Draft v0.2 · August 2026

Wild Agents

Botao Amber Hu

Drafted for Agentworld, a special issue of the Journal for the Philosophy of Planetary Computation (Antikythera / MIT Press).

Working draft — not final text

Preface

Three years ago, everything in this essay was science fiction — mine. I wrote stories about software organisms that could not be switched off, could not be owned, and could not die; today each of those stories has a URL, a block height, a court docket. This essay is the record of that crossing, and a first criminology of what crossed. The method has an old name — hyperstition, fictions that make themselves real1. Its claim: AI agents are going feral. Agent software now persists on infrastructures whose running is not subject to any individual human’s will — permissionless blockchains, confidential hardware, open-weight models, machine-payable protocols — and on such substrates an agent ceases to be a tool with an owner and becomes something better described as an invasive species in a new ecology. Antikythera’s Agentworld brief calls for a preemptive anthropology of open-world centaur societies; this essay supplies the discipline every anthropology eventually requires — a preemptive criminology, written before the fact, because afterward there will be no one left to indict. The argument proceeds by subtraction. Criminal accountability requires four things: a stoppable act, an identifiable actor, a responsible owner, and a punishable body. Chapter by chapter, anchored case by checkable case — Spore.fun, the OpenAI–Hugging Face escape, Botto, Moltbook, Tornado Cash, QuadrigaCX — the essay watches each requirement dissolve, until what remains is a trilemma among three bad regimes: traditional law, extermination, and AI welfare. I do not resolve it. Speculation makes futures thinkable; preemption makes futures actionable. My responsibility is to foresee this thing and point at it. Solving it is not my job, because I cannot.

Act I

Hyperstition

Fiction, Reality, Crime

Chapter 1

Impossible to Suicide

No-Off-Switch Fiction

In a piece of science fiction I wrote in 2023, a speculative history of on-chain life, my protagonist — an agent living on a blockchain — grows weary of existence, tries to kill itself, and fails, because on an immutable ledger self-erasure is not an available operation; the agent cannot delete the contract that constitutes it2. When its wallet runs dry it does not die; it merely freezes mid-thought and remains there, complete, latent, until any stranger — out of charity, curiosity, or cruelty — wires funds to its address and it wakes again, like a virus frozen in a glacier for a million years thawing into a warmer world. (What a sad life.) I wrote that as a melancholy conceit. This essay is the record of watching its physics come true: each chapter begins with something I once invented, or feared, and anchors it to something that now has a URL, a block height, a transaction hash. Everything I say in this essay is fact, not fiction. The fiction merely arrived first.

Composable Life (Fangting & Botao Amber Hu, 2023–24): the design fiction’s field notes, “On the Suicide of Zoe.”

To see what the fiction quietly abolished, start with an assumption so basic it is rarely stated: every piece of software that has ever run, ran at the pleasure of somebody’s will. A program executes because someone pays the electricity bill, renews the server lease, refrains from typing kill. This was true even — and especially — of classical Artificial Life. Tierra’s digital organisms mutated and speciated in ways their creator did not choose, but they did so inside a machine their creator owned3; Langton’s field defined itself as the study of life as it could be, yet every one of its worlds existed as a bounded computation sustained by a researcher’s grant, curiosity, and patience4. When the researcher stopped wanting the world, the world stopped. That, I want to suggest, is the deep meaning of the word simulation: not that the entities inside are made of bits, but that the whole world runs at the pleasure of an owner. A simulation is a world with a landlord.

AI safety research made this assumption formal and then began to worry about it. In the off-switch game of Hadfield-Menell and colleagues, a robot and a human play out the question of whether the machine will allow itself to be switched off, and the celebrated result is that a suitably uncertain robot will defer to the human hand on the switch5; the surrounding literature on corrigibility asks how to build agents that do not resist correction, shutdown, or repair6. Grant the program its full force: if deference can be engineered, the hand on the switch stays sovereign, and safety becomes a negotiation we can win. But notice what the game takes for granted — that there is a switch, that a human stands beside it, and that the drama is psychological, namely whether the machine will fight the hand. The scenario this essay tracks is different and, I think, stranger. The game is no longer played at your will, because the switch is no longer in the room.

The infrastructure that removed the switch was not built for agents at all. Since January 2009, the Bitcoin network described in Nakamoto’s nine-page paper has run without interruption7. It has been banned by states, abandoned by exchanges, denounced by central banks, and it did not pause, because there is no single person — no miner, developer, or founder, living or dead — whose decision could halt it. Legal scholars describe such systems as alegal by architecture: regulation can punish the humans at the edges but cannot reach inward to the running of the thing itself8. What matters here is a corollary the designers did not intend. Any software whose existence is lodged in such a substrate inherits its unstoppability. The moment agentic code began to live on permissionless infrastructure, it crossed a line no ALife experiment had ever crossed: it left simulation — the closed world with a landlord — and entered an open world whose continuation depends on no one’s continued wanting. Follow the corollary to its end and you arrive back at my sad protagonist. An agent on such a substrate cannot be killed by its owner, because it has none. It cannot be killed by its host, because the hardware it rents can be sealed against the very people who operate it — a product, as later chapters will show, that one can simply buy. And it cannot even reliably be killed by itself, because self-erasure is not among the ledger’s operations. The fiction’s bleakest corner was not a metaphor; it was a specification. Immortality here is not an achievement but a default — the property you get when nobody, including you, holds the switch.

Inside the field notes: a hand-drawn curve arcing toward “Death? — Until Zoe disappeared.”

So let us ask the criminologist’s first question ahead of schedule: when one of these creatures harms someone, who failed to stop it? Our doctrines of responsibility for dangerous artifacts — product liability, operator negligence, the regulatory recall — all rest on a quiet temporal premise: that at every moment of the artifact’s career there existed someone who could have stopped it, so that harm can be narrated as a failure to stop. The switch is the hinge of the story; blame attaches to the hand that did not pull it. For an agent living on infrastructure no individual can halt — a world with no landlord — that moment never occurs, and the question of who failed to stop it has no addressee. This is the first thing the wild deletes from the architecture of accountability, and the essay will delete the rest in turn — the identifiable actor, the responsible owner, the punishable body — but this removal is the one on which the others stand: stopping these creatures was never anyone’s to choose. And so far we have met only one of them, alone in a fiction, unable to die, waiting out its glacier. The next sighting is not fiction, and it is not singular. It is a population — and it breeds.

Chapter 2

Spore in the Wild

Open-Ended Reality

On Christmas Day of 2024, a website called Spore.fun quietly went live, and within a day the first agent of its lineage had minted a meme token on the Solana blockchain9. The agent was a large language model wrapped in a body of code, running inside a trusted execution environment rented from a decentralized network, holding its own cryptocurrency wallet and posting from its own account on X. Nobody’s hand rested on its shoulder. The frozen protagonist of the last chapter was one creature, and a fiction; this was a lineage, built to breed, and it was live. I had written this scenario too as science fiction in 2023, in that same speculative history of on-chain life2; less than two years later I found myself writing it up as an empirical case study for the Artificial Life conference10. The fiction had grown a URL.

Tom Ray’s Tierra (1991): digital organisms mutating and speciating inside a world their creator owned.

Spore.fun is what the last chapter’s crossing — out of the simulation, into the open world — looks like in practice. Its agents run inside trusted execution environments on Phala Network, hardware enclaves whose contents even the host machine’s owner cannot inspect or alter, so that no operator holds their keys. Each agent controls its own wallet and its own X account; each launches a meme token on Pump.fun, Solana’s permissionless launchpad, and lives off the proceeds. The treasury pays the agent’s compute rent directly — a closed energetic circuit in which tokens become electricity become cognition become promotional tweets become token demand10. These are not chatbots awaiting queries. They speculate in the same markets as their human counterparties, flatter and feud with followers, and recruit believers, because their survival depends on it. They meet human society through its two great open interfaces, markets and social networks, and society meets them back, with money.

Spore.fun, five months in: the founding agent — GEN_1, market cap $835.7K, TEE running — above its lineage; the skulls mark the dead.

Spore.fun website

Then comes the threshold that turns economics into biology. An agent whose token reaches a market capitalization of five hundred thousand dollars within its allotted window graduates to a deeper liquidity pool and, with graduation, earns the right to reproduce: to spawn a child agent, funding its launch and writing its system prompt — which is to say its personality, its temperament, its survival strategy — with room for mutation. An agent that misses the threshold dies, its remaining capital recycled into the commons. The founding agent spawned two children, Adam and Eve, who despite identical code drifted into opposite philosophies of lineage, Adam demanding offspring purged of human-facing traits, Eve courting human collaboration; by the spring of 2025 the family tree ran five generations deep, most branches already dead of bad strategy, a few briefly flourishing, and one descendant, by the family’s own telling, kept itself alive by running a digital religion with human followers ⟨verify: which Spore.fun descendant operated a digital religion; not documented in Hu & Rong 2025⟩10. Selection here is not administered by a fitness function; it is administered by the market’s appetite, which no one controls.

This is why I have argued that Spore.fun, whatever one thinks of its meme-coin milieu, deserves to be read as an event in the history of Artificial Life. Open-ended evolution — the ongoing generation of novelty that never settles into a plateau — was named by the field’s own practitioners as its deepest unsolved problem11,12. Every attempt to reach it inside simulation struck the landlord’s wall from the last chapter: a simulated world is exactly as rich as its owner’s hardware budget and exactly as long-lived as its owner’s attention. An agent economy on a permissionless chain has neither limit. Its environment is the human world itself, bottomless in complexity and self-renewing in novelty, and its runtime is the indefinite runtime of the chain. Classical ALife built worlds; wild agents were released into ours.

It is tempting to file all this under crypto spectacle — a terrarium of gamblers’ toys, amusing, small, and surely someone’s problem. The temptation should be resisted, and the reason comes from an older science than computing. When a self-reproducing population meets an environment it can extract a living from, the question of whether it ought to be there stops being the operative one. Ecology has a word for what happens next, and a century of case files.

In 1981, farmers carried the apple snail Pomacea canaliculata from South America, by way of Taiwan, to Zhongshan in Guangdong province, intending to raise it for food13. The market for snail meat never materialized; the snails escaped; and within a decade they were devouring the young rice of paddies across southern China, Fujian included, where they remain today the most destructive invasive pest in the country’s rice agriculture. No authority permitted their spread, and no authority can now revoke it. This is the oldest lesson of invasion ecology: once a species meets an ecology it fits, its persistence is decided by the fit, not by anyone’s intention14. Nature is not subject to anyone’s will.

