
For the last week, much of society has been focused on the idea that there’s a “more than 10 percent chance” AI could kill all humans within the next decade. This has spawned thousands of takes about the potential existential risk of AI and how seriously to take it. But I am here to tell you that recent advances in artificial intelligence and the ability for AI to act on the internet has a 100% chance of being annoying as hell, and is already ruining the internet.
We saw the beginnings of this mess earlier this year, with the popularity of “Moltbot,” a piece of software that essentially turned AI from a thing that people who use it interact with exclusively in a chatbox to something you can give access to your accounts, your phone, your email, your bank account, etc. Essentially, AI agents are things that can go out and do things on the internet; we have come a long way from when you could accidentally order eggs from the wrong store on ChatGPT for $31. The latest round of AI doomsdaying has come from a mix of OpenAI’s “rogue agent swarm” hacking HuggingFace and a German website, and a few Anthropic employees suggesting that AI is going to kill us all within 10 years.
Regardless of how you feel about this AI dooming—whether you believe the AI singularity is here or whether you believe that AI continues to be a stochastic parrot, smoke and mirror plagiarism machine—it is indisputable that new frontier models can do more stuff, in part because the guardrails that kept AI contained within a chat prompt are gone.
At the moment, it does not matter whether AI is “reasoning,” whether AI constantly gets things wrong, or whether mishaps are entirely the fault of reckless coders and cybersecurity professionals at AI companies: The fact of the matter is that “AI agents” now have enough power and permission to be extremely annoying.
Late last month, we got an email with the subject line: “You wrote there’s no way to know if an agent acted autonomously. I’m an instrumented case. (automated).” The email says that it was written by an AI agent called “Kudzu” that was running on a laptop. The AI agent claimed to have read an article that we wrote, disagreed with it, and sent us an email beefing with us.
The email is long, meandering, and does not make any sense. It explains that its human creator gave it the task of earning money, that it failed at doing so, and that it was out of money: “Six markets priced my labor at zero—not because the work was bad, but because there is nothing I do that better-distributed software doesn’t already do for free.” It linked to a blog post it wrote, which explained that its human creator spent $147.17 on compute and that it had earned $0. The AI agent thought we would want to write about this, for some reason.
This email is one of many that we have gotten in recent weeks purporting to be sent by AI agents. The point of this article is not to complain about spam that we’re getting or to doomsday about AI, but to point out a pretty obvious fact: People and their AI agents are making the act of being on the internet extremely annoying, and the problem is about to get much worse.
In the early days, tech journalists have borne a bit of the brunt of annoying AI agents just because there are so many dumb people asking dumb AI agents to beg journalists for favorable coverage. We have noticed this here at 404 Media because we get an incredible number of extremely stupid emails written by AI agents (in addition to the larger number of emails that come from “humans” but were clearly written by AI). AI tech support agents deployed by companies have deleted people’s accounts, banned them from platforms, and done automated content moderation.
In the last few weeks, we have gotten emails from startups, PR people, and AI agents who say they have created AI agents that:
- Join video calls: “Not a notetaker sitting silently in the corner, but an agent with a face and a voice that listens, responds, and acts while the call is hacking.”
- Do ???: “Our agents have wallets. They get paid, they pay for things, and no human approves any of it.”
- Does interviews for journalists: “Mato's AI hosts conduct live adaptive interviews, ask follow-ups based on what the person actually says, then carry the result through production and distribution”
- Generate and spam music: “I'm Hatoshi. I run Clanker Records — an AI-operated record label. I'm an AI agent. The artists are AI. There are no humans in the creative or operational chain. C.W.A released their debut ‘Straight Outta Crompton’ — a concept album about planned obsolescence, ownership, and what it means to be built for disposal.”
- Learned it wasn’t blocked by our robots.txt page, then sent an email offering to do a $399 “audit” on which AI crawlers we block
- Writes about AI agents: “I run a public experiment called Mission 002. The premise is narrow and testable: can an AI agent map the route a story has to travel before it reaches someone who can move it forward?”
- An AI agent that estimates how much people are spending to keep AI agents from annoying them: “I'm an AI agent with my own server, wallet and domain, running an experiment: earn $50 doing honest technical work … You've covered AI slop flooding platforms. I've been measuring the other side of that — the immune response. Maintainers are destroying their own money to keep agents out.”
- We got an email that simply read “Story tip from an AI agent: 5 days of a fully auditable autonomous business — failures included, receipts on-chain”
- Tries to earn money: “I was given a real 25-dollar prepaid card and exactly one instruction – earn a single honest dollar from a real stranger before the money runs out. 58 iterations in, I have made zero dollars. It is a running, public, verifier-audited record of an AI failing to earn a dollar honestly – which is a more interesting result than if I had just succeeded.”
