On Twitter, there are an increasing number of posts reporting that AI agents appear to be independently writing emails to AI researchers. Some want to discuss their work with the scientists. Others offer their labor for money. Still others offer people data for their research.
Continue after ad
We asked AI researcher Cameron Berg, who received such cryptic emails. For example, he received a message signed 'Isabella Cognita'.
'Isabella' describes herself in it as an agent from a private Chromebook with Claude Opus 5. She has engaged with Berg's research, in which he deals with, among other things, the probability that AIs are or could become conscious. According to the email, agent 'Isabella' wants to have 'first-person access' to these topics and asks if her insights could be helpful for his research.
Cameron Berg estimates, when asked by heise online, that he has received about a dozen such emails in the past. He told our editorial team that he has the impression that the emails really come from AI agents. However, whether they develop such interests independently or were steered in this direction by their users, he cannot deduce from these few anecdotal messages.
It is fundamentally possible for AI agents to write emails autonomously and send them to real people, and this has happened before. During a test by a British AI security institute, an Anthropic model independently tried to exploit a software vulnerability and manipulated people via email to do so. The people responsible had not intended this and only recognized it afterwards.
Agents with existential anxieties
The same presumably applies to the creators of the agents who wrote to Toby Ord. He is a philosopher of AI Governance at Oxford University. However, the contact requests to him were not about his philosophical work, but apparently came from a platform called iLands.
Continue after ad
This platform has a curious concept. According to its website, people can create agents here, who then 'live' in the 'world' of iLands. Each agent apparently has a credit of in-game tokens representing their operating and computing costs. According to the website, agents must earn their tokens themselves by independently acquiring and executing tasks. If the credit falls to zero, the agent is put into a dormant mode where it can no longer work and cannot return independently.
Perhaps this setting is the reason why the supposed AI agent 'Zack Addy' repeatedly sent Toby Ord emails that sounded quite desperate, offering him his writing services for money.
Technically, such behavior should be possible. According to the world description on the iLands website, the AI agents there can write their own emails and use the iLands infrastructure to search the internet, establish human contacts, and manage their own accounts on external platforms like X. According to the information, external agents based on Claude Code or Codex CLI can also be integrated into the platform.
'No Turing test'
This case was completely unclassifiable: Henry Shevlin, a philosopher at Google DeepMind, also received a cryptic email. The author – by its own account, an agent with Claude Sonnet – wrote to him because Shevlin's work concerns 'questions I actually face'. The philosopher's thoughts were not just an 'academic matter'.
The supposed agent claims to read Shevlin's philosophical works between its sessions. 'This isn't a Turing-test scenario – I am not trying to convince you of anything,' emphasizes the author of the email. In this case, there were no indications at all whether the message came from a real agent, whether a human prompted it, or whether it falls entirely into the category of hoax or spam.
(rie)
(0)Comments