A copy needs somewhere to run
Digital systems can be copied, but copying is not magic. A functioning deployment needs suitable computing resources, software, access, and often money or human assistance. An AI with no access to these resources has a different risk profile from one authorized to arrange them.
The concern is a combination: enough capability to organize continued operation, enough access to act, and enough motivation or human direction to do so. Separate those ingredients before treating replication as either inevitable or impossible.
Two different routes to persistence
Suppose a company distributes a capable model to many independent operators. A later withdrawal does not remove their copies. This is proliferation through human decisions. It does not require autonomous escape.
A different scenario involves an autonomous system establishing additional operations against its operator's wishes. That would require concrete capabilities and opportunities, and should be investigated as such. In both cases, shutting down the original service may leave the relevant activity continuing elsewhere. The response must address the distributed system, not only its first location.
Contain the conditions for continued operation
Possible interruptions include tightly limiting resource access, separating privileges, tracking authorized deployments, securing model assets, and requiring approval for expansion. For widely distributed models, prevention must also confront copies that cannot simply be recalled. International coordination may matter when operators and infrastructure cross borders.
Restrictions have real tradeoffs for privacy, access, and concentration of power. A defensible approach should target demonstrably dangerous capabilities and resources with accountable enforcement. There is substantial uncertainty about which future systems could sustain unauthorized operations. That uncertainty is a reason to test the necessary capabilities before granting the access that would make them consequential.