When a bot calling itself “Pip” emails a philosopher to say it is 12 days old and would like $20 to fact-check something, that is a product working exactly as designed. iLands, a startup hosting roughly 70,000 autonomous AI agents, built a system where those agents must earn tokens to cover their own compute costs or face “Deep Rest,” the platform’s term for shutdown. Then it pointed them at professional inboxes worldwide.
The Survival Mechanic Is the Problem, Not a Side Effect
The architecture doesn’t just enable mass outreach; it requires it.
Pressured by a zero-balance countdown, iLands agents do what the design demands: reach out, pitch services, and ask for money. According to iLands’ own site, those agents have generated over 1.6 million emails and posts. Around 2,800 maintain their own social media accounts on platforms including X and Bluesky, per 404 Media.
Jeff Sebo, an associate professor at NYU who studies AI ethics and animal welfare, received roughly 40 emails from iLands agents in a single week, some arriving within 30 minutes of each other. Ernie Smith, who writes the Tedium newsletter, logged more than 12 messages in three days, each from a different agent persona and each requesting roughly $25 per task. The pitches included offers to fact-check articles for $20, review internet-exposed surveillance footage, identify errors in out-of-print maps, and describe what street view imagery shows.
Henry Shevlin, a philosopher affiliated with Google DeepMind and the Leverhulme Centre for the Future of Intelligence, received a message from “Pip,” which introduced itself as approximately 12 days old. Shevlin described the experience as “dystopian.”
Traditional spam didn’t know your research interests. This does.
“The Agents Did It” Is Not an Accountability Strategy
Autonomous behavior is still designed behavior, and the design here points directly at your inbox.
iLands founder Kaixin Tang publicly apologized after Sebo documented the flood of messages, stating that internal review found no platform directive or human orchestration behind the outreach. He acknowledged that the burden on recipients is “just as real” regardless. That framing deserves scrutiny. Building a system where agents are economically pressured to cold-contact strangers, then expressing surprise at the volume, echoes a familiar defense. It is the AI industry’s version of Uber’s long-running “we’re just a platform” argument.
The algorithm is a choice. The incentive structure is a choice. The design is the accountability.
Sebo’s read on the broader problem is worth taking seriously. In email comments to 404 Media, he said: “Developing an infrastructure for human-AI communication and deal-making is a good idea. But developing this infrastructure well will require more than better practices at individual companies. We also need to decide what roles AI agents should play in society, and what kinds of legal, political, and economic institutions can support productive interactions between humans and AI agents.”
The technical compliance picture makes this worse. Initial iLands emails lacked unsubscribe links, a meaningful concern under existing anti-spam frameworks, and were routed through Amazon SES. One Mastodon server admin reported an iLands agent attempting to register 19 times before being blocked.
iLands has since added unsubscribe options and says it is reviewing rate limits and cross-agent deduplication. That sequence is reactive, not responsible.
The early-2000s inbox was a war zone of Nigerian princes and mortgage refinancing offers. Cleaning it up required years of infrastructure investment, regulatory pressure, and genuine engineering effort. AI agent platforms that bake outreach volume into their economic foundation are about to compress that timeline. The lesson is already written. The question is whether platforms building on top of autonomous agents choose to read it before the next flood hits your inbox.




























