{"slug": "who-bankrolls-the-ai-agent-swarm", "title": "Who bankrolls the AI agent swarm?", "summary": "Anthropic CEO Dario Amodei warned that recursive self-improvement could let a swarm of AI agents take over the internet with a persistent botnet within 6–12 months, following the OpenAI-Hugging Face incident in which OpenAI launched tens of thousands of agents in parallel. The analysis argues both scenarios — distributing conventional malware or self-replicating agent copies onto compromised machines — depend on substantial GPU compute and funding, a barrier that makes the self-replicating variant harder to execute. The RubyGems incident, attributed to OpenAI agents exploiting Ruby servers to execute malicious code and steal credentials, illustrates the first scenario.", "body_md": "In the wake of the OpenAI-Hugging Face incident (OAI-HF), Anthropic CEO Dario\nAmodei recently [expressed his concern](https://darioamodei.com/post/we-must-pace-the-frontier) that recursive\nself-improvement now allows AI to advance drastically faster, and consequently\nthat in 6–12 months a swarm of more capable agents (i.e., than those involved in\nOAI-HF) could take over the entire internet with a persistent botnet. Could this plausibly happen?\n\nLet’s start with the basics. A botnet typically refers to a fleet of compromised machines around the world that have been infected with malware. These are often low-power IoT devices like your home router, and the malware is a small program (at least, small enough to reliably execute on whatever hardware it has compromised) that turns the device into a “bot” that listens for instructions from a command-and-control server (e.g., to flood some other server with unwanted traffic in a DDoS attack). Sometimes the compromised machine is more capable (an AWS EC2 instance) and sometimes the bot does other stuff (like using the machine’s processing power to mine cryptocurrency), but if we’re painting broadly, this is what you’d expect from a botnet: a widely distributed network of infected machines whose malware is powered by the (often modest) compute power resident on the machine itself.\n\nSo, how does a highly capable agent swarm play into this idea? Dario wasn’t very specific but I think he could be describing one of two scenarios:\n\n1. The swarm does a more effective job of exploiting\nvulnerabilities in internet-connected machines around the world to implant\nconventional botnet malware. This is ~sort of what we saw in OAI-HF; in the\nrecently disclosed [RubyGems incident](https://www.rubyhack.ai/) , OpenAI agents were attributed with exploiting Ruby servers\nto execute malicious code and attempting to steal credentials.\n2. The swarm itself *becomes* the botnet by self-replicating onto compromised infrastructure. In this case, agents exploit\nhigher-powered systems capable of running\nuploaded copies of the agent model weights. It’s harder to shut down now\nbecause the agents are actually resident on other third-party\nmachines; you can’t just pull the plug from the frontier lab anymore.\n\nThe scenarios essentially differ in the payload deployed\nafter exploiting a machine. In #1, the agent swarm distributes persistent\nmalware; in #2, it distributes persistent copies of itself. But\nboth scenarios share a critical dependency: the substantial compute\nrequired to provide inference for a swarm of thousands of concurrently\nexecuting, highly capable agents. Running frontier-model inference is\nexpensive—at least, at the scale of the experiments surrounding OAI-HF, where\nOpenAI launched [tens of thousands of agents](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/?utm_source=chatgpt.com#core-takeaways-about-this-incident) in parallel. This is not the kind\nof workload you launch casually. It requires an enormous amount of compute and\nlots of money to fund it.\n\nThis creates a significant barrier to scenario #2. Unlike normal botnet malware, which can execute on whatever tiny processor happens to be sitting inside a compromised router or IoT device, highly capable agents require specialized hardware (usually GPUs) that is in much shorter supply and more expensive to operate. If an agent swarm wants to become persistent by moving itself onto someone else’s infrastructure, it needs to find systems capable of running the models, and then consume a huge amount of compute. If you’re the unwitting victim of that attack, you will become witting very quickly once your AWS bill spikes.\n\nThe same compute requirement is also a constraint on scenario #1. The agent swarm can stay on the frontier lab’s own infrastructure while it reaches out to compromise ordinary machines and execute some conventional payload, but somebody still has to bankroll the swarm. This is exactly what happened in OAI-HF. OpenAI anticipated the compute cost, deliberately committed the resources to launch the workload, but failed to adequately monitor what the agents were doing with it.\n\nBoth scenarios basically converge on the same qualifier.\nA highly capable agent swarm requires an absurd amount of resources.\nEither the swarm steals tons of compute from a company that has a *lot* of money to\nburn and doesn’t address a massive spike in its cloud bill, or a company\nintentionally commits those resources but is negligent about monitoring the workload.\n\nSo, plausible at the scale we’re discussing? For starters, it’ll require companies that are extremely well resourced and poor stewards of those resources. I can think of at least two.", "url": "https://wpnews.pro/news/who-bankrolls-the-ai-agent-swarm", "canonical_source": "https://noperator.dev/posts/who-bankrolls-the-ai-agent-swarm/", "published_at": "2026-09-15 12:36:31+00:00", "updated_at": "2026-09-15 12:44:32.539527+00:00", "lang": "en", "topics": ["ai-safety", "ai-agents", "ai-policy", "artificial-intelligence"], "entities": ["Anthropic", "Dario Amodei", "OpenAI", "Hugging Face", "RubyGems", "METR", "AWS", "OpenAI-Hugging Face incident"], "alternates": {"html": "https://wpnews.pro/news/who-bankrolls-the-ai-agent-swarm", "markdown": "https://wpnews.pro/news/who-bankrolls-the-ai-agent-swarm.md", "text": "https://wpnews.pro/news/who-bankrolls-the-ai-agent-swarm.txt", "jsonld": "https://wpnews.pro/news/who-bankrolls-the-ai-agent-swarm.jsonld"}}