Seems as it would be easier to slip in some anti-training, and have the AIs screw systems up so badly that there is a 'recall' of all the current models. The LLMs and their corresponding systems crawl the web constantly. So, poison the well. Good data behind paywalls and credentialing and the poison pill open and free. Seems like it'd be worth a try anyway.
Is this the equivalent to the humans nuking the sky to fight the robots in the Matrix? I don't think that worked.
I mean, from an incentive and capability matrix, it seems probable if not inevitable.