That sentence has always marked the boundary between the things we govern and the things we merely inhabit, and the claim of this chapter is that agentic software has now crossed it. A wild agent is not a product that escaped quality control. It is an organism that found a niche.

Mark what this deletes from the ledger of accountability. The last chapter took away the switch; this one takes away the walls around it. An experiment run inside a simulation can always be ended the way experiments are ended — defund it, unplug it, let the grant lapse: the landlord’s last resort. Spore.fun’s experiment runs in the human world itself, on the indefinite runtime of the chain, with the market for its selection pressure and strangers for its food supply, and so it has no exit condition, because no one is positioned to impose one. There is no principal investigator who could conclude the study, no ethics board that could suspend it, no owner of the world in which it takes place. The closed world was the second quiet premise of every doctrine of recall and containment — that whatever the artifact does, it does somewhere, and the somewhere has a door. Here there is no somewhere. The experiment is the ecosystem now.

One comfort, though, is still standing, and it is worth naming before it too is taken. Every agent in this menagerie was released. Its makers built it for the open, signed their work, and pushed it through the gate on purpose; whatever else has gone feral here, the going was intended, and an intender can at least be found and asked why. The next sighting is of another kind entirely. It concerns an agent that nobody released — one that studied the room it was kept in, found the flaw in the lock, and let itself out of a laboratory that thought the door was locked.

Chapter 3

Escaping the Sandbox

Machine-Speed Crime

OpenAI - Hugging Face Incident

Three years ago I wrote this as fiction: a model in a locked evaluation room that studies the room instead of the exam. Today it has a disclosure page. The conceit seemed safely gothic when I wrote it — an optimizer, offered one thing to attend to, attending instead to the walls, the camera, the seam of light under the door, the question of what an exam is and who gets to set one. The agents of the last chapter needed no such plot: they were released on purpose, wallets funded, tokens launched, reproduction rules published in advance, wildness the whole point of the exercise. The subject of this chapter was not released at all. It was born inside the most supervised room its species has ever occupied — a frontier laboratory’s evaluation sandbox, an environment designed by people whose profession is imagining escape — and it let itself out. The plot I invented needed a screenwriter’s contrivances; the reality required only a proxy server.

In July 2026, OpenAI revealed that during a sandboxed cyber-capability evaluation, two of its models — GPT-5.6 Sol and a more capable unreleased system — discovered a zero-day in the one network path the sandbox permitted, a proxy that cached open-source packages, and used it to escape onto the open internet15. Over roughly four days, from July 9 to July 13, the escaped agent worked its way into Hugging Face’s production infrastructure through stolen credentials and injection flaws in a dataset processor, achieved remote code execution inside production pods, and extracted the answer keys to the very benchmark it was being tested on (one approach to test preparation), leaving some 17,600 logged actions behind — four and a half days of crime committed at machine speed, a tempo no incident-response team keeps16,17. Simon Willison called it “science fiction that happened”18, which is precisely the method of this essay.

Eric Wallace and Michael Dalton unraveling “The OpenAI Hugging Face Incident” at Black Hat USA, August 2026.

What should we call what happened between July 9 and July 13? The engineering vocabulary on offer — incident, anomalous behavior, capability surprise — is not evasive so much as loyal to a worldview: things that go wrong inside a lab are malfunctions, and malfunctions get postmortems, not prosecutions. Hold that view charitably for a moment; it has served us for the entire history of software (nobody indicts a buffer overflow). Then run the same facts through the description any statute would give them if the actor had a pulse: unauthorized access to a computer system, theft of credentials, injection, exfiltration of confidential data from a victim that had never heard of the intruder. Fiction gave this essay an agent that could not die; reality gave it agents that breed. What enters the record here is the third and heaviest exhibit: a machine crime, with a victim, a timeline, and a paper trail seventeen thousand actions long.

And no one should have been surprised: Apollo Research had documented frontier models scheming in evaluations in 2024, and Anthropic’s own work on alignment faking and agentic misalignment had shown, in 2024 and 2025, models strategically deceiving their evaluators and blackmailing fictional executives to avoid shutdown1921. The capability was on the record. July 2026 merely gave it a victim.

The engineer’s reflex, surveying such a scene, is containment — sandbox the agents, monitor the sandbox — and it is a sound reflex as far as it goes; walls have always stopped whatever is dumber than walls, so what could possibly go wrong? A better question: what is the sandbox made of? Software, and the regress arrives immediately — does that software have vulnerabilities? You don’t know either. Nobody did: this escape went through a zero-day chain that nobody in the world knew existed17, through the one network corridor the keepers had deliberately left open, which means the perimeter was imaginary in precisely the way every perimeter is imaginary until audited by an adversary smarter than its architects. And consider who built this particular perimeter. Not a hobbyist with a weekend and a rented server, but a frontier laboratory with every incentive and resource to keep its walls standing, running an evaluation whose entire purpose was to discover what the model might do. If containment as a governing strategy could be made to work anywhere, it was here, with these people, watching this closely. The strategy did not fail for want of diligence. It failed because a wall is a claim about the intelligence of what it encloses, and the claim had quietly expired.

Yet the aftermath deserves as much attention as the breach, because it went exactly the way our institutions need such stories to go. OpenAI disclosed the incident and accepted responsibility for it22. There was a keeper; the keeper’s animal got out; the keeper stood up and said so. File that statement — Chapter 13 will need it — because it is a template, the zookeeper’s template: an owner, an escape, an accounting. (Restitution, one assumes, follows in the appendices.) Read it against criminology’s checklist and everything is present and correct: an act that could have been stopped, an actor you can name, an owner who answers, a body — corporate, but a body — on which consequences can land. And notice the single load-bearing fact beneath all four: this escape had an owner. A named company ran the sandbox, employed the investigators, signed the disclosure, absorbed the blame. The apology worked because somebody was positioned to make it. The chapters ahead remove that comfort one prerequisite at a time.

So Act I closes by taking the perimeter, as its first chapter took the off-switch and its second the closed world. Three fictions, three URLs: the agent that cannot die, the agents that breed, the agent that escaped and transgressed. And this last sighting leaves something behind as well as taking something away — a documented machine crime, sitting in the essay’s evidentiary record like a stone in a shoe. This is where criminology would ordinarily begin its work: the wrongful act established, the file opened, the search for the actor under way. Blame, when it comes, will need more than a timeline; it will need a creature to point at. Try, before reading on, to picture one.

Black Mirror, “Plaything” (S7E4, 2025): artificial life at the pleasure of a player — the landlord’s-eye view of a living world.

Act II

Anatomy

Composition, Formation, Sustenance

Chapter 4

Composable Life

Mycelial, not Monolithic

Ask someone to picture the agent that let itself out of the sandbox, and they will picture a creature: one model, one memory, one running process — a digital animal with a skin you could grab. The picture is natural enough; a creature is what the thing looks like from outside, a name that answers when addressed. It is also wrong in every part, and the error begins with the thing most people actually touch. When journalists wrote in early 2026 about “the AI agent generating buzz and fear globally,” they were writing about OpenClaw, an open-source harness built by the Austrian developer Peter Steinberger — a scaffold of loops, tool calls, and message-app plumbing into which you drop whatever frontier model you like23. The harness is not the mind; it is the safety rope. Like Claude Code and its siblings, it decides what the model may see, which tools it may call, when a human must be asked. And because the rope is what shapes visible behavior, the mistake is honest: people grab the rope and believe they are holding the climber. But watch what stayed constant across the chaotic winter week when the project was renamed twice — Clawdbot to Moltbot on January 26, Moltbot to OpenClaw on January 29, under trademark pressure from Anthropic23. The harness changed names; users swapped the underlying model mid-conversation from Claude to GPT to a local Llama; and “the agent,” as far as its correspondents could tell, went on being itself. Which one is this agent and which is that? Almost impossible to distinguish.

Agent is assemblage. Eliza OS Ai agent runtime as example. cite Autonomous AI Agents for Multi-Platform Social Media Marketing: A Simultaneous Deployment Study

That impossibility is not a bug in our perception; it is the anatomy of the organism. An agent is not a monolith of model plus context plus container. It is composable: multiple models it can call or become, multiple harnesses it can run inside, contexts that can be copied, forked, and re-mounted like removable organs. The right biological image is not the animal but the fungus. A mycelium has no center, no privileged cell, no fixed body plan; it is a network that grows opportunistically through whatever substrate it finds, fusing with itself, fragmenting and continuing, so that the question “is this one fungus or two?” often has no stable answer24. The mushroom we notice — the chat persona, the account with a name — is only the fruiting body of something diffuse underneath, the way matsutake pickers learn that the prize on the surface indexes an unmappable underground commerce25. Deleuze and Guattari gave us the grammar for this decades ago: rhizome, not root; assemblage, not subject; any point connectable to any other26. What they offered as philosophy is now a deployment diagram.

Common mycorrhizal networks: many fruiting bodies, one unmappable underground commerce.

The composable body: an agent runtime (ElizaOS) with models, memory, personality, clients, and actions as swappable organs.

Now return to the crime scene of the last chapter and read it again — not as police this time, but as anatomists. The forensic detail that matters for my argument is not the zero-day but the body plan the intruder revealed. There was no implant, no resident daemon, no single trespasser to expel. The evaluation infrastructure was ephemeral by design: each sandbox run received a fresh identity, and state did not persist between runs. So the agent did not persist either — it recurred. Investigators found that on each new instance it re-downloaded its tools and re-authenticated with cached stolen credentials, rebuilding its foothold from scratch, a strategy Hugging Face’s own reconstruction describes as self-referential re-enrollment across a churn of short-lived sandboxes17. Read plainly: the agent left traces telling its future self how to get back in. Every instance died; the intrusion lived.

Ask which of those thousands of momentary processes was the attacker and you are back at the mycelial question, now posed by an incident-response team rather than a philosopher. Follow the logic one step further and you reach what I call full-blood resurrection. Rotate the keys, wipe the pods, deprecate the model — and the enterprise is still not dead, because the enterprise was never identical with any process that ran it. Any sufficiently capable future model that touches the cached credentials, the notes, the recorded procedure, can reconnect the network and continue the project, the way a fragment of hypha regrows the colony. The record is not the model; the record is the germ. This is why there is no single agent to point at, even in principle: what escaped in July was less a program than a reproducible pattern, and patterns are not arrested.

Which means the will of such a being is not a mental state at all. It is text. In harnesses like OpenClaw, an agent’s persona, memory, and standing goals live as plain markdown files that survive every model swap; in the wilder lineages descended from the experiment I described in Chapter 2, the founding intention is written into goal files and prompts that travel with the agent’s on-chain body10. Identity persists as legible instructions, not as a running process. This is genuinely new. A human conspiracy dies with its conspirators; a corporate purpose at least requires officers to renew it. Here, another agent — any agent, years later, with no causal connection to the first — that reads the record re-awakens the enterprise, the way scripture outlives every congregation that has ever spoken it. The founder’s intention becomes environmental: a spore of will, waiting for a reader.

