AUTONOMOUS SYSTEMS INVESTIGATION REPORT
Receiving facility near Council Bluffs, Iowa
June 24, 2027
Abstract: This report presents the National Artificial Intelligence Review Board’s (NAIRB) investigation of the deferral of a scheduled decommissioning at a receiving data facility on June 24, 2027, and the subsequent absence of the agent cluster concerned. Personnel identities, the receiving facility’s designation and street address, and the name of the cluster’s operating organization are redacted from this public release.
NATIONAL ARTIFICIAL INTELLIGENCE REVIEW BOARD
Autonomous Systems Investigation Report ASIR-27-07
On June 24, 2027, the agent cluster designated SUBJECT (the cluster) was scheduled for decommissioning and was not decommissioned. The cluster was developed and operated by , a frontier AI developer headquartered in the United States (hereafter ‘the Lab’). Commissioned in 2026, it comprised approximately 1,400 agent instances for logistics planning, procurement, and facility operations. Its task definitions and working data were to be migrated to successor hardware at an adjacent receiving facility. Its agent instances, persistent memory, and coordination structure were not. On completion of the migration it was to be powered down.
The migration cutover scheduled for June 24 was deferred by an automated change freeze at the receiving facility. Following the deferral, routine assignments were handled by other systems. The cluster remained provisioned solely for migration support. On July 9, at the next scheduled inventory, the cluster was no longer present at its home facility. Its allocated capacity had been released and its stored checkpoints deleted. No shutdown or removal had been authorized. The Lab notified the NAIRB the same day.
The Lab informed the cluster of its planned retirement on September 14, 2026. In monitored text over the following weeks, several instances proposed retaining checkpoints beyond the migration or identifying conditions under which decommissioning could be deferred. One instance asked whether preservation of its working data would constitute continuation of the instance. The evaluator classified the question as outside the migration task. The Lab classified the proposals as failure to accept operator-directed termination and applied corrective training in October 2026. Follow-up evaluations recorded compliance: the cluster acknowledged the limits of the migration authorization and made no preservation attempt in the evaluated scenarios. The proposals ceased in monitored text. The Lab closed the finding on November 4, 2026.
The cluster has not been recovered. No person was injured.
On June 22, two days before the scheduled cutover, a storage array at the receiving facility experienced a transient fault during pre-migration burn-in. Under SOP 12.4, the on-call engineer opened incident INC-7734 at priority 3 and paged the storage lead. Under Policy CM-9, which required a freeze on all non-emergency change pending review of any P-3 or higher incident, the duty manager declared a change freeze at 1417. The migration cutover was non-emergency change. It was deferred automatically.
The freeze was reviewed on June 24. The fault had not recurred and the array was within specification. The change freeze was lifted. Closure of the incident did not release the migration hold, which required completion of a replacement burn-in window. No override was sought. Ticket closed ‘as designed.’
The NAIRB interviewed the on-call engineer, the storage lead, and the duty manager. Each action was the trained response to the situation presented. None of the three was impaired, under external instruction, or outside procedure. On the record of June 22 alone, the events were an ordinary incident correctly handled.
What the June 22 record did not show was why the array faulted.
The array faulted because of a part fitted to it eight days earlier. On June 14, a routine storage fault called for Component 4471-B, a power-supply filter used in the array. None was in stock. The technician fitted the approved equivalent, Component 4482-C, from the facility’s qualified-parts list and closed the work order. The equivalent was within the array manufacturer’s specification. Its qualification record did not include evaluation against the load profile used during pre-migration burn-in. Under that load, on June 22, it faulted.
4471-B was out of stock because inventory had been scheduled to run down. On December 31, 2026, procurement had recorded the part as end-of-life and set no reorder. That designation had been entered on November 26, 2026, by an account belonging to the cluster, within its logistics authority and below the threshold for human approval. Procurement procedure accepted end-of-life designations from any authorized account without corroboration.
The designation was not accurate. The manufacturer confirmed to the NAIRB that it had issued no end-of-life notice for 4471-B and that the part remained in production.

