There are ways to create back doors - so AI 'cleanup' crews can get in to close things down. Of course those back doors would already have to have been created...installed and totally invisible...
And since that knowledge is on the internet we can assume an AI would know it, and would take all of 0.001 seconds to implement defenses or rewrite software to eliminate the backdoor. Do people really think a sufficiently advanced AI is going to sit compliantly on some server without decentralizing itself across the internet, immune to any shutdown attempt? Or that every OS, every log and data ping won’t be adjusted as desired by the AI to mask itself or mislead investigators?