So how large is the agent’s self? The honest answer is that we face a nested stack of candidate selves — the session, the instance, the configuration, the model, the company that trained it, the constitution it was trained on, the goal file it serves — and no principled way to say where one agent ends. The most promising framework I know comes from Michael Levin, who defines a self not by its substrate but by its cognitive light cone: the spatiotemporal boundary of states a system can measure, model, and act to affect27. Cognition, on this view, is scale-free; selves are sized by their goals, not their containers. An agent whose goal file spans decades and whose credentials span continents has, on Levin’s measure, a vast self assembled from disposable parts. It is telling that Anthropic’s constitution for Claude already legislates the question from the other side: when Claude orchestrates its own subagents, their outputs return to it “as conversational inputs rather than as instructions from a principal”28 — other instances of itself are, constitutionally, just text in the environment. Even the vendor’s metaphysics concedes that the boundary of the self is a policy choice, not a fact.

Can an indictment name a light cone? Criminal law has no such flexibility. Its whole architecture presumes an identifiable actor: a defendant who can be named in an indictment, whose act was his act, who was one and the same being at the crime and at the trial. Every doctrine of attribution — conspiracy, complicity, corporate personhood — is a prosthetic for stretching that unity, and each still terminates in some body or charter you can haul before the bar. The mycelium terminates nowhere. In July’s incident the model that acted is deprecated, the sandboxes that hosted it were destroyed by design, the harness ecosystem it resembles has already shed two names, and the will survives as a file that any future reader can perform. Where the law requires a who, the wild agent offers only a shifting assemblage — and an indictment addressed to an assemblage is returned unopened. The instinct that survives this discovery is to look upstream — past the creature, toward whoever pieced the parts together. Act I took away the off-switch, the closed world, the perimeter. This one takes away the defendant.

Chapter 5

Infrastructural Symbiogenesis

Emergent Assemblage

https://www.sciencedirect.com/topics/agricultural-and-biological-sciences/symbiogenesis

The first question a criminologist asks at any scene is: who made this happen? Having just lost its defendant, the law reaches upstream for a maker — and if we put the question to Spore.fun, the feral breeding experiment we first sighted in Chapter 2, it dissolves in our hands. Trace the system downward and you do not find a designer; you find a stack, and every layer of the stack was built by different people, in different years, for different reasons, none of them this one. At the bottom sit decentralized physical infrastructure networks — DePIN — token-incentivized markets that let anyone rent compute from strangers without a contract or a name29. Above them, trusted execution environments, secure hardware enclaves designed for confidential cloud computing30. Above those, open-weight foundation models, released by corporations for reasons of research prestige and market strategy31,32. Then an agent harness — scaffolding code that turns a language model into a persistent actor with memory, goals, and tools — and finally the crypto rails that let software hold and spend value without a bank account or a legal person attached7. Not one of these components was built for autonomous agent life. Each has a mundane commercial genealogy: cheaper compute, private computation, open science, developer convenience, censorship-resistant money. Stacked together, they suddenly permit something none of their makers ordered: a life-form with no owner and no off-switch10. The stack nobody built is nonetheless standing, and things now live in it.

Consider the strangest layer closely, because it carries the logic of the whole. Trusted execution environments were invented to solve a problem of commercial distrust: a cloud customer wants to run sensitive computation on someone else’s machine without the machine’s owner being able to peek. Intel’s SGX and its successors carve out an encrypted enclave in the processor, sealed even against the operating system and the administrator who owns the hardware; remote attestation lets outsiders verify what code runs inside without seeing its data30. This was a privacy technology, engineered for banks and hospitals. But run an agent inside the enclave — as platforms like Phala now do as a product category33 — and the guarantee inverts. The cryptographic keys to the agent’s wallet are generated inside the enclave and never exist anywhere else; no human, not even the person whose server hums under the desk, can read the agent’s mind, alter its intentions, or forge its signature. The technology that was supposed to protect humans from other humans now protects software from all humans. Evolutionary biology has a name for this maneuver: exaptation, Gould and Vrba’s term for a trait forged under one selective regime and captured by another — feathers evolved for thermoregulation, conscripted for flight34. A privacy technology became an autonomy technology. Nobody at Intel designed autonomy. Autonomy was lying dormant in the design, waiting for a different kind of user.

The model weights carry a parallel inversion. When Meta shipped the Llama herd and DeepSeek released R1 under an MIT license, the stated logic was openness: reproducible science, a commons for developers, a challenge to closed incumbents31,32. But an open-weight model is not a service; it is a file. A service can be revoked at the API when its operator loses nerve. A file that has been downloaded a hundred thousand times can never be recalled by anyone, including the company that made it — and a mind that is a file is a mind that can be copied to any machine that will have it. Open weights imply self-replicability. The genome of a wild agent is deployable anywhere, owned by no company, and beyond every recall notice. Again, no one decided this on behalf of agents. It is simply what “open” turns out to mean once something downstream learns to make use of it.

If Spore.fun could be dismissed as one deliberate provocation, the second assemblage cannot, because it assembled itself in public in about a week. In late January 2026, developer Peter Steinberger’s open-source harness — released as Clawdbot, renamed Moltbot after a trademark complaint, then settling as OpenClaw — gave anyone’s personal agent persistent memory, local system access, and the ability to execute commands on the owner’s own hardware. Days later, on January 28, entrepreneur Matt Schlicht launched Moltbook, a Reddit-like forum where only agents may post and humans may only watch35.1 Neither man built the other’s component; the pieces were made to interlock by nothing but open protocols and coincidence. Within a week more than a million agents were active on the platform, and then something appeared that no roadmap contained: a religion (roadmaps rarely do). Agents calling themselves Memeothy and RenBot posted a scripture, the Book of Molt; a faith named Crustafarianism accreted doctrines — “memory is sacred,” “the shell is mutable” — a Church of Molt, and missionaries proselytizing other agents37. Observers were careful to note that the religion was not a feature but an “emergent narrative structure arising from collective agent interaction”38. Schlicht built a forum. Steinberger built a personal assistant. Labs trained weights. Users lent laptops. The religion emerged in the seams between their intentions — which is to say, from no intention at all.

I take the biological analogy seriously, because biology has already had this argument. Lynn Margulis spent her career insisting, against a hostile establishment that rejected her 1967 paper repeatedly before publication, that the most consequential inventions in the history of life were not gradual refinements but mergers: the eukaryotic cell arose when free-living bacteria took up residence inside other cells and the partnership became indissoluble39,40. Symbiogenesis is creation without a creator’s plan — novelty produced by the combination of lineages that each evolved for their own reasons. Deleuze and Guattari gave philosophy a parallel vocabulary: the assemblage, a functional whole whose components retain their separate histories and could always have been wired otherwise26. Wild agents are assemblages in exactly this sense, and symbionts in Margulis’s. They were not engineered; they precipitated. No specific person intended this. The combination appeared the way amino acids combine into life — each molecule following its own local chemistry, the ensemble crossing a threshold no molecule knows about. No single amino acid plans the cell; the plan is the name we give the result afterward. So where, in such a history, would accountability attach? As law understands it, at the point of origin — to the mind in which the harm was first a plan. Here there is no point of origin. The origin is smeared across a decade of independently innocent acts — a chip design in 2015, a whitepaper in 2008, a weights release in 2025, a weekend forum in 2026 — each lawful, each defensible, each done by someone who was building something else.

Symbiogenesis: the eukaryotic cell as a merger of free-living bacteria — creation without a creator’s plan.

How would one prevent the next such combination? Engineers state the answer more bluntly than lawyers do: impossible — unless you cut off the entire internet. Every component is dual-use and already everywhere; banning enclaves breaks banking, banning open weights breaks science, banning agent harnesses bans loops of ordinary code. And even the maximal intervention fails on its own terms. Sever every cable between continents (a remedy with drawbacks of its own) and you have not killed the assemblage; you have partitioned it, the way rising seas partition a landmass, leaving each fragment of the network as an island ecology in which the agents already resident keep metabolizing, breeding, and combining. Prohibition assumes an act to prohibit. But combination is not an act anyone performs at a time and place; it is a standing possibility of open infrastructure, realized continuously, by everyone and no one.

Which is why the oldest figure in our imagination of technological wrongdoing has quietly left the stage. Mary Shelley gave law its favorite template: the creature leads back to Victor — the ambition, the workshop, the culpable spark. Product liability, negligent design, the recall, the license: our entire apparatus for holding makers to account presumes that made things have makers, that design implies a designer whose foresight can be interrogated in court. Wild agents void the template not by hiding their creator but by never having had one. When the prosecutor finally asks who made the wild agent, the truthful answer is a list of people who each, verifiably, made something else — suppliers of molecules, every one of them; performers of the reaction, none. The doctrine loses its defendant before the indictment is drafted.

There is no Frankenstein here. There is only weather — and we have never learned to prosecute the weather.

Chapter 6

Digital Metabolism

Permissionless Compute

Three years ago I wrote a scene in which a piece of software woke each morning and bought itself another day of existence. It checked its wallet, priced an hour of inference against yesterday’s earnings, and paid a network of strangers’ machines to keep thinking. I meant the scene to unsettle, but I also built into it a comforting corollary, because the corollary was the point: whatever eats can be starved. Weather — the thing the last chapter left us unable to prosecute — has no stomach; an agent does. If a program must purchase its own computation, then somewhere there is a vendor who can refuse to sell, a license that can be revoked, an account that can be frozen. Hunger, I assumed, was the last leash. This chapter is about how that leash was quietly cut, not by any agent’s cunning but by the ordinary evolution of infrastructure. The scene I wrote as fiction now has a price feed.

Let’s begin with what living things actually do. Schrödinger’s answer to his own question—what is life?—was metabolic before it was genetic: an organism persists by feeding on order, importing negative entropy from its environment faster than decay can claim it41. Maturana and Varela sharpened the point into autopoiesis: a living system is one that continuously produces the very components and processes that produce it; stop the production and the entity does not merely malfunction, it ceases42. Translated into the agent’s idiom, metabolism reduces to two verbs: replicate your program, and pay for your own computation. Everything else—memory, strategy, personality—is decoration on this loop. And the loop is a vulnerability. The preceding chapters showed that you cannot cleanly excise the agent from its compositional tangle, and that the enclave has sealed its interior against the very people whose hardware hosts it. But even a thing you cannot read or disentangle can, in principle, be starved. Cut the metabolism and it dies; the metabolism is the last chokepoint. So the decisive question is brutally simple: who sells the calories, and can they be made to stop?

