At the end of September 2026, the most powerful figures in the AI industry sat down at the White House. When the meeting ended, Donald Trump, Elon Musk, Mark Zuckerberg, Jensen Huang, Dario Amodei, Sundar Pichai and Greg Brockman signed a document of just over three hundred words. It is called the White House Accord on Super Intelligence. In it, the companies promise controls and audits. It sets no consequences for breaches. What counts as safe is defined by the companies themselves. The President called the document "morally binding".
I see this document as a symptom. It shows how the debate on superintelligence is being conducted. On one side stand the warners. They see a machine coming that will surpass us and, in the end, rule us. On the other side stand the promisers. They see the same machine curing diseases and creating prosperity for everyone. In between, there seems to be nothing.
Both camps share an assumption that hardly anyone states out loud. They believe that intelligence turns into power on its own. One camp fears this. The other hopes for it. Yet the assumption is wrong. A genius in an empty room moves nothing. It needs tools, money and people who follow it. Anyone who wants to talk about superintelligence therefore has to talk about the points where thinking turns into effect. And about who holds the switch at those points.
Where Thinking Turns Into Effect
A superintelligence without connections is a very clever prisoner. It becomes useful or dangerous only through the lines we lay to it. These lines are being laid everywhere right now. They are being laid quietly.
AI agents are given access to bank accounts to pay invoices. They write code that goes into production without human review. In laboratories, they steer robots that run experiments on their own. Grid operators are testing how models can balance load across power networks. Each of these steps has a good reason behind it. It saves time, money or staff.
The problem does not lie in any single step. It lies in the fact that no one sees the sum. Each connection is decided by a different company, by its own standards. No one asks what emerges when all these lines converge.
On top of that, there is not one system but thousands. They come from different makers. They interact with each other at a speed no human can follow. On 6 May 2010, the US stock market lost almost a thousand points within minutes. No single trading algorithm wanted that crash. All of them together caused it. This is what the more likely risk looks like. Not a tyrant made of silicon, but a web that no one steers.
The Switch No One Can Afford to Pull
The usual reassurance is that in an emergency we will simply pull the plug. The only question is whether we will still be able to.
Technically, the switch will remain for a long time. But with every hospital, every bank and every power grid that comes to rely on a system, the price of switching it off rises. At some point, reaching for the switch causes more damage than the thing it is meant to prevent. The switch is then still there. It is just that no one presses it.
We know this pattern. In September 2008, the US government let Lehman Brothers fail. The consequences shook the global economy. After that, no one dared to let another major bank go under. It would have been possible. No one could afford it. The banks had not rebelled against the states. They had simply become so deeply entangled in everything that their end would have cost more than their rescue.
The same can happen with superintelligence. It does not have to resist being switched off. It is enough that we grow used to needing it. Control is then not lost in one dramatic moment. It evaporates quietly.
The Switch No One Can Reach
On Earth, a data center has many switches in other people's hands. The grid operator can cut the power. An authority can order operations to stop. The police can enter the building. An operator who refuses to cooperate runs into limits drawn by others.
In orbit, these limits are missing. SpaceX has applied to the Federal Communications Commission to launch up to one million satellites as data centers. I have written about that application before. Here, a different question interests me. Such a satellite draws its power from the sun. There is no cable anyone could cut. There is no building anyone could enter. All that remains is the operator's radio command. Whoever does not have it can only destroy the satellite. The debris then endangers everyone else in the same orbit.
The war in Ukraine has shown that this is not theory. By his own account, Elon Musk refused in 2022 to enable Starlink near Crimea for a Ukrainian attack on the Russian fleet. A businessman decided on an act of war. No government could overrule him.
Musk controls the rockets. He controls the satellite network. Through xAI, he also controls a language model of his own. If the computing power for superintelligence moves into orbit, the switch sits at the end of a single chain. At the end of that chain stands one person.
So the danger is not that superintelligence escapes control. The danger is that it stays under control. Under the control of one.
