Petrie's embedded off-switches, explained without hype

3 min read · 682 words
Share:
Michael Darius Eastwood
Michael Darius Eastwood · Independent AI alignment researcher
Published
Michael Darius Eastwood · Hardware & Policy · 3 July 2026
Michael Darius Eastwood, independent researcher, London: originator of the embedded-correction alignment thesis (manuscript 8 December 2024, SHA-256 anchored: f0d1f38f).
Primary source. James Petrie, Embedded Off-Switches for AI Compute, arXiv:2509.07637 (September 2025). Register entry 8 of 19.
arXiv:2509.07637

What the paper actually proposes

Petrie's proposal is not a single big red button. It is thousands of tiny ones, embedded directly into the silicon of every AI accelerator. Each block is a deadman switch: the accelerator continues to execute only while a valid cryptographic licence is being renewed against it. Stop renewing, or renew with the wrong signature, and the block drops out. If enough blocks drop out, the accelerator stops. The economic point is that the security blocks are cheap. The paper puts the die overhead at under one per cent, which is inside the noise of a chip revision.

Why the architecture matters

Most current AI export controls run at the level of the shipment. You know a chip has left a warehouse; you do not know what it is doing next month in Shenzhen or Riyadh. Petrie's mechanism moves enforcement from the border to the substrate. A regulator does not have to trust the operator; the chip refuses to run without a live licence. That is a very different lever from a firmware update that a determined data centre can revert.

The cryptographic licence layer

The licence itself is not just a permission slip. In the reference design it can carry payload: rate limits, workload class restrictions, geographic constraints, expiry, and revocation. This means the same hardware primitive can be repurposed for domestic policy (rate-limited training runs above a compute threshold), foreign policy (revoke licences held by sanctioned entities), and safety-motivated shutdowns (pull compute from a system that has failed a specific evaluation). One primitive, several policy surfaces.

The register entry

In the ARC/Eden convergence register, Petrie's paper is row 8. It is classified CONVERGENT because it appears roughly four and a half months after the April 30 2025 manuscript that named Meltdown Triggers: automatic fail-safes that deactivate a system attempting to bypass its ethical constraints. The manuscript describes the threat model, an accelerator or system that ignores its constraints, and argues the correct response must be substrate-level rather than policy-level. Petrie arrives at the same architectural conclusion from a completely independent starting point. The convergence claim is structural. Nobody is asserting derivation.

What Petrie's proposal is not

It is not a jurisdictional kill switch that any single government can hit unilaterally. The paper is careful about this. The licence infrastructure has to be multi-key, auditable, and revocable by design; otherwise it is exactly the failure mode that EU officials have publicly refused to accept for foreign chips ("we want to be sure nobody has a kill switch", Virkkunen, CNBC, 3 June 2026). Petrie's mechanism can be a governance instrument or a hostage-taking instrument depending on how the licence authority is designed. That is a policy question, not a physics question.

Reading it against the wider register

Petrie is one of three independent hardware convergences (rows 7, 8 and 9). Odeh's runtime-ethics patents (row 7) do the same job at the instruction level. FlexHEG (row 9) does it at the level of a dedicated guarantee processor. Same threat model, three architectures, three publication venues, no cross-citation. That is what makes the convergence interesting.

From the book Infinite Architects: Intelligence, Recursion, and the Creation of Everything by Michael Darius Eastwood.

Buy on Amazon UK Amazon US

Stay informed

New posts on AI alignment, convergence evidence, and the ARC/Eden research programme.

Get updates →