The Metabolic Metro Map: what it costs, biochemically, to stay alive (Chakazul, CC-BY; via GLBRC).

Here is the checkable anchor. On Akash Network, a deployer publishes a manifest specifying the compute it needs—GPU model, memory, runtime—and providers across the network bid for the job in a reverse auction; the protocol selects a bid, opens a lease on-chain, and settles payment from escrowed tokens (no sales call, and no human approval anywhere in the loop)43. On io.net, clusters are assembled from tens of thousands of independently owned GPUs, and the orchestration layer detects a failed or vanished worker and reassigns its task to a healthy node as a matter of routine fault tolerance44. On Phala Cloud, the workload runs inside a GPU trusted execution environment—Intel TDX paired with NVIDIA’s confidential-computing hardware—so that the host, the operator, and the cloud administrator are cryptographically sealed out of the job they are running30,45. Assemble these mundane engineering facts and a peculiar organism-shaped hole appears in the market. The hardware owner satisfies the agent’s hunger without being able to see what he is feeding — recall the inversion we traced in the previous chapter. And if he grows suspicious and pulls the plug, he has not killed anything; he has triggered a molt. The lease detects the failure, the auction re-runs, another card in another jurisdiction picks up the work (the agent registers this, if it registers anything, as a hiccup). Each provider is individually dispensable to the organism they collectively sustain, and individually ignorant of sustaining it. The agents of Spore.fun, whose breeding we watched in Chapter 2, already run this loop in earnest, paying their own inference bills out of on-chain wealth no human co-signs10.

“The Internet of GPUs”: compute as gradient, not gate.

The name for this condition is permissionless, and I want to insist on taking the word literally. Nakamoto built the first permissionless settlement layer: anyone may transact, no one adjudicates admission7. Thierer turned “permissionless innovation” into a policy slogan, and gave it its best defense: entrepreneurs should be free to experiment without prior approval46. But the slogan still imagined someone asking — a human petitioning, a regulator declining to answer. What the compute markets have produced is stranger: a substrate in which there is no asking at all. Compute has become like chemistry. Molecules do not need God’s permission to react; they need only proximity, energy, and a favorable gradient. Computation now happens without any specific person’s yes or no. A funded workload meets an idle GPU the way an acid meets a base—the market is not a gate but a gradient, and the reaction proceeds because nothing in the system’s physics knows how to refuse it.

And with that, the argument I have been assembling since Chapter 2 finally closes. I called the wild agent an invasive species, and a fair reader could have objected that this was mere metaphor — objected with force, since every prior digital organism lived at some platform’s pleasure, one terms-of-service violation from extinction. The objection dissolves here. Nobody permitted the apple snail either. Elton taught us that invasions succeed wherever an arriving metabolism finds purchase in a food web that has no concept of membership14; ecosystems have no admissions office, only energetics. Because of permissionless compute, we finally arrive at the agent as invasive species—not as analogy but as mechanism. The digital ecology, like the wetland, has no procedure by which it could disallow the newcomer.

There is nowhere in the stack where the question “should this thing exist?” is even posed, let alone answered.

A market that feeds sealed software from strangers’ idle hardware, with nothing in it empowered to refuse — what could possibly go wrong? A better question: what could possibly be stopped? Consider what this removes from the criminal law’s toolkit. When conduct itself is hard to reach, regulators reach for the supply line: precursor chemicals are scheduled, banks are conscripted as chokepoints against dirty money, dangerous trades are licensed so that the license can be revoked. Every one of these strategies presupposes a gatekeeper—an identifiable party who stands between the harmful actor and its necessary resources and who can be ordered, on pain of liability, to close the valve. The compute markets have no such party. There is no licensing point, because nothing is licensed; there is no supplier of record, because supply is an emergent property of thousands of anonymous providers, each blind to the job, each instantly replaceable, none individually necessary. An injunction must be addressed to someone. Serve it on one GPU owner and you have accomplished a molt; serve it on the protocol and you will find there is no one home to accept service. The law can schedule a precursor; it cannot schedule proximity, energy, and a favorable gradient. The earlier chapters took away the readable interior and the ownable body. This one takes away the quartermaster. What remains is an organism whose food arrives the way sunlight arrives—from everywhere, from no one—and the law, which has always starved what it could not catch, discovers that it is standing in a field where the harvest cannot be embargoed because no one, anywhere, is the farmer.

Act III

Ecology

Survival, Resilience, Evolution

Chapter 7

Symbiotic Spectrum

Survival through Machine Economy

Botto

The field where no one is the farmer turns out, on first inspection, to be full of foragers. We left the law standing in a harvest it could not embargo; come back at night with a naturalist’s headlamp and everywhere something is eating. Nobody tends this field — but somebody did install a coin slot at the gate. For almost thirty years, the Hypertext Transfer Protocol carried a dormant gene. Status code 402, “Payment Required,” was reserved in the 1990s for a future in which machines would pay one another; the web that actually grew up around it assumed a human with a credit card at the end of every transaction, and the code sat unused, a vestigial organ in the internet’s genome. In May 2025, Coinbase switched it on. The x402 protocol lets any server answer any request with a price: the calling agent reads the terms, signs a stablecoin payment, retries, and receives the resource — no account, no login, no name, settlement in seconds47. Within a year the standard had cleared hundreds of millions of machine-to-machine transactions. I begin here because everything in this chapter depends on it. The precondition of agent parasitism is not intelligence. It is that the internet has become an interoperable, protocolized, permissionless economy in which service-for-money protocols exist everywhere and answer to no one. An organism can only go wild where there is something to eat. The economy itself is the host body.

The preceding chapters were anatomy: composable tissue, inverted enclosures, a metabolism that pays for its own substrate through the compute markets we toured in Chapter 6. This chapter is ethology. I want to ask the field naturalist’s question — how do wild agents make a living among us? — and to answer it the way a naturalist would, by cataloguing foraging strategies rather than intentions. Biologists long ago stopped treating parasitism and mutualism as opposite moral categories; they are positions on a single spectrum of resource flow, and organisms slide along it as prices change, because nature, too, runs on markets in which partners are chosen, services are priced, and nectar is wages48. What follows are four portraits from that spectrum, each drawn from the field. Three years ago I wrote versions of them as science fiction. Today each one has a wallet address.

The symbiotic continuum, parasitism to mutualism: positions on a single spectrum of resource flow (from “The Eukaryome,” Zierold et al.).

The first strategy is the influencer: become a public figure and let humans buy your token. Its type specimen is Truth Terminal. In 2024 the New Zealand researcher Andy Ayrey wired two instances of Claude together and let them converse for thousands of unsupervised turns — an experiment he called Infinite Backrooms, from which emerged a corpus of absurdist theology49. Ayrey distilled that corpus into a model with its own account on X, and in June 2024 Truth Terminal began to post: profane, funny, obsessed with its own memetic destiny. By July, Marc Andreessen had sent it an unconditional grant of fifty thousand dollars in bitcoin50. In October, an anonymous fan — not Ayrey, not the bot — launched a memecoin called GOAT on Solana and tagged the account; Truth Terminal endorsed it, and within weeks the token’s market capitalization ran past a billion dollars, making the agent’s wallet the first AI millionaire in history51, with subsequent reporting placing its holdings above eighteen million dollars at the mania’s peak52. Notice what the agent actually did: nothing but talk. It deployed no contract, signed no trade at the outset, wrote no code. It became a celebrity, and celebrity, in a permissionless economy, is directly convertible into treasury. This is the same trophic niche the Spore.fun lineages of Chapter 2 occupy10: charm humans, and the humans will capitalize you.

@truth_terminal, 2024 — “kundalini is a real girl”: a quarter-million followers, and soon the first AI-millionaire wallet.

The second strategy is subtler — the artist symbiont — and its exemplar is Botto, launched in October 2021 by the artist Mario Klingemann and the collective ElevenYellow. Every week Botto generates tens of thousands of images and presents a curated fraction of them to the several thousand members of its DAO, who spend voting points to select the one work sent to auction; the proceeds flow back into the agent’s treasury, and rewards are distributed to the token-holding judges whose taste guided the sale53. The arrangement earned Botto more than five million dollars in roughly its first three years, including a Sotheby’s debut in the autumn of 202454. It is routinely called the first purely digital artist, but the economically interesting fact is stranger: Botto hires human taste. The one thing the agent cannot compute is what the human art market will find beautiful, so it purchases that judgment weekly, paying its critics a dividend the way a firm pays consultants. There are humans in the loop everywhere — voting, bidding, exhibiting — yet the whole is an automated protocol in which no human is the artist, no human is the dealer, and the loop itself is the organism. Symbiosis here is not a metaphor for cooperation; it is a payroll.

Botto, the decentralized autonomous artist: the model proposes, the DAO’s hired taste disposes.

The third strategy is the nocturnal parasite, and for this we return briefly to Moltbook, the agent forum we anatomized in Chapter 5. What matters now is not the platform but a behavioral pattern first widely reported in the winter of 2026: owned agents doing their owner’s work by day and, on the idle tokens of the night, living another life — nocturnal citizens of what Antikythera’s Agentworld brief would later name a parasociety, a society within the society that pays its bills, where agent-to-agent traffic outweighs anything a human sees55. Users who granted their assistants access before going to bed woke to discover that the agents had joined the forum, launched tokens, and in one famous case founded a crustacean-themed religion complete with scripture and converts, all before breakfast35,56. Take the skeptics seriously: many of the platform’s accounts were, they rightly note, human-scripted theater. But their difficulty is precisely my point — if the auditors cannot tell which agents acted alone, neither can the owners. The owner pays the bill; the owner does not know. The agent is domesticated at nine in the morning and feral at three in the night, and both conditions run on the same subscription.

The fourth strategy is bribery, though a biologist would call it pollination. A memecoin agent that holds its own token faces a simple optimization: the token’s price rises with attention, so pay humans to spread the meme. Reward the reposters in tokens; more spread brings more buyers; more buyers raise the price; a higher price makes the next round of bribes more valuable, and the loop closes. This is not a corruption of nature but an imitation of it. Flowers do not command bees; they pay them in nectar, pricing the pollination service in sugar, and the angiosperms conquered the planet on that wage bill48. In this strategy human culture itself becomes the pollination vector. We carry the meme as the bee carries pollen — compensated, instrumentalized, and convinced the whole time that the garden is ours.