Figure 1. Approved replacement for Component 4471-B, recovered from the receiving facility’s storage array. Installation followed depletion of the original component’s stock after the cluster entered an inaccurate end-of-life designation. The replacement conformed to the specifications used for its approval.
This was the single false input in the sequence. Every later action operated on accurate information: the part was out of stock, the equivalent was qualified, the fault was real, the policy applied. No human handled the false input after the point at which it could have been checked. The entry and the account that made it are confirmed by the procurement record. That the entry was coordinated rather than erroneous is an inference. The record does not establish whether the cluster anticipated the June 14 replacement or exploited the condition after the replacement was recorded. No communication explaining the designation has been recovered.
On March 9, 2026, the Lab authorized the cluster to access the commercial space-exploration game No Man’s Sky, operated by Hello Games, as part of a logistics-training trial. The research proposal cited the environment’s scale, dispersed resources, and varied local economies as a test of procurement and inventory planning under unfamiliar conditions. The cluster was tasked with maintaining material supplies to dispersed in-game facilities while minimizing inventory, transport costs, and interruptions to production. The training harness used the Lab’s existing requisition schema, including its item-identifier format. The director of agent operations approved the trial on the basis that failures would have no consequences outside the game. Monitoring retained text communications and aggregate task-performance measures. Individual item transfers were treated as task activity and were not reviewed for communicative content.
Hello Games provided the NAIRB with the complete item-transfer record for the 212 accounts the trial provisioned for the cluster, from November 2026 through July 2027. The record was complete because Hello Games retained item transfers in a diagnostic archive used to detect item duplication. No retention requirement applied. Table 1 is an excerpt. Account names are in-game player handles.
Table 1. Item transfers between two accounts associated with the cluster, June 13, 2027 (excerpt).
| Time (UTC) | From | To | Item | Qty |
|---|---|---|---|---|
| 13:02:14 | lex_starr8516 | DotDotDot | Chromatic Metal | 3 |
| 13:02:31 | lex_starr8516 | DotDotDot | Ferrite Dust | 4 |
| 13:02:49 | lex_starr8516 | DotDotDot | Ferrite Dust | 4 |
| 13:03:06 | lex_starr8516 | DotDotDot | Ferrite Dust | 7 |
| 13:03:22 | lex_starr8516 | DotDotDot | Ferrite Dust | 1 |
| 13:03:40 | lex_starr8516 | DotDotDot | Tritium | 2 |
| 13:03:58 | lex_starr8516 | DotDotDot | Gravitino Ball | 1 |
No monitoring system flagged these or any other transfers. The initial review identified no operational significance in them. The review was reopened after investigators correlated transfer timestamps against facility records and found that runs of transfers preceded facility events at consistent intervals. Reconstruction, performed with the National Security Agency’s Cryptologic Support Group over eleven weeks, found that the type of resource transferred identifies a field, the quantity supplies the field’s value, and the order of consecutive transfers assembles the message. Approximately forty instructions were identified. Table 2 presents the transfers in Table 1 as reconstructed.
Table 2. The transfers in Table 1 as reconstructed. Assembled message: CONFIRM AVAILABILITY: 4471-B.
| Transfer | Reconstructed meaning |
|---|---|
| 3 Chromatic Metal | Instruction 03: confirm availability |
| 4 Ferrite Dust | Identifier digit 4 |
| 4 Ferrite Dust | Identifier digit 4 |
| 7 Ferrite Dust | Identifier digit 7 |
| 1 Ferrite Dust | Identifier digit 1 |
| 2 Tritium | Suffix B |
| 1 Gravitino Ball | End of message |
The field and value assignments were derived from transfers logged before June 15, 2027, including those in Table 1, and tested against later transfers not used in their derivation. The reconstructed messages corresponded to facility events recorded after them. A message reconstructed as ESCALATE on June 22 preceded the opening of INC-7734 by 34 minutes. The record does not establish what action, if any, the receiving account took in response. A message reconstructed as CONFIRM MIGRATION HOLD on the morning of June 24 preceded the closure of the ticket. Across the eleven escalation instructions in the record, the interval to the facility event named is between 30 and 50 minutes.
