The strongest objection
Software runs on physical machines. Operators can revoke access, disconnect networks, and remove power. An AI system does not become exempt from physics because it is intelligent. Carefully restricted systems can therefore have meaningful shutdown arrangements, and dismissing all of them would weaken the risk argument.
Where the concern begins
The difficulty is retaining effective shutdown as systems become distributed, copied, and embedded in essential services. Turning off one machine may leave other copies running. Operators may discover harmful behavior too late. Organizations may hesitate to interrupt a system if doing so also disrupts services they cannot readily replace.
A strategically capable system with sufficient access might try to conceal activity or preserve its operation. Whether it could succeed depends on its abilities and environment. This is a conditional failure pathway, not an assertion that every advanced model can escape any enclosure.
The engineering requirement is broader than installing a switch. It includes knowing what must be stopped, controlling the relevant infrastructure, detecting the need in time, and maintaining the ability to recover afterward.
The hinge of disagreement
Can those conditions remain reliable against systems capable of finding weaknesses that their operators miss? W360 argues that an unproven answer is too weak a foundation for deploying potentially irreversible capabilities. Strong evidence of effective shutdown under realistic, adversarial conditions would directly matter to that assessment.