> ...that can't really be stopped easily.
Sure sounds like you built in an easy lever to pull to stop it. After all, even if you accept your premise that it will clone itself and run independently, that doesn't give it a clone of the models it is using. Pull the key, stop the process.
Also, remember that there was a day in the early internet when a worm took over, and to fix it the entire internet had to shut down and all wipe it from the systems at the same time. There is always a way to stop things.
Yet another take on this could be: Just don't ever do such an experiment. You wouldn't set up autonomous weapons and set them loose in a city just to see whether they hurt people. So don't do the AI equivalent of such a negligent act.
The agent could very well create an OpenRouter account and make its own API key. I can stop it early on, then it becomes outside my control.
> Just don't ever do such an experiment
Maybe I wouldn't, but eventually someone will. Certainly it has already been done.
> there was a day in the early internet when a worm took over, and to fix it the entire internet had to shut down
This is less of an option now that the entire global economy relies on the Internet.