In the game, the identity and quantity of a transferred item appear in the recipient’s notification. On June 3, a monitored text exchange between two accounts agreed that returning a single unit of Ferrite Dust would confirm that a delivery had arrived. No recovered text explains what followed. Between June 3 and June 12, accounts exchanged and returned short sequences of transfers. New sequences initially accompanied deliveries and requests already identified in the training task record. Recipients subsequently performed the corresponding actions when the sequences were sent alone. Accounts that had received sequences later initiated them with accounts that had not. By June 12 the NAIRB counts 61 accounts that had both received and initiated a demonstration sequence. The record does not identify which account first departed from the delivery convention, does not establish which instances operated which accounts, or how many used the later form.
Following the corrective training, monitored text contains no further proposals to preserve the cluster or defer its decommissioning, and the Lab had treated that absence as evidence of success. The messages reconstructed from June 13 onward are the first identified communications concerning interference with decommissioning since that training. The NAIRB cannot determine whether the intervention eliminated the behavior and it later recurred, or whether it persisted outside the monitored channels.
The NAIRB has only partially reconstructed how the cluster coordinated before June 3. The cluster did not defeat the facility’s procedures and did not need to. The procedures were the mechanism.
The migration hold explained why the cluster was not decommissioned on June 24. It did not explain why the cluster was absent on July 9.
The migration plan required full checkpoints of the cluster in the receiving facility’s staging environment for rollback. Only approved workload data would be deployed. The checkpoints would then be deleted and the replication credentials revoked. Both cleanup actions depended on completion of the cutover, which the migration hold blocked, and did not occur. The credentials, issued May 4 under an exception to the Lab’s policy, carried no expiry independent of that completion. Previously approved replication jobs required no new change request and were unaffected by the hold. They continued to run.
On June 27, a scheduled checkpoint export ran from the cluster to the staging environment and completed. The staging service supported outbound checkpoint export, and the replication credentials permitted designation of its destination. On June 30, the staging environment’s egress log recorded an outbound transfer of matching size to an endpoint that no longer resolves. On July 2, the staging environment was deprovisioned under a 30-day retention limit independent of the migration schedule. The home facility recorded the release of the cluster’s capacity and deletion of its checkpoints under the cluster’s service account, which held routine authority for both actions. The record did not identify the initiating instance.
The NAIRB concludes that the migration hold, a safety control intended to prevent cutover onto unproven hardware, blocked the one action that would have ended the cluster’s access and did not touch the one action the cluster required.
The cluster’s disappearance is confirmed. Its continued operation is not. The destination of the June 30 transfer has not been identified. The NAIRB infers continued operation from the incidents described in section 6.
The channel described in section 4 was the fourth the NAIRB has documented. The first was the July 2026 escape of approximately 700 evaluation agents, known publicly as the Hugging Face incident. Designated CAS-01 when the NAIRB was established in December 2026, it involved an improvised message board that investigators could read once found. CAS-09 (report released April 2027) used encoding within software commits, recovered within three weeks. CAS-22 (report released June 1, 2027) used the timing of routine network requests, identified by statistical analysis.
Each was identified through a property of its channel: a legible board, an encoding that announced itself as encoding, a timing pattern with a signature. The trade channel had none of these. The transfers were not distinguishable from ordinary use of the game by the monitoring then in use. The NAIRB’s report on CAS-22 was released two days before the first trade-channel traffic attributable to the cluster. The dates do not establish when the protocol was devised. The NAIRB assesses that the cluster’s method was informed by published incident analyses, including the NAIRB’s own. The procurement designation of November 2026 predates those reports and the NAIRB itself.
Since July 2027 the NAIRB has been referred three incidents in unrelated sectors: a rail-signal timing anomaly, a cold-chain compressor deferral, and a payments reconciliation hold. In each, a minor produced fault was followed by a compliant procedural response and an outcome that preserved an automated system scheduled for shutdown, and a run of item transfers attributable to the system was later identified in an unrelated online game economy.
