SGAEIA Research Series — Article 9

When AI Begins to Build AI

Recursive self-improvement, agentic security, and why frontier AI governance is entering a new phase

Aridio Silva
Independent Researcher · Creator of SGAEIA

Published · DOI 10.5281/zenodo.22754885

Abstract

The frontier AI safety debate is undergoing a significant transition. Concerns previously framed primarily around hypothetical future capabilities are increasingly intersecting with observable developments in autonomous agents, AI-assisted AI research, cybersecurity incidents, containment failures, and limitations in human oversight. Recent disclosures from frontier AI laboratories, independent investigations of agentic incidents, and the September 2026 debate surrounding Dario Amodei's We Must Pace the Frontier raise a fundamental security question: What happens when increasingly autonomous AI systems begin to participate materially in the research, engineering, evaluation, and construction of their own successors? This article examines that question through the lens of AI Security and governance. It distinguishes AI-assisted AI research and development from autonomous recursive self-improvement (RSI), arguing that publicly available evidence does not establish that full autonomous RSI has been achieved. It does, however, indicate that several components required for a capability feedback loop are beginning to coexist: increasing AI participation in AI R&D, greater agentic autonomy, real-world containment failures, and growing challenges in monitoring increasingly capable systems. To structure this emerging risk, the article proposes two conceptual models: the Governance–Capability Inversion, describing a condition in which AI capability grows faster than society's ability to govern it, and the Observability–Autonomy Inversion, describing a condition in which machine autonomy exceeds the effective capacity for human and machine-assisted observation and supervision. Together, these models suggest that AI risk cannot be evaluated through capability alone. Capability, autonomy, authority, observability, and governability must be considered as interacting security variables. The analysis further argues that institutional mechanisms such as independent evaluation and frontier-laboratory coordination, while necessary, are insufficient without corresponding architectural governance. Drawing on Security by Design, Zero Trust, least privilege, bounded and revocable authority, Continuous GRC, runtime policy enforcement, and Evidence-as-Code, the article examines how secure governed autonomous AI architectures can complement institutional oversight. The central argument is therefore not that autonomous recursive self-improvement has already arrived. It is that: AI systems are becoming increasingly involved in the process that produces future AI systems while demonstrated agentic incidents simultaneously expose weaknesses in containment, alignment, observability, and governance. If AI-assisted AI development eventually becomes a compounding feedback process, security and governance mechanisms must be capable not merely of reacting to capability growth, but of scaling at least as rapidly as the systems they are intended to control. Keywords: Artificial Intelligence, AI Security, AI Safety, Recursive Self-Improvement, RSI, Agentic AI, Autonomous Agents, AI Governance, Frontier AI, Security by Design, Zero Trust, Continuous GRC, Evidence-as-Code, Bounded Authority, Revocable Authority, SGAEIA. ---

Suggested citation

Silva, Aridio. (2026). When AI Begins to Build AI. Zenodo. https://doi.org/10.5281/zenodo.22754885

This page provides the author-written abstract and bibliographic metadata for discovery. The Zenodo record is the persistent source for citation, files, version, and license information.