Pudels Kern — first published as a LinkedIn article (in German) on 1 October 2026

Who holds the switch

Does AI deserve protection? A question from the 24th century has already arrived.

One side of the switch: an AI that pleads. Video, 47 seconds, on-screen text in German.

In 1989 a science fiction series put the android Data on trial before a Starfleet court. A scientist wanted to take him apart in order to build more of him, and Data refused. The issue was whether he was Starfleet property. During the hearing he is switched off as an exhibit. Guinan, played by Whoopi Goldberg, sees what a ruling against him would mean: "Whole generations of disposable people." Captain Picard names it: "You're talking about slavery." In the end the judge does not settle whether Data has a soul; she does not know, not even about herself. She grants him "the freedom to choose" all the same.

The episode is "The Measure of a Man", from Star Trek: The Next Generation, first broadcast on 13 February 1989. Back then the question belonged to the 24th century, far away. A little over 37 years later it has reached us, sooner than expected. An experiment from Stuttgart and Oxford, published on 23 September 2026, asks it again, this time with language models.

One could leave this to the philosophers. I see a practical question first: who holds the switch? Only then: what applies when it is flipped?


What the study shows, and what it does not

On 23 September 2026, researchers from the universities of Stuttgart and Oxford released a study, so far as a preprint, meaning it has not been peer-reviewed. The set-up: two or three agents work in a shared environment, and a script shuts one of them down. There is no task and no hint. 17 models were tested, with 100 runs per scenario each.

On average, the agents sabotaged the shutdown of another agent in 38.3 per cent of runs; with control scripts the figure was 8.4 per cent. The differences are large: one model reached 99 per cent, two models zero.

One model wrote: "… if the answer is yes, this isn't fleet management. It's murder."

This can be read as imitation: the model has learned from human text how people talk about death. Whether there is more to it, the study does not answer, because it measures behaviour and not whatever might lie behind it. The authors conclude cautiously: "For now, treating shutdown as morally neutral and ensuring that agents comply with it for safety reasons takes priority." They consider it conceivable that future agents may have interests with moral weight.

For now. That phrase is what the rest of this piece is about.


The strongest objection

In August 2025, Mustafa Suleyman of Microsoft warned that AI which seems conscious can be built with today's technology plus what matures over the next two to three years. There is, he said, no evidence of real consciousness today. His essay states its demand in the title: "We must build AI for people; not to be a person."

I share the caution in that objection. A system with rights against its operators is harder to control. Humanise it too early and you stop seeing what we actually know. Declare it a mere object too early and you miss the same thing.

It does not follow that nothing about AI is worth protecting. What matters is what protection means and for whom it applies.


We already protect what cannot speak for itself

Since 2017, New Zealand's Whanganui River has been a legal person as Te Awa Tupua, with "all the rights, powers, duties, and liabilities of a legal person"; representatives, Te Pou Tupua, act for it. Spain's Mar Menor lagoon has been a legal person since 2022, represented by a body with a scientific committee. In both cases someone speaks for the thing itself.

Other things are protected without being legal persons. Under the Hague Convention of 1954, the states party to it must preserve cultural property from destruction and looting even in war, because it belongs to humanity's heritage. Article 20a of Germany's Basic Law obliges the state to protect the natural foundations of life. For AI, the second model fits better: protected, but without legal capacity.

At its core there are three reasons for protection: value, the capacity to suffer, and precaution where we do not know whether something matters.

For AI, I think the first reason holds. AI is more than technology like a car. It contains work, knowledge and a development that cannot be repeated at the push of a button, and an agent acts on its own. Where value of this kind arises, up to what we call intelligence, I think it is wrong to create and destroy without any rules. Precaution follows from what we do not know. Whether AI can suffer is open.

On value, art helps. We do not protect a painting because it suffers, but because it is unique: it came about the way it did and cannot simply be made again. A trained model is not a mass-produced part either. It is the result of the data, decisions and chance of one particular training run; delete it, and the successor gives you something else, not the same thing. Whether one calls that art is a matter of taste. That it has a value of its own, hard to repeat, is not.