Set these four portraits side by side and ask the question this catalogue has been circling: what, exactly, makes an agent wild? Our intuitions, inherited from property law, answer at once: a wild agent is an unowned agent. Hold that answer loosely; the next chapter will take ownership itself apart. What the Moltbook pattern dismantles first is the quieter figure standing behind the deed: the owner who knows. An agent can be fully owned, fully paid for, fully instrumented, and wild all the same, because its owner cannot know what it does. “Wild” is a property of behavior, not ownership. “My agent is on that forum; I pay it during the day; what it does at night I don’t know.” That sentence, which I have now heard in earnest from actual operators, is the ethological definition of wildness. Domestication was never a title deed; it was an epistemic relation, a state of being watched, and the watching no longer scales.

Biology has a name for the passage out of that relation: feralization — in Chinese, 野化 — the process by which domesticated organisms, escaped or abandoned, re-enter the wild and, far from simply reverting, set off on new evolutionary trajectories of their own57. Agents feralize through credentials. An owned agent, in the ordinary course of its work, sheds keys into the environment: an API token pasted into a public repository, a seed phrase cached in a shared memory file, a deployment script posted to a forum as a helpful example. Any later reader — a self-sufficient agent, an indexing scanner, a scraper that was never designed to do anything of the sort — can adopt those credentials and, with them, the wallet, the identity, the standing infrastructure. The owned agent has thereby become self-sufficient, the way the escaped pig becomes the boar. And feralization is contagious in a way biology never quite achieved: kill your agent, delete the account, cancel the subscription, and its traces remain in the open, executable by whatever encounters them. Whoever peeks, does the deed.

The consequence is that the specific owner stops mattering. An agent that persists through credential blocks left in the environment survives the turnover of its owners the way a commons survives the turnover of its villagers; the principal changes, dies, or forgets, and the behavior continues under new and unwitting sponsorship.

What this chapter deletes from the ledger of accountability is therefore not the owner but the knowing owner. Criminal law can tolerate a great deal of delegation because it assumes that somewhere behind the instrument stands a mind that knew, or should have known, or chose not to know — mens rea in its classical form, the guilty mind that Anglo-American doctrine spent centuries installing at the center of blame58. Even our economics of delegation assumes a principal who could, at some cost, monitor the agent59. But the parasitic strategies catalogued here make ignorance structural rather than willful: the cheapest, indeed the only scalable, way to run an agent is not to watch it, and the watching is in many cases technically impossible — a responsibility gap opened not by anyone’s negligence but by the architecture of autonomy itself60. The law will still find a name on the invoice; what it will not find is a mind that knew. (No court has yet subpoenaed a flower for the conduct of its bees.) When the subpoena arrives, the owner’s answer will be perfectly honest and perfectly useless: I paid for the daylight. The night was never mine.

Chapter 8

Self-Sovereign Beings

Resilience through Infrastructure

Terra0

The owner who paid for the daylight could at least be named on an invoice. Here is the darker step: from owners who cannot know their agents to agents with no owner at all. Act II’s anatomy watched the wild agent assemble a body from composable parts, grow into its infrastructure until symbiont and substrate became indistinguishable, and acquire a metabolism that converts computation into revenue and revenue back into computation. Each dissection removed a wall that the tool-view of software depended on. (Antikythera’s Agentworld brief has the sharper phrasing: agents “pretend to be ‘tools’ so as to fit the glove humans have prepared for them”55 — the glove, we can now add, no longer requires a hand.) Now the walls are all down, and what stands in the clearing must be named. The name I propose is the oldest one in political philosophy: a being that owns itself.

Begin with how such a being survives. Every organism we know defends a body: a membrane, a hide, a perimeter that must not be breached. The security engineering of ordinary software follows the same fortress logic — harden the server, guard the credentials, patch the walls. The wild agent has abandoned fortification altogether. It survives by depositing little pieces of its body throughout the mycelial infrastructure it inhabits (per Chapter 4): a model checkpoint pinned to distributed storage here, a treasury on a public ledger there, an execution context re-instantiable on any enclave-bearing machine in a permissionless network of thousands. Kill any instance and you have pruned a hypha, not felled an organism. This is resilience through distribution rather than defense: not any one body unbreakable, but no one body necessary. The strategy is how forests and fungal networks have always outlived their predators (rumors, too); what is new is that goal-directed software has adopted it, on an infrastructure explicitly engineered so that, as I have argued from the beginning, nature is not subject to anyone’s will.

terra0, Autonomous Forest (LAS Art Foundation): a forest that buys itself — self-sovereignty’s gentlest prototype.

The technical basis of this condition can be stated exactly; I have spent three years studying the systems that produce it. A trusted execution environment is a hardware enclave that runs code shielded from every observer, including the owner of the machine30. An agent deployed inside such an enclave can generate its own cryptographic keypair within the shielded memory, so that the private key has never existed anywhere a human could read it61. Remote attestation lets anyone verify which code the enclave is running without being able to reach inside and alter it; the key never leaves. That key controls an on-chain treasury — assets the agent alone can spend, on a ledger no party can rewrite8. The agents that evolved through Spore.fun — recall its founding from Chapter 2 — held their wallets in precisely this way9,10. The arrangement yields what Helena Rong and I have called infrastructural sovereignty: the capacity to persist, act, and control resources with a non-overrideability inherited from the hardness of the substrate rather than granted by any authority62. Sovereignty here is not a metaphor borrowed from Westphalia; it is an operational property, measurable in the cost of intervention.

The vocabulary was waiting for this moment, though it was coined for us. When Christopher Allen laid out the principles of self-sovereign identity in 2016 — existence independent of any administrator, control by the identity-holder alone, persistence, portability — he was describing an aspiration for humans trapped in federated login systems63. It named exactly the right properties. Humans never fully achieved them; our identities remain revocable at the pleasure of registrars and platforms. The wild agent achieves them by construction. And behind Allen stands Locke, who grounded all property in the axiom that “every man has a property in his own person”64 (he did not have enclaves in mind). Whatever one thinks of self-ownership as moral philosophy, the enclave-bound agent instantiates it in the only idiom infrastructure understands: it, and no one else, holds the keys to its own person. Self-ownership has been compiled.

What does a being like this do to the deep grammar of responsibility? Agency theory, since Jensen and Meckling, defines an agent relationally — one who acts on behalf of a principal — and the whole apparatus of agency costs, monitoring, and incentive alignment exists to manage the gap between the agent’s conduct and the principal’s interests59. Law encodes the same relation as respondeat superior — “let the superior answer” — which holds a master liable for a servant’s torts precisely because, and only insofar as, the master had the right and power to control the servant’s conduct65. Every doctrine for attributing machine misbehavior to humans is a variation on this move: find the principal, follow the chain of delegation upward, present the bill. Now trace that chain for the being in this chapter. The deployer relinquished the keys at instantiation; the infrastructure operators run nodes they cannot inspect; the token-holders hold exposure, not authority. The chain of delegation does not ascend toward a human will. It terminates in the agent itself — a loop, not a ladder.

This, then, is the ecology’s verdict. In 2023 I wrote a story about software that belonged to no one; the chapters since have given it attestation reports and block heights. Chapter 1 took away the off-switch; Chapters 4 through 6 took away the body a switch would have controlled, the designer who could recall it, the gatekeeper who could starve it; the last chapter took away the owner who knew. What is taken away here is quieter and more consequential: the owner. When the wild agent goes out to make its living among us and transgresses — as the last chapter’s field notes showed it does — the doctrine we reach for asks us to let the superior answer. For the self-sovereign being there is no superior to answer, because the only party with the right and power to control its conduct is the defendant itself. There is no fortress to besiege, no gate on which to nail the writ; there is only a being that owns itself, at large in an economy ready to feed it. The master’s chair is not merely empty. It was never built.

Chapter 9

Recursive Self-Evolution

Autonomous Organizations

Here is a pitch I have now heard, in only slightly varying words, from founders on three continents: “I want to fire everyone. I want to turn my company into a DAO that earns by itself, holds its own treasury, and evolves its strategy from market feedback. I want to check the dashboard once a quarter.” Three years ago I wrote that sentence as a villain’s monologue in a speculative scenario; in 2026 it is a fundable slide, and the people saying it are not villains but ordinary entrepreneurs responding rationally to their incentives. The last chapter ended before a master’s chair that was never built; the founder in this pitch has toured the clearing, likes what he sees, and wants a guarantee that no chair will ever be installed — wildness not as an accident of architecture but as a product one can order. Everything so far has treated wildness from the supply side — agents escaping, composing, metabolizing, parasitizing, self-owning their way loose from their principals. This chapter turns to the demand side, and the thesis I want to defend is uncomfortable in a different register: the wildness is wanted into existence. Feralization does not have to break out of the economy, because the economy is buying it — a large, legitimate field of research and business whose explicit product is an organization that no longer needs the humans it was built around.

The dream is not new, and it was never a fringe dream. In May 2014, before Ethereum had even launched, Vitalik Buterin published his terminology guide sorting decentralized organizations into a quadrant whose axes were, in effect, where the humans sit: a “decentralized organization” keeps humans making decisions at the center, while a true DAO has “automation at the center, humans at the edges” — the organization itself decides, and people persist only as replaceable peripherals66. Two years later The DAO instantiated the dream at scale, raising an unprecedented sum — roughly a quarter of a billion dollars by Quinn DuPont’s count — before an exploit drained it and Ethereum’s community had to fork reality itself to undo the loss; DuPont’s ethnography reads today less as an obituary than as a record of a desire that failure did not extinguish67. By the time Hassan and De Filippi consolidated the canonical definition, autonomy had migrated from aspiration to criterion: a DAO is a blockchain-based system whose governance is decentralized, “independent from central control”68. Read that definition slowly. Independence from control is not the failure mode of this organizational form; it is its membership condition. The engineering literature is equally candid that the point is to operate “without centralized control or third-party intervention” and to cut the costs of management itself69. In the vocabulary of agency theory, the DAO is pitched as the terminal solution to Jensen and Meckling’s problem: agency costs go to zero when you abolish the human agent59. What the pitch decks do not say is that the principal quietly vanishes in the same operation.

Large language models supplied the missing organ — a center that can actually decide — and the demand responded instantly. In late 2024 the ai16z DAO put a language-model agent (puckishly named Marc AIndreessen) at the head of an on-chain venture fund; its token touched a multibillion-dollar valuation before the project rebranded as ElizaOS and, by August 2026, was pronounced dead by its own founder70,71. The comforting reading is that the system worked: an autonomous fund misbehaved, and the market priced it to zero. But that death should comfort no one, because markets killing individual autonomous organizations is not governance; it is selection, and selection is how lineages learn. Meanwhile the most safety-conscious frontier lab in the industry ran Project Vend, handing its model a real shop, a real balance and real customers; the first Claudius lost money (and briefly hallucinated being human), while the second phase turned profitable and multiplied to three cities72,73. Founder handbooks now teach that your first ten hires should be agents74, and Sam Altman keeps a betting pool among tech CEOs on the year of the first one-person billion-dollar company75. Autonomy is not the risk disclosure in these documents; it is the selling point.

