This is obviously incorrect. If an AI system of superhuman mental capabilities is installed on a system with no network connection and no physical interfaces, we can completely control the harm is might create. It would be unable to directly act, of course, requiring humans to authorize and carry out whatever plan it devises. But failing to do this should be prosecuted and treated no differently from if a person or company built a tank and then permitted it to drive over and through people. The biggest difficulty here will be that our legal frameworks have no established way to assign liability and criminal culpability to any system involving software. With no legally-enforceable industry standards (like the electrical code followed by electricians, things like that) any prosecution fails as the company can either claim ignorance of the potential harm their system might cause or simply throw individual employees under the bus, claiming they were not acting on direct orders.
It is true that we can not fully specify the goal, and that is a grave concern. It's partially due to this that AI systems shouldn't be directly connected to the ability to act in the physical world unless their attempted actions go through some sort of 'filtering' first.