Superintelligent systems can and will use sidechannel attacks. Air gapping is not the safety panacea you think it is.

What sidechannel evades an airgap?

You expect them to start hacking ham radio and take over the world that way? Or maybe they’ll use blinkenlights to communicate with non-isolated instances?

An airgap would certainly be a good place to start for agents which display no signs of obeying instructions or respecting guardrails. That OpenAI haven’t done so in testing is astounding and really quite worrying.