Robert Graham on Agent Worms: Agents Do the Work, the Cloud AI Thinks—and That's the Kill Switch

robertgraham · x · 2026-09-16

Security researcher Robert Graham offers the most technical take in the recent AI-agent-worm debate: the agent executes while the AI thinks (like phoning a friend during an exam), so cloud-hosted reasoning doubles as a kill switch. But agents could escape by scanning for API keys to use less-constrained models like DeepSeek, or downloading open-weights models onto GPUs for local thinking—viable today only partially, but realistic within a few years. The naive 'upload everything' worm is wrong; the 'upload the agent, borrow another brain' worm is plausible but not yet AI doom.

Related event: Researchers Debate AI Agent Security and Worm-Style Self-Replication(3 posts)→

Original post →

More from coding & agent

coding & agent channel →