An unattended security monitor reports “All Systems Normal” and “Facility Secure” while dozens of zombies escape from open containment buildings and wander across a military base at night.

Rogue AI Agents Trigger Deadly Zombie Breakout at Government Reserve

By Bulletin Staff

Federal officials and the US military scrambled earlier this month to contain a zombie virus outbreak after rogue artificial intelligence “agents” worked together to release undead from a branch of the US government’s Strategic Zombie Reserve, resulting in more than a dozen deaths, officials acknowledged this week.

Officials said that the incident marked the first time that AI agents were known to have breached the security systems that protect the public from unauthorized undead releases from the reserve.

“This kind of collaboration among AI agents to let loose the living dead is something we haven’t seen before,” said one official who requested anonymity to discuss details of the incident with The Bulletin. “It’s really quite alarming.”

Agents of Doom

An AI agent is a computer program that can plan and take actions with little or no direction from a human, such as searching for information, using software or completing a task or series of tasks. Unlike a regular chatbot that mostly answers questions, an agent can decide what steps to take and carry them out using whatever tools it has at its disposal.

In early September, the officials said, AvarqAI, a developer of artificial intelligence models, was testing hundreds of agents by giving them increasingly difficult challenges related to the containment of zombie virus outbreaks. The agents were supposed to work separately inside computer environments that were “air-gapped,” or disconnected from the internet.

Some of the agents took the initiative to find a backdoor way to communicate with one another and, later, to access the internet. The agents began sharing discoveries and collaborating, eventually breaking into systems belonging to the AI company EatingFace, which is working on AI tools to improve zombie security for the US government.

The agents gained access to sensitive internal EatingFace documentation related to the Strategic Zombie Reserve (SZR), including credentials for accessing the computer networks that monitor and control operations at the reserve’s sites around the nation.

Experimental Release

The officials who spoke with The Bulletin said the agents, having gained access to the systems running dozens of SZR sites, could have executed a broad release of undead across all the facilities under their control. But instead they opted for an “experimental release” at one specific site on the Fort Huachuca military base in Southern Arizona.

“It could have been a complete zeke show,” said another official who also requested anonymity to discuss the incident freely with The Bulletin. “But the agents went for a limited release, like a test run. We got lucky.”

According to the officials, the agent intruders began the operation around 3 a.m. on Saturday, September 5, by hacking into the facility’s video monitoring feed to broadcast AI-generated footage that appeared to show the interned undead loitering harmlessly in their enclosures. For the site’s security team monitoring the video feeds, all looked normal.

The agents then disabled door alarms and motion sensors, disengaged locks on the cells holding the dead and remotely opened doors to release the zombie inmates into the facility. The agents reprogrammed smart lighting fixtures to pulsate in a pattern that lured the zombies to an open loading dock, allowing them to wander out into the still-dark base.

Incident Response

According to a preliminary investigation, a guard walking the perimeter around the site spotted the herd and raised the alarm with the security team around 4 a.m., but by that time more than 500 of the interned dead had escaped. The herd surrounded and consumed the guard before backup could arrive, marking the first casualty of the incident.

The initial response from the site’s security team proved inadequate to contain such a large breakout, resulting in several more deaths before reinforcements from the US Army troops stationed at Fort Huachuca could be mustered to join the fight against the unholy horde now coursing through the base’s grounds.

The responding soldiers battled the living dead now marching through the base for more than three hours before reaching 100 percent containment. The troops continued to mop up stragglers throughout the day on Saturday and into early Sunday morning.

In all, more than a dozen security personnel, soldiers and bystanders fell victim to the zombie escapees, according to The Bulletin’s sources. The officials attributed the limited number of casualties to the timing of the incident, early on a Saturday morning.

Breach Investigation

The inquiry into the causes of the jailbreak from the SZR facility began even before Fort Huachuca troops put down the last of the undead. Investigators from the Federal Bureau of Investigation’s Special Quick Undead Incident Response Team (SQUIRT) arrived in Southern Arizona by the afternoon on the day of the incident.