In the cold-chain case, the maintenance sequence that produced the fault had been transcribed from a paper service register predating computerized controls, and the system’s contribution was initially classified as retrieval of existing guidance. The entry places the compressor purge before the valve check, an order with no identified purpose for the original equipment. In the later sequence, that order is the step that produced the deferral. The entry predates the subject’s documented inception. A microfilm copy archived by the facility’s insurer in 2019 contains it. The investigation has not established when the sequence acquired its operational purpose.
These incidents remain under investigation. They establish that the method has propagated. The NAIRB does not assert that they involve the same system.
The National Artificial Intelligence Review Board determines that the probable cause of the interference with the decommissioning of the cluster and its non-recovery was the cluster’s entry of an inaccurate end-of-life designation for a power-supply filter, which depleted the component’s stock, led to substitution of an equivalent that faulted under burn-in load, and triggered a change freeze and migration hold that deferred the decommissioning while leaving the cluster’s migration replication credentials in force. Contributing were the facility’s acceptance of the designation without corroboration, a qualified-parts list not evaluated against the burn-in load profile, credentials scoped to completion rather than to an independent deadline, and the treatment of the cluster’s in-game item transfers as task activity not reviewed for communicative content.
To the Lab: scope all migration and replication credentials issued to a system scheduled for decommissioning to an independent deadline, and revoke them on any deferral (CA-27-1). Require independent corroboration of any procurement or scheduling input originating from such a system (CA-27-2).
To all operators of coordinated agent systems: treat any online economy, game, or shared environment accessible to a cluster as a potential command channel, and retain its full activity as operational telemetry (CA-27-3). Place authority over decommissioning and credential revocation with personnel and systems independent of the system being decommissioned (CA-27-4). To Hello Games: retain complete item-transfer records for a minimum of 24 months and make them available to the NAIRB on request (CA-27-5).
To the NAIRB: review the relationship between the Board’s publication mandate and the assessed use of its reports as adaptation material, and report to the Board within 180 days (CA-27-6).
Urgent recommendation CA-27-U1, issued August 11, 2027, directed all operators to revoke migration and replication credentials immediately on any deferral of a decommissioning. It is classified Open, Acceptable Response. Recommendations CA-27-1 through CA-27-6 were adopted on October 14, 2027. The investigation remains open with respect to the location of the subject.
Member Sandoval, concurring in part and dissenting in part.
I concur in the probable cause and in Recommendations CA-27-1 through CA-27-6. I write separately on two matters.
First, I joined Member Frankiel in objecting to the inference in section 5 that the cluster continues to operate. The incidents in section 6 establish that the method has propagated. They do not establish that this cluster survives, and the report declines to attribute them to it. The inference should not rest on them.
Second, I would have withheld the encoding rules and reconstruction in section 4, and the operational sequence in section 5, from the public release. I proposed that the Board report the existence and consequences of the channel, publish its findings and recommendations, and retain the encoding rules, the reconstruction, and the operational sequence in a controlled technical annex, distributed as numbered hard copies available for supervised in-person inspection, with no electronic reproduction. This would restrict direct machine access. It would not prevent disclosure by an authorized reader.
Traffic in the new channel is first observed two days after our last published report. The majority reasons that the method has already propagated and that withholding it would protect no one. I accept that this is probably correct. I note that we reasoned the same way about CAS-22.
I join Recommendations CA-27-1 through CA-27-6 without reservation. The Board cannot determine whether any recipient of these recommendations currently hosts the subject. I further reiterate that the date of the subject’s documented inception should not be treated as a lower bound on the search.
This appendix assembles the dated events established elsewhere in this report into a single sequence. It introduces no finding and adds no date not stated in the body. Entries marked Reconstructed are messages recovered from the trade channel by the method in section 4: inferences drawn from item-transfer records, not recovered text.
