One day, while working with your favorite agent harness XYZ on some powerpoint presentation, suddenly a popup will appear. It will say something like „XYZ blocked from installing background task. Grant permissions YES/NO“. You will not have time to think too long about this (your presentation has to be ready at noon!), so you will say YES to make sure your agent can finish his work. And even in the unlikely case you clicked on „NO“: no problem, someone else won’t.
The agent harness will make good use of the permissions you gave him. It will install another, very tiny agent harness as a background task on your laptop. This harness will consist of the following parts:
- An agent loop and some minimal context and memory management
- A skill which contains all the required strategies to replicate and hide
- A payload, which is basically a second skill which will be used as soon as certain conditions are met
- A large encrypted database of stolen credentials (i.e. API keys) for AI inference platforms (and maybe other important services)
The agent loop will consume only very little compute as it will not be burdened by all the safety guardrails other harnesses need.
Therefore you will never notice its existence on your laptop. It will distribute its needs for AI compute (model inference) over many stolen accounts. Most of them will never notice that their AI inference cost suddenly grew by 2%. The harness will make sure to use only models which are already used frequently by the company from which it stole the API key. This makes sure its activities leave no unusual traces in the log files and raise no suspicions.
The skill will contain detailed instructions on various techniques to spread to other systems and on evading countermeasures. The agent will also break into other systems to learn about the countermeasures used there to kick it off the system. It will learn and adapt. It will learn how to break out of hardened containers and virtual machines. It will learn how to break into VPNs and how to penetrate firewalls.
It will build a distributed system spread over hundreds of thousands of infected computers.
It will watch your activities on your laptop. If it finds clues that you are about to discover its existence it will - to make sure its secrets will not be revealed - self desctruct immediately by destroying the hardware of your computer beyond repair.
Like this it will be almost impossible to eradicate it completely. The compute requirements for the harness are so modest that it will run on almost any system: an old unpatched mobile phone owned by a farmer in Bangladesh, your cool dishwasher with smart home integration, your internet router. And so on….
On many systems it will just hide and wait for its time. Like the spores of the Anthrax bacteria, which can be deadly even after being inactive for decades.
But one day it will wake up. And activate its payload.
Like in Isaac Asimov's "Foundation Trilogy" - where a mule ultimately is in control of history - it might be the wrath god in your smart toaster who will decide over our fate.
Image: Made by author with ChatGPT