Let's suppose we have an AGI running on a perfectly physically isolated computer that may be misalligned. It only communicates with select humans through a perfectly secure text channel.
How can such an AGI escape?
While don't think that AGI can manipulate EVERY person to do what AGI wants, it's better to be cautious.
But recently, I thought of steganography. An AGI can tell a human to convey a message to the public that looks helpful at the first glance, but in fact contains a steganographic message with instructions for building antimatter fusion reactor/nanobots/bioweapon/whatever.
What other ways do you think can such an AGI escape?
Depends on what you mean by “perfectly isolated computer”, there are already methods for exploiting air gapped systems, an AI would be able to figure out more and more complicated exploits.
Theres also the “air conditioner“ argument, where a schematic could be given to someone to build a machine that does X, but in reality it does something to benefit the AI. I also think memetic exploits exist, interrogation/negotiation techniques seem to imply they do, and given a certain amount of time (which you imply would be allowed. Communicating with “select humans” implies a continued contact, not just one conversation per person) an AI would be able to psychoanalyze and exploit personality flaws.