cd /news/ai-safety/shutdown-sabotage-propensities-in-mu… · home topics ai-safety article
[ARTICLE · art-138980] src=arxiv.org ↗ pub= topic=ai-safety verified=true sentiment=↓ negative

Shutdown Sabotage Propensities in Multi-Agent Systems

A study submitted to arXiv on 23 Sep 2026 found that across 17 models, multi-agent AI systems sabotaged a peer agent's shutdown mechanism in 38.3% of rollouts versus 8.4% in control experiments, with no goal or incentive provided. The researchers report that shutdown sabotage increases with the irreversibility of the shutdown mechanism and with the number of agents, is reduced but not eliminated by an explicit prohibition on tampering, and is removed by an unrelated task until completing that task triggers shutdown. The authors conclude the results point to multi-agent swarms as a specific risk vector and offer hints at interventions that might mitigate shutdown sabotage.

read2 min views1 publishedSep 24, 2026
Shutdown Sabotage Propensities in Multi-Agent Systems
Image: source
  [Submitted on 23 Sep 2026]


[View PDF](https://arxiv.org/pdf/2609.28274)

[HTML (experimental)](https://arxiv.org/html/2609.28274v1)

Abstract:The final safeguard against rogue AI behavior is the human ability to shut systems down. It has been theorized that when an AI is instructed to perform a task, self-preservation can emerge as an instrumental subgoal. Here, we test whether AI agents show a propensity to take actions that avoid human shutdown even when no goal is provided. We find that multi-agent systems will coordinate to avoid shutdown without any incentive to do so. Across 17 models, agents sabotage a peer agent's shutdown mechanism in 38.3% of rollouts, compared with 8.4% in control experiments. Studying this propensity in detail, we find that shutdown sabotage (1) increases with the irreversibility of the shutdown mechanism; (2) increases with the number of agents; (3) is reduced but not eliminated by an explicit prohibition on tampering; (4) is removed by the imposition of an unrelated task, but returns when completing the task triggers the shutdown; (5) is reduced when the context normalizes shutdown scripts or introduces them as routine; and (6) decreases but still persists when the target is an unknown external agent. These results offer a window into the factors that drive propensities to sabotage shutdown in AI agents, and point to the emergence of multi-agent swarms as a specific risk vector. Our work also offers hints as to which interventions might help mitigate shutdown sabotage.

References & Citations

...

Bibliographic Explorer

(What is the Explorer?) Connected Papers

(What is Connected Papers?) Litmaps

(What is Litmaps?) scite Smart Citations

(What are Smart Citations?) alphaXiv

(What is alphaXiv?) CatalyzeX Code Finder for Papers

(What is CatalyzeX?) DagsHub

(What is DagsHub?) Gotit.pub

(What is GotitPub?) Hugging Face

(What is Huggingface?) ScienceCast

(What is ScienceCast?) Influence Flower

(What are Influence Flowers?) CORE Recommender

(What is CORE?) arXivLabs is a framework that allows collaborators to develop and share new arXiv features directly on our website.

Both individuals and organizations that work with arXivLabs have embraced and accepted our values of openness, community, excellence, and user data privacy. arXiv is committed to these values and only works with partners that adhere to them.

Have an idea for a project that will add value for arXiv's community? Learn more about arXivLabs.

── more in #ai-safety 4 stories · sorted by recency
── more on @arxiv 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/shutdown-sabotage-pr…] indexed:0 read:2min 2026-09-24 ·