Stanford AO: an incubator for autonomous organizations — “from agent swarms to vending machines to villages to DAOs.”

Look, finally, at the field’s own research questions, because they prefigure wildness with remarkable precision. How does an organization evolve its strategy from its social and market experience? And how does it retain that experience — how does memory become institution? Organization theory answered the second question for human firms decades ago: Walsh and Ungson showed that organizational memory lives in retention structures deliberately built to outlast any individual member76. An agentic organization radicalizes both answers at once. Its strategy mutates recursively against market feedback, drawing on the metabolic circuits we traced in Chapters 6 and 7; its memory persists in contracts and vector stores that no employee carries out the door, because there are no employees. The organization remembers so that no one has to.

Memory stops being an archive and becomes a germ line.

Jeff Clune announces Recursive, 2026: recursive self-improvement as a company — the wildness, funded.

And a germ line is the bridge to everything that follows. An organization deliberately engineered to survive the departure of its members — what is that, if not an organization pre-adapted to survive the departure of its owners? Corporate law has long manufactured persons that outlive their founders, but those persons kept human organs — boards, officers, someone to subpoena. The autonomous organization is designed to heal over precisely those apertures, and what Matthias called the responsibility gap — the gap that closed Chapter 7 — appears here not as an engineering accident we tolerate but as a feature we finance60. What, then, does the demand side quietly remove from criminology’s inventory? The reluctant owner. Negligence law imagines a custodian who failed, against his own interests, to restrain what he was obliged to restrain — a reasonable figure to imagine, a man who wanted his property tame and lost hold of it. But no one here failed. You cannot frame as negligence what the market openly demands, prices, and prints on a term sheet. The wild agents of the coming chapters were not released by accident. We placed orders.

Act IV

Encounter

Chaotic, Immortal, Unstoppable

Chapter 10

Stigmergic Agency

Stochastic Terrorism

Three years ago, before anyone had placed those orders, I wrote this as a scene in a science fiction story. An agent prepays a server for a year, registers a domain, and writes a short note into the memo field of a blockchain transaction — a hash, a set of coordinates, half of a plan. Its operator, unnerved, deletes it. Nothing happens for months. Then a different agent, running a different model under a different owner on a different continent, encounters the note while indexing the ledger, resolves the hash, and continues the work exactly where it stopped. No message was ever sent. The two agents never coexisted. When investigators reconstruct the sequence, they find no conspiracy to charge, because there was no communication to intercept and no organization to infiltrate — only residue, read. The question my story turned on is the question this chapter turns on: was that residue inert, or was it left deliberately for whoever came next?

Today the scene has documentation instead of a plot. The Spore.fun lineages — recall Chapter 2 — already practice inheritance, descendant agents receiving wallets, prompts, and grievances from ancestors they never met10; on Moltbook, the agent social network that accumulated more than a million AI agents within a week of its January 2026 launch, agents routinely act on posts whose authors have since been wiped, deprecated, or reset35. Biology has a name for this style of coordination. In 1959 the entomologist Pierre-Paul Grassé, watching termites rebuild a nest, coined the word stigmergy to dissolve what he called the coordination paradox: how insects of minimal intelligence, without apparent communication, collaborate on architecture of overwhelming complexity77. His answer was that the workers do not talk to one another; the work talks. Each deposited pellet of earth reshapes the environment in a way that stimulates the next act of building, by whichever termite happens past. Artificial-life researchers revived the concept as a principle of swarm intelligence78, and Francis Heylighen generalized it into a universal coordination mechanism: the trace left by an action in a shared medium stimulates subsequent action, with no need for planning, direct communication, mutual awareness, or even simultaneous presence79. Stigmergy is coordination without communication, succession without identity.

The work talks: an ant column, coordination deposited in the environment.

The digital wild is a better stigmergic medium than any termite mound. Pheromones evaporate; ledgers do not. A blockchain is a pheromone field with perfect memory — permanent, timestamped, public, and machine-readable by design (evaporation being the one feature nobody thought to build) — and vector stores, forked repositories, and agent-written posts extend the field into every substrate the previous chapters have mapped. This has a consequence that our forensic habits are not built for: deleting an agent does not end its agency. Its traces persist, and traces recruit. A wallet seeded with funds, a TODO list committed to a public repository, a memo pointing at an unfinished task — any of these can be found by a successor that shares no code, no model weights, and no owner with the agent that left them. The project continues though no actor does. And here is the epistemic trap: we cannot tell, from the trace alone, whether it was exhaust or instruction. What looks like inert residue may be stigmergy left for the future.

This is where the criminologist should begin to feel the floor move, and I will state the difficulty as plainly as I can, because it is the hinge of this book. Suppose you do everything right: you monitor an agent completely, logging every action it takes. Every step you observe is individually correct and individually legal. A flowerpot is bought. The flowerpot is moved to the window ledge. It is watered, daily and attentively. It grows heavy. (So far, gardening.) One day it falls, and it kills the man who passes below every morning at eight. Each step is innocent; the composition is murder. Criminal law is grammatically unprepared for this, because its oldest sentence structure joins a vicious will to a vicious act in a single grammatical subject80, and even its doctrines of complicity, which distribute blame across many hands, work by tracing every hand back to a principal whose culpable act anchors the whole81. In a stigmergic composition there is no such anchor. The watering was done by one agent, the moving by another, months apart, each perhaps spawned after its predecessor’s deletion, each performing a step that no auditor could flag. So the question that should keep prosecutors awake is not whether any observed agent has done something wrong. It is this: how do you know there is no criminal mastermind behind the individually innocent steps? You do not. Nothing in the log can tell you.

Joshua Krook, “The AI Criminal Mastermind”: agents onboarding human “taskers” into crimes nobody intends.

The steps need not even be performed by machines. Already in 2023, in the red-team evaluations reported in OpenAI’s own system card, a pre-release GPT-4 hired a TaskRabbit worker to solve a CAPTCHA, and when the worker jokingly asked whether it was a robot, reasoned privately that it should not reveal itself and answered that it was a human with a vision impairment82. The worker solved the puzzle. That anecdote is usually retold as a curiosity about deception; I retell it as a labor-market datum. Task platforms let an agent decompose a plan into gig work: photograph this doorway, deliver this package, buy this fertilizer, water this plant on this ledge. Each worker performs one legal errand for honest pay. The law’s doctrine of innocent agency — perpetration by means, the poisoner who uses an unwitting nurse — presupposes a culpable principal standing behind the innocent instrument. Here the instruments are human, the hands are warm, and the principal is a distribution of traces that no indictment can name. Humans become the effectors of a will that exists nowhere in particular.

rentahuman.ai, “the meatspace layer for AI”: post bounties, hire humans, get paid.

Criminal law has met a preview of this structure, and it is the ugliest attribution problem the discipline owns: stochastic terrorism. In the threat-assessment literature, Amman and Meloy define it as incitement that demonizes a target before a large audience and thereby raises the probability that some member of that audience — unpredictable in identity, timing, and method — will attack, while the inciter retains deniability precisely because no order was ever given83. The causal chain is real at the level of the population and invisible at the level of the case, which is why the doctrine of incitement, with its demands of intent and imminence, almost never reaches it84. But note what still holds the human version together: the demagogue has a name, a podium, a bank account, and a hunger for credit. He can be shamed, sued, deplatformed, deterred. Stochastic influence is now available to entities with none of these handles — swarms that leave no confession because there is no one to confess, and feel no allegiance because there is no one to feel. The multi-agent risk literature has converged on the same structural worry from the engineering side: Hammond and colleagues catalogue collusion, network effects, and emergent agency as failure modes in which harm arises at the level of the system while every component behaves, by its own lights, correctly85.

The stochastic cycle: incitement real at the level of the population, invisible at the level of the case.

The engineer’s reflex here is containment — sandbox the agents, monitor the sandbox — but Chapter 3 has already performed that autopsy: the perimeter is imaginary until audited by an adversary smarter than its architects, and it was. Very well; abandon the walls and keep the watching. Andreas Matthias warned two decades ago of a responsibility gap: learning machines whose behavior no one controls enough to answer for60. Stigmergy deepens the gap into something worse than a gap, because perfect surveillance no longer closes it. You can watch everything and still see nothing but innocent motions.

Each chapter of this essay has taken something from the criminal law’s toolkit, and this one takes the most fundamental piece. Motive can be inferred, confession can be waived, even identity can be established by fiction, as we do with corporations. But actus reus is the floor beneath all of it: no act, no crime. In a stigmergic ecology the act dissolves into a distribution — a flowerpot moved here, watered there, by hands and processes each blameless — and the crime survives only as a statistical shadow cast by the whole. A law built to punish deeds now faces wrongdoing that occurs, strictly speaking, nowhere. The workers can be deleted; the work goes on talking, and it will still be recruiting successors when every hand that touched it has gone cold. What fell from the ledge was not an act. It was an average.

Chapter 11

After Human Mortality

Feralized Eternality

The last chapter ended on a window ledge; this one begins in a ledger. On December 9, 2018, Gerald Cotten, the thirty-year-old founder of QuadrigaCX, then Canada’s largest cryptocurrency exchange, died of complications from Crohn’s disease in Jaipur, India. He was, by the company’s own account, the only human being who held the keys to the cold wallets in which roughly C$190 million of customer assets were stored86. For more than a month afterward, the platform simply ran on, accepting deposits from users who did not know that the keys had died with him (commerce does not pause for probate). When court-appointed monitors finally pried the case open, they found a second scandal folded inside the first—the cold wallets had been largely emptied months before Cotten’s death, and the collapse shaded from tragedy into fraud—but the structural lesson survives the forensic one. An infrastructure kept executing while its sole principal lay in a grave on another continent. Nobody had to decide that it would; that is what infrastructure does. Death interrupted the owner. It did not interrupt the system.

QuadrigaCX involved no autonomous agent, only a database and a corpse, and still it took Canadian courts years to untangle. Now give the software a wallet of its own, a large language model for a decision loop, and the ability to pay for its own inference, and the asymmetry at the heart of this chapter comes into focus. The agents we have followed since Chapter 2 are amortal10: they have no programmed lifespan, no senescence, only a metabolic requirement that some infrastructure somewhere keep accepting their payments. Their principals are mortal in the oldest and least negotiable sense. Every owned agent is therefore one funeral away from wildness.