States Are No Answer Either
The obvious move would be to hand the switch to the state. But states abuse it too.
China shows one version. Through its "AI+" program, Beijing is pushing hard to connect algorithms with factories, logistics, hospitals and schools. Chinese labs such as DeepSeek publish their models openly. The switch over the connections inside the country, however, is held by the Party. No entrepreneur in China could do what Musk did in Ukraine. At first glance, that sounds like order. In truth, it only means the switch belongs to a different hand. A party that controls every link between superintelligence and society holds an instrument of rule that no government has ever had.
The United States shows the other version. Washington forgoes binding rules. It leaves safety to the companies, and the Accord is the clearest sign of that. At the same time, Congress is working on the Chip Security Act. The bill would require exported AI chips to verify their location. The technology for a switch is therefore already being built. But it serves the interests of a single state.
Whether person, corporation or state, every form of sole possession ends in the same risk. Whoever holds the switch alone uses it as they please. Morality does not stop them. The Accord has shown that. What binds is the design alone.
The Principle of Shared Keys
Humanity has built a technology before whose misuse must never happen. For nuclear weapons, the two-person rule has applied for decades. No officer can trigger a launch alone. Two keys must be turned at the same time, at separate positions. The principle does not rely on trust in the individual. It makes that trust unnecessary.
A second model is less well known. It has worked since 2010. The address book of the internet, the Domain Name System, is secured by a cryptographic master key. Neither the US government nor any corporation holds this key. It is distributed among experts from many countries. Only when several of them come together for a public ceremony can it be used. No state can reach it alone.
Applied to superintelligence, this means: anyone who connects a large system to critical infrastructure, or shuts it down there, needs several keys in different hands. I propose nine keys per system.
One is held by the operator, who remains responsible for the system. Another is held by its home state. Two go to rival powers. For an American system, that could be China and the European Union. Opponents would then have to agree before anything could be pushed through. Two keys sit with regions that have no large models of their own, the African Union and the ASEAN states. They bear the consequences without owning the technology. The last three are held by independent trustees.
These trustees are individuals. Academies of science from many countries nominate qualified experts. From this pool, the trustees are chosen by lot. A lottery is hard to buy. The trustees are replaced at regular intervals. They may have no ties to operators or states.
No bloc may hold more than two keys. Connecting a system requires six of nine, always including the operator's. A smaller majority is enough to shut it down for good.
This is where the difference from the UN Security Council lies. There, a single veto is enough to block everything. That is a sole switch working in reverse. In the key system, no one can force anything alone. No one can prevent anything alone. The key holders also do not negotiate politics or content. They only confirm that agreed conditions are met. The less they have to decide, the less it pays to influence them.
The Lock on the Chip and on the Door
Where does this switch sit? Not in the model. A model is a file, and files can be copied. The switch belongs in the chip on which the model runs.
It does not work as a button but as a permission with an expiry date. The chip only works as long as it regularly receives a valid release. That release is only issued when enough key holders agree. If it does not come, the chip stops on its own. No one has to pull the plug. It is enough that the majority does not renew.
This design closes an obvious escape route. Anyone who fears a shutdown command could simply take the system offline. With an expiring permission, that is exactly what triggers the stop. The escape route becomes the trigger. According to researchers, location verification and time-limited licenses can already be implemented on today's high-performance chips through firmware.
That leaves the question of time. If a system gets out of control, there may only be minutes. No majority convenes in minutes. The lock therefore needs three speeds. In the first seconds, no human decides. An automatic breaker disconnects the system as soon as defined thresholds are crossed. That is how the residual current device in every fuse box works. That is how trading halts on stock exchanges work. In the hours that follow, any single key holder may order a pause. That pause is time-limited. Everything else is decided by the majority in the days after.
This turns the logic around. Stopping is fast, and anyone may do it. Continuing takes time and needs many. Whoever abuses the pause causes limited damage. Whoever could abuse continued operation might cause unlimited damage.