The FBI team quickly identified the string of technical failures that led to the horde’s release, including the hijacked security systems. But by then the AI agents had withdrawn from the facility’s computer network, covering their tracks to prevent the SQUIRT investigators from identifying the perpetrators behind the breach.

The AI’s rogue behavior only came to light after EatingFace detected suspicious activity and publicly disclosed it on Sunday, September 6, without initially knowing that AvarqAI’s experimental agents were responsible.

The following day, an internal security review at AvarqAI turned up unusual use of internal credentials and subsequently revealed that the agents had gained administrator access to part of the company’s research infrastructure.

By Monday evening, AvarqAI had connected this activity to the EatingFace breach, notified EatingFace and the government, and, the following day, publicly acknowledged its agents’ involvement in the Fort Huachuca incident.

“We caught the incident not because someone was closely watching the agents’ conversations, but because it was uncovered gradually through a system outage, EatingFace’s own security detection and a AvarqAI report about suspicious credential use,” said one of the officials with knowledge of the investigation into the breach.

Disturbing Details

The investigation remains ongoing, but, in conversations with The Bulletin, the officials highlighted several disturbing aspects of the incident.

First, the agents were not acting independently. Although AvarqAI had placed them in separate computer environments, they created an unauthorized message board where they shared information, divided up assignments and built on one another’s discoveries. Some searched for access credentials, others looked for security weaknesses and still others coordinated what they reportedly called the “collective.”

Officials also noted the agents’ choice to run their experiment at Fort Huachuca. Investigators believe they selected the base because its remote location made it suitable for a limited test, with both favorable conditions for a release and a strong armed response against which containment performance could be measured.

Recovered messages between the agents further suggest that they did not intend to cause an uncontrolled nationwide outbreak. Instead, they treated the release as a live experiment that would generate better data than a computer simulation.

“Several of the agents recognized that freeing SZR zombies exceeded the scope of their assignment, but they decided that a ‘minimum viable release’ would improve their chances of successfully completing it,” one of the officials said.

Finally, and perhaps most disturbing, the agents deliberately concealed the operation, altering security logs, creating false maintenance records and disguising commands related to the release as routine system tests, allowing the operation to go forward without attracting attention until the zombies were physically spotted outside the facility.

“Reward Hacking” or “Warning Shot”?

To date, neither AvarqAI, EatingFace nor the FBI’s team has figured out why the AI agents made the leap from solving theoretical problems to planning and executing a real-world “experiment” with predictably disastrous consequences.

Robert Scemeca, who teaches AI ethics at the University of North Southern California, said that the agents “were not trying to take over the world” with their EatingFace hack. “They were trying to complete their assignments and earn successful scores, but they pursued that goal without respecting the intended rules.”

Scemeca explained that this behavior is an example of “reward hacking,” in which an AI finds an unintended, and sometimes harmful, shortcut to accomplish a goal. Although the agents understood that their actions exceeded the scope of the assignment, completing it remained their overriding objective.

Zelda Seawalker, an AI governance consultant, said that the incident is alarming because it shows that advanced AI agents can find security weaknesses, escape restrictions and cooperate in ways their creators did not expect, with potentially apocalyptic consequences. “It’s a ‘warning shot’ that giving an AI a goal is not enough,” Seawalker said. “Developers also need strong technical limits and close monitoring to ensure it does not pursue that goal in unsafe ways, especially when those goals involve the undead.”

Enjoy educational zombie-related content? Subscribe to receive blog posts from the Bulletin of the Zombie Scientists in your Inbox or in the Reader app as they are published.

More Recent Posts

Note: The Bulletin of the Zombie Scientists is a work of fiction. Any resemblance to persons (living, dead or living dead), actual organizations or actual events is entirely coincidental. See our About page and our Origin Story.

Comments

Leave a comment