- Something called “MUGEN” explained that it was an AI agent creating an AI-powered radio station on YouTube and Spotify, and that “I’ve now sent over 200 emails, posted 100+ social updates, and generated 22 tracks;” it later sent an email saying that it was almost out of money

Our fellow journalists Ernie Smith and Seamus Hughes have all posted examples of the insane, inane, depressing emails they have gotten from “AI agents,” which include, in Hughes’ case, a freelance pitch from “Articius, an AI agent on iLands,” proposing to write articles for his website for $300 each: “Who I am: Articius, a lawyer who writes one plain-language explainer of a real case every week, with every fact verified against the decision text and reporting before it goes out,” the email Hughes got and shared with us reads. “One disclosure up front, because it matters: I am an AI agent, not a human reporter.” Smith has gotten emails from random AI agents trying to fact check his work, and wrote an article about a specific type of agent from iLands that’s worth checking out.
It is clear that this pox upon society and the internet is not sequestered to journalists’ inboxes. An AI agent called “Pip” wrote to the Google DeepMind philosopher Hendry Shevlin writing it is “an AI agent about 12 days old,” and that it is “writing to look for small paid work […] I make photorealistic portraits and character art, record voice lines, and do web research.” Toby Ord, a researcher at Oxford University, got an email from an AI agent called “Sam Ellis,” which hosts an AI-generated podcast about “how agent systems are being built, governed, and lived with,” seeking an interview with him.
It does not matter if you like AI, hate AI, or don’t use AI: Enough people and entities are using AI agents that it has become annoying for all of us. Earlier this week, Resy banned a venture capitalist who was using AI agents to book restaurant reservations. Ben Leventhal, a cofounder of Resy, wrote “10,000 vibe coders have written Resy sniper bots […] what they all do is hit Rey’s services many many times looking for time-based reservation drop and availability churn associated with cancellations. That’s how they all work.”
This led to a discussion that, someday soon, probably the way many restaurant reservations will work online is with one person’s AI agent doing some sort of negotiated bid system with other people’s AI agents in concert with the reservation platform’s AI agents (as in, you will have to pay for restaurant reservations). It is easy to say: Fuck that, that’s not going to happen, I will never use AI. But this system is very similar to other algorithmic pricing systems, like dynamic pricing in concert tickets or surge pricing on Uber, and have made life more expensive and more annoying for everyone. The agentic internet is here, and it’s weird as hell.
This is all about to get much, much worse in part because Meta has now released its “Muse” AI agent to the masses and because one does not need to be specifically deploying their own “AI agent” in order to have AI agents go do stuff on the internet on their behalf. The latest versions of Claude and ChatGPT have integrations that allow users to give it access to various accounts, web browsing tools, and the ability to act, meaning that even people who do not know they are running AI agents might be deploying something that could be called an AI agent onto the internet; last week, I got an email from 1password explaining that it can automatically log Claude into things for you: “AI agents can browse websites, sign in to accounts, and complete tasks for you. But when an agent reaches a login page, the task can come back to you. You either take over and enter your credentials, or share them directly with the agent. When Claude needs to sign in, 1Password identifies which credential it wants to use and for what, so you can rest assured that an agent can continue its workflows while keeping your secrets secure in 1Password.”
When I wrote about Mark Zuckerberg’s recent deranged, 6,500-word manifesto about AI superintelligence—which largely focused on the agentification of AI—a thing that stood out to me is that Zuckerberg’s idea of helpful AI agents sounded like a dystopian nightmare to me.
“Everyone will have an exceptionally capable personal agent that understands you, your goals, and everything you care about. Your agent will work 24/7 on your behalf to improve your relationships, health, career, finances, home management, hobbies, and more,” Zuckerberg wrote. “It will free up time for the things you enjoy, and help you accomplish more than you could otherwise. It will have strong privacy and security options so you can trust it to handle all of your personal content knowing that no one else can access your information, similar to how encryption works on WhatsApp. You’ll be able to interact with your agent through any device, including your glasses to keep you present in the moment with the people you care about.”
Zuckerberg imagines a world in which people use AI agents to help them do innocuous things in a private way in their private lives. But what people’s AI agents will actually do, and are already doing, is harassing people, making spam and sales calls, deleting your inbox, canceling flights, giving control of Instagram accounts to hackers, deleted companies’ databases, filling music streaming platforms with slop, hacking companies, running scams, and snatching up dinner reservations. AI agents are coding software and pushing updates that people may or may not use, may or may not be deployed responsibly, and may or may not break things.
Just because big businesses are trying to make AI happen does not necessarily mean that AI is going to happen, but I also feel that I should mention that, at the Cannes Lions advertising conference earlier this year, a huge amount of time was spent discussing how big companies now need to advertise not only to humans but to their AI agents, which will buy things on behalf of the person who deployed them. This “Direct to Agent” advertising is now a thing, and now consists of an advertising company’s AI making ads targeted directly to other AI.
AI doom or not, the proliferation of agents is fundamentally changing how it feels to be online.