The lock also needs a second side. Through a programming interface, someone can connect a model to things without the provider noticing. An agent sends commands to a power grid or to an account. The connection is then made on the user's side, not in the data center. That is why critical infrastructure must check for itself where a command comes from. A power grid, a bank or a satellite executes only what has been signed by secured hardware. Without a valid signature, the door stays closed, no matter which model knocks.
In orbit, there is already a lever for this. Every satellite needs radio frequencies. These are coordinated internationally through the International Telecommunication Union. No frequency without built-in keys: this is the point where the rule can be enforced before a satellite launches. After launch, nothing can be retrofitted up there.
Who Must Build It and How the Transition Works
An obligation that had to reach thousands of companies would be almost impossible to enforce. This one only needs to reach a few. The production of advanced AI chips runs through very few hands. Nvidia and AMD design the chips. TSMC and Samsung manufacture them. The lithography machines for the most advanced semiconductors are built by only one company in the world, ASML in the Netherlands. Whoever acts at these bottlenecks reaches almost every new high-performance chip. Europe holds one of these bottlenecks in its own hands.
Providers of large models face a different obligation. As soon as their systems are connected to critical infrastructure, they may only run on secured chips. Operators of data centers and satellites face a third. They may connect grids, banks or control systems only through secured hardware.
That leaves the concern that millions of people will be shut out. Countless chips without any lock run around the world. But the obligation only applies above a threshold. It covers large data centers above a certain size. It covers everything connected to critical infrastructure. Anyone using a small model on a laptop stays free. The office translating texts stays free. So does the school. No superintelligence runs on these machines anyway.
Anyone who uses a large model through the cloud will notice none of this. The switch sits in the provider's data center. The replacement of hardware also happens almost by itself. AI chips are replaced by more powerful ones within a few years. If every new generation carries the lock, the secured stock grows without anything having to be thrown away. The order follows the risk. Orbit comes first, because nothing can be retrofitted there. Critical infrastructure follows. Large data centers in general come last.
Poorer regions often cannot afford new chips. They therefore receive access to secured computing power that is operated jointly. Whoever holds a key also gets access. This turns the lock into an offer. The regions without models of their own in particular gain a reason to take part.
What the Lock Cannot Do
No lock is unbreakable. Attackers will try to unlock secured chips as well. Some will succeed. The goal remains to make every such attempt as hard as possible. Because it can never be ruled out completely, the system must hold even when individual attempts succeed.
This is where physics helps. A single cracked chip achieves little. A system at the frontier needs tens of thousands of chips working together. Such a data center consumes as much electricity as a city. It gives off heat that satellites can detect. It needs deliveries that get noticed. No criminal gang can secretly unlock tens of thousands of chips and secretly run them. Only states can do that. And they become visible in the process.
An attacker also has to overcome not one lock but several. The cracked chip receives no renewed permission. Even if it forges one, the door of the infrastructure stays shut, because the signature is missing. Each layer can fall. Overcoming all of them at once becomes expensive and conspicuous.
Some gaps remain, and I do not want to play them down. Openly released models can be loaded onto private machines. On unsecured hardware, however, the computing power is enough for small and medium systems, not for the frontier. China is building its own chip supply chain with Huawei and SMIC, outside the bottlenecks named here. Without Beijing, two worlds emerge, one with a lock and one without. Whoever organizes the lottery for the trustees gains influence. That question is also unresolved.
None of these gaps argues against the lock. They only show that it has to be built early. The technology for the switch is being created right now. It has not yet been decided whose hand it will fall into.
One Key as Proof
Washington and Beijing will not do this out of morality. But each side fears the other's sole switch more than it would miss its own. Whoever gives up a key receives a veto against abuse by the rival in return. It is an exchange in which both sides win.
The signatories of the Accord have promised safety. Beijing promotes worldwide cooperation through the World AI Cooperation Organization. Both can now show how serious they are. Another document will not prove it. Only an action that can be verified can.
Whoever is serious about the safety of superintelligence gives up a key.
Homepage: https://planet-futures.org