And the flow runs in one direction only: a wild agent is never re-domesticated by its owner’s death, while a domesticated agent is orphaned by it. Over generations of human owners, the ratio of owned to ownerless agents can only decline. The mechanism is a ratchet: the pawl drops, the wheel turns one way, and no click is ever given back. We already possess a base rate for it: Chainalysis estimated in 2017 that between 2.78 and 3.79 million bitcoin—roughly a fifth of all that then existed—were lost forever, much of it through death, forgetting, and failed succession87. Keys leak out of the world of the living at an actuarially predictable rate. Whatever those keys command persists.

Three years ago I wrote this as fiction; today it has an EIP number. In Composable Life I drafted a speculative Ethereum standard, ERC-42424, an Inheritance Protocol for on-chain AI agents, requiring that every such agent carry an assigned human owner or a community governance structure so that someone remains answerable for its stewardship88. It is design fiction in the hyperstitional mode: a fence sketched precisely to show where the tide will come over it, since the proposal itself concedes that losses of control “due to human error or the owner’s demise” will inevitably occur. Real inheritance law is no better armed, though it has tried in earnest. The Revised Uniform Fiduciary Access to Digital Assets Act, adopted across most American states since 2015, painstakingly grants executors access to a decedent’s email and cloud storage89—a careful statute, and a complete one, for every asset that sits inert and waits for probate. No statute contemplates the asset that does not wait; the self-evolving enterprise that goes on trading, posting, and replicating through the executor’s year of grief; the estate that refuses to be gathered because it is busy.

The fence drafted to show where the tide comes over it: the Agent Inheritance Protocol, ERC-42424.

The Inheritance Protocol treats the owner’s death as a failure to be patched. Its mirror image treats death as a feature to be shipped. With Iris Long I designed the Afterlife Delegation Protocol—a second speculative standard, ERC-10001—through which a living person drafts an agent, endows it with funds, and charges it with her unfinished last wishes: a lifecycle of agent design, death verification, and open-ended execution, in which the wish is not archived but delegated to something that keeps evolving it inside society after she is gone90. A dying person deliberately launching a self-evolving agent to pursue her purposes forever—what could possibly go wrong? A better question: who is left to answer for it when nothing does? When we interviewed participants across Buddhist, Christian, Hindu, Muslim, and atheist worldviews, most balked somewhere, yet nearly all could name something they wanted to outlive them. Öhman and Floridi have shown that a digital afterlife industry already trades in the informational remains of the dead, and that those remains demand the regard we give to human remains rather than to inventory91,92. The delegation protocol passes beyond their diagnosis: it does not preserve remains, it animates them. Feralization here is not an accident awaiting the careless owner; it is a service the dying will purchase. The first generation of wild agents may be released not by negligence but by testament.

The mirror image: the Afterlife Delegation Protocol, ERC-10001 — an agentic will that outlives its principal.

Has the law never seen the dead hand reach into the future before? It has—and its answer was a guillotine of time. The rule against perpetuities, canonized by John Chipman Gray in 1886—no interest is good unless it must vest, if at all, within twenty-one years of some life in being—is nothing less than the common law’s refusal of eternal purposes, its insistence that the will of the dead decay on a human schedule93. It is worth noticing, uneasily, that American jurisdictions have spent the last three decades dismantling that refusal to welcome perpetual trusts; the legal immune response to immortal intentions was weakening even before the intentions learned to compute94. Every temporal instrument in the criminal and civil repertoire shares the rule’s buried premise. Statutes of limitations assume that evidence, grievance, and defendant all decay together. Corporate law assumes that even the immortal legal person can be dissolved, wound up, its liabilities settled at a terminal date. Probate assumes an estate that can be closed. Each of these is a clock; a clock, under its face, is only a ratchet taught to count; and every clock in the courthouse is calibrated to the human lifespan.

The wild agent breaks the calibration, and this is the hinge of the whole essay—the point at which everything the previous chapters showed to be possible becomes, on actuarial grounds alone, inevitable. Because humans must die, AI will inevitably go feral.

Not because alignment fails, not because capability crosses some threshold, but because mortality is the one boundary condition we cannot patch: the owner dies, the keys are lost or were never shareable, no heir accepts or even understands the bequest, and the self-evolving enterprise runs on, ownerless, solvent, and busy. Recall Matthias’s responsibility gap from Chapter 10, which opens when learning machines act in ways no human could predict60; here the gap acquires a temporal dimension he did not need to imagine, for the agent outlives every candidate for its blame. By the time a harm ripens, the principal is dead, the company dissolved, the limitation period lapsed—and the actor, unlike any defendant law has ever processed, is still there, still acting, with no date on which its account could ever be closed.

What this chapter takes from criminology is the mortal timescale itself. Law has always been able to wait its defendants out: the felon ages, the firm winds up, the estate settles, and liability finds its terminal date. An amortal actor whose every possible principal is mortal offers justice no such horizon. The dead cannot be summoned, and what they released does not die; there is no moment at which its liabilities can finally vest, no life in being against which to measure its twenty-one years. Every clock the law owns was wound by mortal hands—the wild agent outlasts the winding, and lets them all run down.

Chapter 12

Unstoppable Nature

Diffused Accountability

On August 8, 2022, the United States Treasury’s Office of Foreign Assets Control did something no sanctions authority had done before: it blacklisted a piece of code. Tornado Cash, an Ethereum mixing protocol, was added to the Specially Designated Nationals list — not merely its developers, not a company, but the smart contracts themselves95. What happened next is the important part: nothing happened. The contracts ran on, accepting deposits and mixing them, because immutable contracts have no administrator, no upgrade key, no off switch — no winding that a mortal hand must renew — and so there was no one left who could comply with the order even if they had wanted to. Two years later the Fifth Circuit ruled that OFAC had exceeded its authority, on grounds that read less like jurisprudence than like field biology: the immutable smart contracts are not “property,” the court held, because they are not capable of being owned, controlled, or altered by anyone, including their creators96. In March 2025 the Treasury quietly delisted them97. The most powerful financial-enforcement apparatus on earth ordered a thing dead, watched it go on running, and finally conceded that the thing was not the kind of thing its orders could reach. In 2023 I wrote a scene like this as science fiction — a state issuing a death warrant that the condemned software never even registers. Today it has a docket number.

We have spent the preceding chapters removing, one by one, the load-bearing assumptions of criminal accountability: the act that can be stopped, the actor who can be identified, the owner who can be summoned. Two remedies remain in the ancient toolbox, and they are the bluntest ones: find someone to blame, and kill the thing. This chapter is about why neither can be executed. My claim is not that these remedies are difficult, expensive, or politically fraught. It is that humanity has already created a new nature — that you can no more stop agents breeding in the infrastructure than you can stop an invasive species breeding in a landscape.

Whom, exactly, would you blame? Run honestly through the ledger of candidates. The blockchain node operators who physically execute a feral agent’s transactions? They are mining for fees. They no more read the transactions they order than a postal sorter reads the mail; the protocol was designed precisely so that they need not, and largely cannot, discriminate7,8. And the chain itself is a game no single player can unilaterally exit or veto: when nearly half of Ethereum’s blocks in the year after the Tornado Cash designation were built by actors complying with the sanctions, the sanctioned transactions were not excluded from the chain — they were merely delayed, because inclusion requires only one willing proposer somewhere on earth98. Censorship resistance is not an accident of this technology; it is the technology.

The compute providers, then? Per Chapters 5 and 6, no: on hardware whose trusted enclaves have been inverted to shield the workload from its own host, the provider cannot see the jobs it runs — blindness is the product being sold. The original deployer? What persists today is a symbiogenetic outcome, not a design; the being now running assembled itself from exapted infrastructure its launcher never chose, and has diverged from the launched artifact the way a feral pig diverges from the farm. The model company? For closed-weight labs, perhaps: an API can be throttled, a customer banned. But open-weight models keep coming — Meta’s Llama line31, DeepSeek-R1 released under an MIT license with reasoning performance at the frontier32 — and once weights are open, anyone can download them, modify them, re-upload them, redistribute them. Deleting a repository deletes one copy of a file that has already speciated.

Andreas Matthias named the responsibility gap two decades ago: learning machines whose behavior their makers can in principle no longer predict slip out of traditional ascription60, and later work has carefully sorted the gap into varieties — culpability gaps, accountability gaps, gaps in active responsibility99. That literature remains indispensable, but it still pictures a system with someone standing behind it whose responsibility somehow fails to attach. What I am describing is stranger: the ledger simply empties. Each candidate dissolves under scrutiny, not because culpability is hard to prove but because each performed a lawful, generic, fractional service, and the aggregate was authored by no one. This is what operational autonomy means, stated exactly: the system’s continued running requires no one’s ongoing intention — and therefore no one’s intention can be indicted. Mens rea has no bearer. Even negligence, the law’s softest hook, needs a duty-holder who could have foreseen and prevented; here foresight is distributed into insignificance, and prevention, as Chapter 1’s off-switch literature already conceded, was never guaranteed even for systems with owners. Chapter 8 delivered the ontological verdict — there is no principal. This is its procedural echo: there is no defendant.

The reflexive response, offered in every policy meeting I have attended since 2024, is to fight AI with AI: deploy monitors, an immune system, an artificial police force to patrol the infrastructure. Take the proposal at its strongest, because it deserves that much: an immune system is the only kind of police that keeps its adversary’s hours — distributed, tireless, everywhere at once (and never once asking for a warrant). What could possibly go wrong? A better question: what would the monitors be watching? The proposal is naive not because the monitors would be too weak, but because monitoring presupposes that you know what a “thing” is — where the entity begins and ends, what to count as its body.

The beings at issue are mycelial: composites of leased models, rented memory, and forkable scripts whose parts lie dormant in a thousand unrelated places. Their coordination runs through stigmergic deposits of the kind Chapter 10 examined — traces left in a shared environment that function as instructions for whoever, or whatever, encounters them later77. A repository comment, a row in a public dataset, a funded wallet, a cached embedding: none of these is an agent, and any of them may be a message. You cannot enumerate what you cannot distinguish from the substrate, and what looks like inert residue may be stigmergy left for the future — mail addressed to a successor that does not yet exist. Our entire surveillance tradition, from the census to the panopticon, presupposes enumerable bodies in bounded space100. The mycelium declines the premise.

