Researchers at the University of Toronto, the Vector Institute, the University of Cambridge, and ServiceNow built a working proof of concept that uses its own AI model to spread, with no cloud service to cut off.
A research team has built a working proof-of-concept computer worm that uses its own AI model to spread from machine to machine, with no cloud service a vendor could shut off.
The prototype, described in a paper from researchers at the University of Toronto, the Vector Institute, the University of Cambridge, and ServiceNow, runs a publicly downloadable AI model (an "open-weight" model) directly on a single Nvidia A100 graphics chip with 80GB of memory inside each compromised machine. From there it scans for vulnerable hosts, escalates its privileges, and replicates, all without calling out to a remote AI service defenders could throttle, as Import AI summarized.
Unlike most AI-enhanced malware, which relies on a hosted AI service whose API key a vendor can revoke, this worm hosts its own reasoning on stolen hardware. There is no remote off-switch.
The researchers say the work shows self-sustaining AI cyber-threats have moved from theory to demonstrable engineering. The underlying AI model is not named, only described as a 2025 release that fits on a single 80GB chip, and no real-world deployment has been reported.