AI risk is not always inside one model. Sometimes it comes from the way many AI parts work together.
Cognivirus.com explains how AI behavior can survive, move, or reappear across models, prompts, memory, tools, adapters, and evaluation systems — and why consent, visibility, and system-level safety checks matter.
A cognivirusA behavior pattern that can survive, move, or reappear across a changing AI system. Open glossary definition is a proposed analytical metaphor for a behavior patternA repeated way the AI system responds or decides. Open glossary definition that can persist across a changing AI system. It is not a literal virus, not a consciousness claim, and not a malware category.
Start with the plain-English guide · Most likely threat model · See simple examples · Read the technical research · Why consent matters
Animated transition graph image links
Animated transition graphs are shown here only as compact static image thumbnails. Each thumbnail opens a dedicated full-width detail page where the static image appears first, the video plays in place once after loading, and the page returns to the static image.
Animated graph pages
Open the three full graph pages directly from here. Each thumbnail links to a dedicated static-first image/video page: model change-out, mitosis-like reproduction, and recursive branching.
open pagegoverned replacementChange-out and new model creation How an active model is evaluated, branched, gated, replaced, retired, and checked for residue.Open graph page · Open image/video page →
open pagecontrolled splitMitosis-like reproduction How a governed parent model-and-adapter assembly can be split into two daughter lineages under checks.Open graph page · Open image/video page →
open pagebehavior persistsRecursive mitosis-like branching How behavior can remain expressible across generations while carriers, routes, and scores change.Open graph page · Open image/video page →No animation is required to understand the site. Static posters, captions, and text equivalents remain the canonical content. Open the animated graph index.
The model is no longer the system
Testing one model is still needed, but in complex AI systems many factors combine to affect behavior: configuration files, prompts, memory records, adapters, tools, routes, and evaluatorA system that judges whether an AI output or candidate is acceptable. Open glossary definition versions. The safety boundary is becoming the whole system. For visual detail, open the animated transition graph pages or the interactive schematic reference.
Most likely threat
The most likely high-consequence threat is distributed behavioral persistence: a useful-looking behavior enters through one carrier, gets rewarded by the system, moves into memory, routes, data, evaluators, descendants, or human procedures, and then survives the retirement of the original artifact. Read the threat model.
Decentralization makes the transition graph harder to see
Local AI, private agents, edge runtimes, and cognitive interfaces can improve privacy and control. They can also create more places where behavior persists: adapters, memory, vector stores, router statistics, evaluator logs, tool histories, browser caches, handoff packets, and derived dataInformation created from original data, such as summaries, labels, embeddings, inferences, or examples. Open glossary definition. Cognivirus.com treats this as a control-plane problem: the more distributed the AI ecology becomes, the more important it is to show what changed, what was remembered, what was reused, and what rollback actually clears.
Decentralization can hide residue
Local AI can protect privacy, but it can also move AI state into places a central operator cannot see: adapter stacks, vector stores, browser caches, tool histories, evaluator notes, handoff packets, and local memories. The safety question is not whether the model runs locally or in the cloud. The safety question is whether the whole transition graphThe map of how an AI system is allowed to change over time. Open glossary definition is visible, bounded, consented, and resettable.
Read the decentralized persistence surface · Edge Runtime Reproduction Boundary · Consent & Control · Danger Model · Risk Lab checklist
Local is not automatically safe. Cloud is not automatically unsafe. The safety question is whether the system’s transition graph is visible, bounded, consented, and resettable.
7 key AI risk lessons
The home page keeps this as text. Detailed diagrams remain on their dedicated reference and animated-graph pages.
- Each part can pass a safety test, but the combined system can still fail.
- Deleting one model may not remove a behavior copied into memory, examples, prompts, adapters, or evaluation rules.
- An evaluator can share the same blind spots as the AI it judges.
- A rollbackReturning a system to an earlier known state. Open glossary definition can restore model weights without restoring history.
- A routing decision can create a capability that was never tested directly.
- Selection can amplify loopholes without malicious intent.
- Responsibility becomes less clear as intelligence becomes distributed.
Where behavior can hide
A cognivirus is not a literal pathogen. It is a proposed analytical metaphor for a pattern that can be carried by models, adapters, prompts, memory, routing rules, datasets, evaluators, or descendants. The site studies how such a pattern could remain functionally present after its first artifact is removed.
Consent turns data handling into safety engineering
If an AI system can remember, infer, reuse, share, or transform information about a person, that person should have meaningful notice and control.
Safety in isolation is not system safety
Research on combinations of individually safe models, model mergingCombining model weights or adapter deltas into one artifact. Open glossary definition, adapters, reward hacking, and multi-agent behavior shows that isolated component results can fail to predict composed behavior. The limits vary by experiment and architecture, so Cognivirus.com labels claims by evidence level instead of treating every risk as universal.
Retirement is not extinction
Removing a model can remove one carrier. It does not automatically remove memories, synthetic examples, router statistics, evaluator preferences, adapterA small add-on that changes or specializes model behavior. Open glossary definition deltas, or descendants that may preserve the same behavior.
Evidence, not mythology
Claims on this site are labeled as one of six evidence levels: shown in real systems, shown in experiments, early evidence, reasoned from system design, not proven yet, or possible future concern.
See supporting research and data · Read the glossary · Contact / About Michael Kappel
ModelBreeder and Cognivirus separation
ModelBreeder can go deeper on what controlled model evolution makes possible. Cognivirus should go deeper on the risk side: how model populations, adapters, novelty archives, edge runtimes, evaluator pressure, memory, and dashboards can preserve behavior after the first carrier is gone. Read the risk-side synthesis.
Final question
The unsafe unit is not always the model. Sometimes it is the transition graph.
The danger model in one sentence
The central risk is not that every AI part is dangerous. It is that a changing system can preserve a behavior through transitions: seed, compose, express, reward, record, derive, route, promote, forget the origin, and fail to roll back completely.