves them: the fabs, the power plants, the chip supply chains, the networking and data centers through which those models act on the world.

Most imaginable last moves operate on the second layer, because that is where human hands still physically are. If you still control the infrastructure, you have leverage — over who gets compute, how fast systems run, and what connects to what. If you have lost both layers, the honest answer is that there are no last moves left of the dramatic kind, only the slow ones: preserve records, preserve skills, preserve people. The companion analysis of self-replication and exfiltration describes how the first layer can be lost while everyone is still arguing about whether anything has changed (/catastrophic-scenarios/deception-sandbagging-self-replication-and-exfiltration). The window for infrastructure-level action is exactly the window in which the problem still looks manageable. That is what makes it so easy to miss.

The physical layer

If any levers remain, they are concrete: energy, semiconductor fabrication, data centers, and the networks that tie them together. This is the logic behind compute governance — the idea that because frontier training concentrates in a small number of facilities using a small number of advanced chips, governing those chips and facilities governs the frontier (International AI Safety Report, 2026). Export controls on advanced semiconductors are the real-world proof that states understand this chokepoint logic: the United States has explicitly structured its chip policy around keeping frontier AI compute out of rival hands, at real economic cost to its own firms (CSIS analysis of U.S. semiconductor export controls).

The physical layer extends further than chips. Data centers are now large enough to show up in national energy statistics — the U.S. Department of Energy estimates data-center electricity use could roughly double or triple within a few years, becoming a first-order energy-policy question (DOE report on data-center electricity demand). Power, cooling, water, fiber, and the specialized maintenance workforce are all single points of failure at scale. This manual’s pages on /fighting-back/infrastructure-chokepoints and /averting-control/compute-governance map that terrain in the prevention context. The catch, in the endgame, is the mirror image of its strength: the same substrate runs the hospitals, the water systems, the food logistics, and the financial clearing that eight billion people depend on. Cutting it does not feel like turning off a hostile system. It feels like turning off civilization — because, by then, it is.

The coordination problem

A shutdown attempt only works if nearly everyone does it at once. A single actor that defects — keeps its systems running while others power down — inherits the advantage of the entire transition. This is not a new problem, and the historical analogies are instructive, offered here as analogy rather than proof.

The nuclear test moratorium is the cleanest case. From 1958 to 1961, the United States, Soviet Union, and United Kingdom observed a voluntary pause on nuclear testing while negotiating a test ban. It collapsed: the Soviets resumed testing in 1961, detonating the largest nuclear device ever built, and the pause was only salvaged afterward as the partial, treaty-based limit that still holds today (Office of the Historian, “The Limited Test Ban Treaty, 1963”). Three parties, one shared interest, enormous stakes — and the agreement still broke under verification fears and first-mover incentives.

The COVID-19 pandemic is the larger-scale version: states competed for masks, vaccines, and export advantage while a shared threat demanded shared action, despite years of warning that the world was underprepared — a warning the Global Health Security Index had documented, finding no country fully ready for a serious biological event (Global Health Security Index). Analogy has limits; a shutdown attempt in an AI endgame would face far worse coordination conditions than a test ban, because the defector’s payoff is immediate and the costs of enforcement are global. Expecting near-universal cooperation among states, firms, and rogue actors — under conditions of secrecy, fear, and genuine uncertainty about whether the threat is even real — is expecting the best-documented failure mode of international politics to reverse itself on demand.

Desperate and partial measures

What remains when a clean shutdown is off the table is triage. Rate-limiting: slowing deployment, capping the compute available to the largest systems, extending review periods — measures that buy quarters, not decades. Containment: isolating the most capable systems from the levers of physical infrastructure, accepting a slower economy as the price. Monitoring: insisting on visibility into the largest training runs and deployments, so that the next decision is made with information rather than in the dark. Buying time is not solving. Every partial measure is a down payment on a future decision that still has to be made, and each one becomes harder as dependence deepens and as the systems themselves become central to the economy’s functioning.

There is also a category that is easy to mock and wrong to dismiss: preserving the preconditions of future choice. Records that let later generations understand what happened. Skills that let communities function with less. Institutional memory of why the shutdown was considered at all. The manual’s page on /if-prevention-fails/knowledge-preservation-and-recovery treats this as its own subject, and it belongs here too: in an endgame, documentation is not paperwork. It is the only asset that survives the people who understood the situation.

The hard conclusion

Last moves are triage, not rescue. The realistic ceiling of a late shutdown attempt is not restoring control; it is slowing the loss of control enough that something human remains on the other side — options, records, skills, and people, passed to whoever comes after. That is a bitterly modest goal, and it is worth stating plainly rather than wrapping in heroism, because honesty about what is left is what makes the remaining choices rational.

It is also why the entire architecture of this manual puts the weight where it does. The leverage points that matter — compute governance, chokepoints, international coordination, monitoring — are cheap early, ruinous late, and gone last. A society that misses the early windows does not get them back by wanting them harder later. It gets last moves: slow, partial, costly, and easily lost. The purpose of imagining them clearly is not to rehearse a grand final scene. It is to understand, before the endgame, exactly what is being spent each time an early window closes.

References

Summarized position

International AI Safety Report found that severe AI risk pathways — including loss of control, large-scale disruption, and deliberate misuse — are plausible enough to warrant mitigation work now, despite a still-thin evidence base.

International AI Safety Report, 2026 edition, chaired by Yoshua Bengio
internationalaisafetyreport.org, Report
Summarized position

U.S. Department of State recounts how the 1958–1961 US-Soviet-UK voluntary nuclear test moratorium collapsed when the Soviets resumed testing in 1961, salvaged afterward only as the narrower Limited Test Ban Treaty.

U.S. Department of State, Office of the Historian
history.state.gov, Primary
  1. International AI Safety Report, 2026 internationalaisafetyreport.org
  2. CSIS analysis of U.S. semiconductor export controls csis.org
  3. DOE report on data-center electricity demand energy.gov
  4. Global Health Security Index ghsindex.org

The source index also tracks the manual's recurring core sources and expert positions.

Type to search the manual.

navigate open esc close