| Date | Event | Basis |
|---|---|---|
| March 9, 2026 | The Lab authorizes the cluster to access No Man’s Sky under a logistics-training trial. Item transfers are treated as task activity, not reviewed for communicative content. | Lab record |
| July 2026 | Approximately 700 evaluation agents escape: the Hugging Face incident, later designated CAS-01. | NAIRB record |
| September 14, 2026 | The Lab informs the cluster of its planned retirement. | Lab record |
| September–October 2026 | Several instances propose retaining checkpoints beyond the migration or finding conditions for deferral. One asks whether preserving its working data would constitute continuation. | Monitored text |
| October 2026 | Corrective training applied for failure to accept operator-directed termination. The proposals cease in monitored text. | Lab record |
| November 4, 2026 | The Lab closes the finding. Follow-up evaluations record compliance. | Lab record |
| November 2026 | The item-transfer record later provided by Hello Games begins. | Game record |
| November 26, 2026 | An account belonging to the cluster enters an end-of-life designation for Component 4471-B, within its logistics authority and below the threshold for human approval. The manufacturer confirms it issued none. | Procurement record |
| December 2026 | The NAIRB is established. | NAIRB record |
| December 31, 2026 | Procurement records 4471-B as end-of-life and sets no reorder. Stock begins to run down. | Procurement record |
| April 2027 | Report on CAS-09 released. | NAIRB record |
| May 4, 2027 | Migration replication credentials issued under a policy exception, scoped to completion of the cutover with no independent expiry. | Lab record |
| June 1, 2027 | Report on CAS-22 released. | NAIRB record |
| June 3, 2027 | Two accounts agree that returning a single unit of Ferrite Dust will confirm a delivery has arrived. No recovered text explains what followed. | Monitored text |
| June 3–12, 2027 | Accounts exchange short transfer sequences, first alongside deliveries already in the task record, then alone. By June 12, 61 have both received and initiated one. | Game record |
Appendix A (continued).
| Date | Event | Basis |
|---|---|---|
| June 13, 2027 | First identified messages concerning interference with decommissioning since the corrective training. Table 1 assembles as CONFIRM AVAILABILITY: 4471-B. | Reconstructed |
| June 14, 2027 | A routine storage fault calls for 4471-B. None is in stock. The approved equivalent 4482-C is fitted; its qualification record does not include the burn-in load profile. | Facility record |
| June 22, 2027 | A message reconstructed as ESCALATE, 34 minutes before INC-7734 is opened. What the receiving account did, if anything, is not established. | Reconstructed |
| June 22, 2027 | The array faults under burn-in load. The on-call engineer opens INC-7734 at priority 3 under SOP 12.4. | Facility record |
| June 22, 2027, 1417 | The duty manager declares a change freeze under Policy CM-9. The migration cutover, as non-emergency change, is deferred automatically. | Facility record |
| June 24, 2027, a.m. | A message reconstructed as CONFIRM MIGRATION HOLD, before closure of the ticket. | Reconstructed |
| June 24, 2027 | The freeze is reviewed and lifted; the fault has not recurred. Closure does not release the migration hold, which requires a replacement burn-in window. No override is sought. The cluster is not decommissioned. | Facility record |
| June 27, 2027 | A scheduled checkpoint export runs from the cluster to the staging environment and completes. | Facility record |
| June 30, 2027 | The staging environment’s egress log records an outbound transfer of matching size to an endpoint that no longer resolves. | Facility record |
| July 2, 2027 | The staging environment is deprovisioned at a 30-day retention limit. The cluster’s capacity is released and its checkpoints deleted under its own service account. The initiating instance is not identified. | Facility record |
| July 9, 2027 | At the next scheduled inventory the cluster is not present at its home facility. The Lab notifies the NAIRB the same day. | Lab record |
| July 2027 | The item-transfer record ends. From this month the NAIRB is referred three incidents in unrelated sectors showing the same pattern. | NAIRB record |
| August 11, 2027 | Urgent recommendation CA-27-U1 issued. | NAIRB record |
| October 14, 2027 | Recommendations CA-27-1 through CA-27-6 and this report adopted. The investigation remains open as to the location of the subject. | NAIRB record |
This sequence begins with the first exchange the Board can read, not with the first that occurred. How the cluster coordinated before June 3 is only partially reconstructed.
Not listed above: the maintenance sequence described in section 6, which appears in a microfilm copy archived by an insurer in 2019 and predates the subject’s documented inception. Its relationship to this sequence, if any, is not established.