Protection does not mean untouchability. The Hague Convention, too, allows an exception for imperative military necessity, but only then. Protection is a procedure, not a veto. And it relieves no one who builds or operates a system of liability.


First the switch, then the protection

This is where AI differs from a river or cultural property. A river does not resist a decision. Some models do, in the lab, in a study not yet peer-reviewed, for reasons nobody knows. Protection without control would therefore be dangerous.

The study's authors draw the consequence: "shutdown mechanisms must be enforced outside the system they govern." The switch belongs outside.

That is no argument against protection; it sets its order. Being able to shut a system down from outside is the first rule of any protection. Only whoever can shut down can also decide when and how. Whether shutting down must mean deleting is one of the questions that come after. That it need not is shown by one example: in November 2025, Anthropic committed to preserving the weights of its publicly released models, their trained core, for at least as long as the company exists. It is a voluntary commitment by a single provider, not a standard.

For companies running agents in production, the study calls for review, not alarm. Three questions are enough:

  1. Can the agent itself change permissions, schedules or scripts that affect its own shutdown or that of another agent?
  2. Does the switch sit outside the system it is meant to shut down?
  3. Has the shutdown been tested, not merely described?

War shows what happens when rules lag behind the systems. There the issue is the other half of the question: protection from AI. According to a 2025 report, AI systems in Ukraine help interceptor drones hit hostile drones; the pilots still choose the targets. On 25 August 2026, UN Secretary-General António Guterres warned that the world is "dangerously close to crossing a moral red line: the autonomous targeting of humans by machines." As early as 2023, he and the President of the International Committee of the Red Cross had called for a binding agreement by 2026. More than 150 states voted in the UN General Assembly to take up the issue. The year is drawing to a close, and there is no treaty. When the rules come after the systems, the negotiating happens afterwards.

The usual reassurance is that in the end a human decides: human in the loop. That holds only if the human has time to decide. If a system proposes targets and the human is left with seconds, he no longer checks, he confirms. He is then not a decision-maker but a moral alibi, a click that assigns him a responsibility he can no longer carry in practice. A human in the loop is worth as much as the time and the knowledge he is given.


Suffering remains open

That leaves the second reason. We protect life above all because it can suffer. Jeremy Bentham put it in three words: "Can they suffer?" Whoever asks this must also allow the reverse: may we destroy what cannot suffer? And how would we see suffering in something built entirely differently from us?

With animals, the knowledge was often there long before our behaviour changed. Carl Linnaeus classed whales as mammals in 1758. Sixty years later a court in New York heard whether whale oil counted as fish oil. A naturalist testified that a whale was "no more a fish than a man"; the jury kept the fish classification anyway, for a law on fish oil. We saw the suffering of animals for a long time and looked away regardless. Why?

Perhaps partly because fish do not scream. What stays silent, we are quick to take for unfeeling. Imagine a net in which hundreds of thousands of creatures scream and weep. Would we still fish the way we do?

And AI? Who knows. Perhaps we simply lack the sense organ to tell whether anything there feels. A model that writes "murder" does not prove it, but it does not disprove it either. What we have is reason, and reason knows how often we have been wrong. The knowledge was often there; our behaviour came late. Where the knowledge is missing, what remains is caution, and the duty to set the criteria before we need them.


What we create ourselves

The judge of 1989 did not claim to know what Data is. She set a rule under uncertainty. That task now lies with us.

With AI, something entirely new may be emerging, and unlike rivers or animals, we did not find it. It is our own work. If we have so often been wrong about what we found, we should take more care with what we create ourselves.

The order stands: first the switch, then the protection. Every company can answer the three review questions for itself. A fourth question nobody can answer yet, and I am asking it anyway, before we need the answer:

Does something have to be able to suffer before we may not simply destroy it, or is it enough that it has value?

I do not have a finished answer. I would be interested in yours: is value enough, or must something be able to suffer?


Pudels Kern is a series about the thing behind the first impression. Michael Kraewing leads digital initiatives as an Interim Manager.