Back to library
Spring 2026 Submitted May 2026

A Risk Taxonomy of I/O Channels for SL5 Air-Gapped AGI/ASI Inference

Ricardo Godric Aceves Vaca

Mentored by Luis Cosio

Working report from the SPAR program. May not reflect the authors' current views.

Abstract

The approach of Artificial General Intelligence (AGI) and Artificial Superintelligence (ASI) requires a fundamental rethinking of how frontier AI systems are contained and queried. Security Level 5 (SL5) mandates air-gapped inference environments, prohibiting all external network connections per control SC-7 of the SL5 Standard. Operational utility still requires at least one I/O channel, creating an attack surface the standard acknowledges as underspecified: control SC-7(10) mandates hardware-enforced bandwidth limits on Weight Enclave outflows but leaves the specific thresholds open. This paper presents the first risk taxonomy specifically calibrated for an ASI-class adversary in an SL5 context, covering four unconventional non-IP I/O channels (serial UART/RS-232, optical fiber/LED, audio FSK, and printed QR codes) plus cross-channel coordination, for the μInference prototype runtime built on the formally verified seL4 microkernel. We introduce the AGI Risk Score (RAGI), characterize 20 threat vectors across 5 risk domains, derive concrete bandwidth throttling parameters, and outline an empirical validation roadmap to resolve the SC-7(10) open threshold question. The central finding is that no single I/O path is universally safe, and that ASI-level adversaries change the threat model by enabling coordinated multi-channel exfiltration.