This assumes that AGI is capable of being done “safely.”
That is an interesting assumption.
That is an interesting assumption.
It might even work, if you could do it.
Actually doing that is going to be essentially impossible, though the reasons are completely different.
For example, but not limited to: there's no point having an AI you're not using, using it — even as an Oracle — involves some kind of interaction with the outside world in the form of what questions you ask and what actions you take in response.