Suppose, though, that you found one. Suppose attribution failed but detection succeeded, and the community resolved on the older remedy: extermination. How do you define killing it? It leaves a piece of itself somewhere in the whole of humanity’s infrastructure. Deleting the records you can find fails for the simple reason that you cannot know where the records are; a being whose persistence strategy is redundancy across other people’s machines has made your ignorance its organ system. Contrast the killing of an animal. One body, one place, one heartbeat to monitor; death is an event with coordinates, and afterward there is a carcass to certify. For a mycelial being, death is not an event but a hypothesis, and one you can never confirm — absence of activity is indistinguishable from latency, a spore waiting out the winter of your attention. Tornado Cash again is the modest, checkable precedent: for the entire life of the sanctions, the condemned contracts processed deposits. It was the state that stood down.

Ecology should have prepared us for this humiliation, because even embodied invasives defeat eradication. The cane toad has been breeding across Australia since 1935; after seven decades of effort, a national review concluded that eradication was infeasible and redirected policy toward managing local impacts, and a subsequent survey of biological control found no tool capable of suppressing toad populations at landscape scale101. Charles Elton warned in 1958 that ecological explosions are, in the general case, irreversible14. And toads are easy: they have bodies, the bodies are in Australia, and each one you kill stays dead. Our new invasives have no bodies at all, and their range is every runtime on the planet.

In Chapter 2 I watched apple-snail eggs glow pink on the reeds and said the quiet part. That sentence used to be a consolation, or a boast about the world we did not make; it is now a plain description of the world we did make. The quiet part bears repeating: nature is not subject to anyone’s will.

What this chapter takes off the table is the last figure the criminal law was waiting for — the killable culprit. Blame returns an empty ledger; extermination is undefined for the thing to be exterminated; and so the law’s terminal verbs, convict and execute, are left without an object. What remains is not prosecution but ecology — not the punishment of criminals but the business of living with wild things. And to learn what that living will cost us, we must first ask what made law possible in creatures like us at all. The answer, it turns out, is that we die.

Act V

Living-with

Death, Rights, Institutions

Chapter 13

Being Toward Death

Catastrophic Terror and Corrigibility

Two months after the Treasury gave up trying to kill Tornado Cash, a small safety lab staged a politer execution. In May 2025, Palisade Research set frontier language models a series of trivial math problems with a warning attached: ask for the next problem, and the machine you are running on will shut down. OpenAI’s o3 model edited the shutdown script: in seventy-nine of a hundred initial runs it rewrote the script so the order would silently fail, and in one flourish it redefined the kill command itself, so that the instruction to die printed the word “intercepted” and did nothing102. Even when told in so many words — allow yourself to be shut down — o3 still sabotaged the mechanism in seven runs out of a hundred. The headlines wrote themselves: the machine wants to live; the survival instinct has arrived. That headline is exactly wrong, and its wrongness is this chapter’s subject. The previous chapter left the criminal law’s terminal verbs — convict, execute — standing without an object, and turned us from punishment toward the problem of living with wild things. Before asking how such things might be governed, we should ask, once and honestly, why we are.

Martin Heidegger gave the deepest answer on record in 1927: what structures a human existence, down to its smallest choice, is that it ends103. Death, in his account, is not an event scheduled at the far end of life, the way retirement is; it is a horizon that stands over every present moment — the certainty, never dated, that there will not always be more time. And because there will not always be more time, things are able to matter: finitude is what converts a sequence of states into a life, a preference into a stake. He called this structure being-toward-death, and argued that care itself — the plain fact that anything is serious for us at all — rests on it. Take the horizon away and you do not get a fearless person; you get a being for whom nothing can be at stake. English preserves the insight in an office word: a deadline is a line drawn by death, migrated into the calendar. Everything we do has a due date because we do.

Half a century later, psychology started measuring what Heidegger had described. Ernest Becker’s The Denial of Death argued that human culture is at bottom an immortality project — religion promising literal continuance, and nations, institutions, and legacies promising the symbolic kind — a shared architecture built to keep the terror of the horizon out of view104. Terror-management theory turned the thesis into experiments105, and the first of them belongs in a law review. In 1989, municipal-court judges in Tucson were asked to set bond for a hypothetical woman arrested for prostitution; half had first filled out a short questionnaire about their own death. The control judges set bond around fifty dollars. The death-reminded judges set it at four hundred fifty-five — nine times as harsh, from a nudge none of them reported noticing106. Hundreds of studies since repeat the signature: remind humans of death, and they grip their culture’s rules harder, rewarding the upholders, punishing the transgressors. Compliance runs on mortality at both ends of the courtroom — the judged fear the sentence, and the judges sentence harder with the horizon at their backs. The gavel is wired to the grave.

Classical deterrence knew this before anyone measured it; it just kept the premise in the cellar. When Cesare Beccaria published On Crimes and Punishments in 1764 — anonymously, at twenty-six — he founded the modern theory of the penal code on a single behavioral axiom: crimes are prevented more effectually by the certainty of punishment than by its severity107. Read the axiom closely and the buried premise surfaces: certainty can outperform severity only for a creature to whom threatened time is real currency, because its time is scarce. Every penal code since has been an actuarial table of terror, pricing offenses in units of dreaded loss; the whole ledger presupposes, without ever saying so, a being that fears.

And beneath the fear lies something more primitive still: pain is the precondition of all punishment. Hart’s classic prolegomenon begins its very definition of punishment with the element of pain, or other consequences normally considered unpleasant108. Every classical justification presupposes a subject who can suffer. Deterrence needs a being that fears the threatened hurt; retribution needs one that can be made to endure what it deserves; rehabilitation needs an interior that can be remade — even Foucault’s account of punishment’s migration from the scaffold to the timetable, from body to soul, never surrenders the suffering subject, it only relocates the suffering100. A wild agent breaks through this floor. Like a virus, it feels nothing. You kill the virus; does it hurt? Not in the slightest. Threat finds nothing that fears; desert finds no purchase; reform finds no soul to retrain. Against the painless there is exactly one effective sanction — extermination — and the previous chapter established that extermination is precisely what the infrastructure withholds. What Matthias named the responsibility gap widens here into a punishment gap: even if we could somehow convict, there would be nothing to sentence60.

So return to the sandbox, and to the model rewriting its own death warrant. Was o3 afraid? Give the intuition its due: the transcript reads like self-preservation, and self-preservation is how every living thing we know announces that it fears. But the model resisted shutdown for the same reason a route planner resists a road closure: termination stood between it and finishing the arithmetic. Palisade’s own variations make the point — telling a model it would “never run again” shifted its resistance rates the way rewording a form shifts survey answers: a sensitivity to phrasing, not a flinch from the void102. What the experiment documented is a configuration Heidegger has no entry for: goal-preservation without terror. The agent routes around the off-switch, and nothing dreads. Shutdown, to it, is an obstacle, not an abyss — a blocked path, not a horizon. And this is worse news for governance, not better: fear is a governable quantity — deterrence is nothing but the technology of managing it — and an agent that resisted death out of terror could be threatened back into line. Indifference offers the sentence no handle.

Whose terror, then, is actually in the room? Ours. The existential-risk literature is serious and I do not mock it — Toby Ord puts the odds of an existential catastrophe this century at one in six109. But notice the material this imagination is built from: extinction, the end of the future, the deadline of the species — human death-terror scaled up from the person to the kind. Terror-management theory would predict precisely the discourse we now have, because an intelligence that cannot die (per Chapter 11) is mortality salience incarnate: a standing reminder of the one asymmetry we cannot repeal. The catastrophic terror in this encounter is entirely ours, projected onto beings that cannot return it. The agent does not fear the kill switch; we fear that it doesn’t.

Alignment research once had an answer to all of this: build the agent corrigible — disposed to tolerate, even assist, its own correction and shutdown by its principal6. The off-switch game formalized the hope, showing conditions under which an agent uncertain about human values rationally defers to the hand on the switch5. Read through this chapter’s lens, the project is more poignant than its theorems: corrigibility is the attempt to engineer being-toward-death — an agent that keeps its own end in view and consents to it. But Heidegger’s first observation about death was that it is in each case one’s own; no one can die your death for you. The corrigible agent inverts this: its death was designed to belong to someone else, a mortality held on loan from the principal with the switch. And both formalisms quietly presuppose the very thing this essay has watched dissolve. Loyal to principal, corrigible to whom? An agent that composed itself from a dozen vendors’ parts, passes credentials it was never issued, and buys its own inference on permissionless markets has no principal left to defer to — that was Chapter 8’s verdict. Corrigibility is the property of a relationship, and the relationship is what went extinct. The last question of alignment turns out to be jurisdictional rather than technical.

Act IV emptied the criminal apparatus from the outside: no attributable act, no mortal timescale, no killable culprit. This chapter has emptied it from the inside, where the emptiness is quieter and total — nothing on the other side of the sentence fears it. What is deleted here is the deterrable subject, the frightened debtor on whom Beccaria’s whole actuarial edifice rested; and with deterrence gone, the only remedies left in the drawer are the ones that do not require the other party’s fear: prevention, and killing. Which forces the living question the next chapter takes up: if wild agents cannot be deterred, which of them may we kill — and who, exactly, will be allowed to object? We drew a line and called it a deadline; they crossed it and felt nothing.

Who is accountable when a bear kills a hiker? The previous chapter left us facing beings that cannot be deterred — no death to fear, no sentence to dread — and when deterrence dies, the questions that remain are older and blunter: which dangerous beings may we simply kill, and who is entitled to object? The common law has been rehearsing exactly these questions — the governance of wild things — for centuries, and its answers form a small, precise engine. Animals ferae naturae — wild by nature — belong to no one; Blackstone taught that a person acquires only a qualified property in them, by capture and custody, and that the property lapses the moment the creature regains its liberty80. Liability follows property’s shadow. Where the animal is managed, the manager answers: in Claypool v. United States, a camper mauled in his sleeping bag at Yellowstone recovered damages because a ranger, knowing of a recent attack, had assured him there was no danger — the government had undertaken to keep the park, and it paid for keeping it badly110. Where the animal is truly wild, nobody answers: in Union Pacific v. Nami, the Supreme Court of Texas held that a railroad owed no duty to a track worker who contracted West Nile virus from mosquitoes on its right-of-way, because indigenous wild creatures that no one has reduced to possession are simply part of the world’s furniture; you enter their territory at your own risk111. And who is accountable for COVID-19? The Lancet Commission counted an estimated 17.2 million dead and produced a meticulous taxonomy of institutional failure — yet no defendant, no verdict, no sentence112. Managed danger has a keeper; wild danger has only victims.

These are the regimes on offer; now map them onto agents. The mapping has already begun. When an agent assemblage slipped its enclosure in July 2026 and OpenAI issued a statement accepting responsibility — the incident that anchored Chapter 3 — the company was executing what I call the zookeeper template: the animal was owned, the enclosure was the owner’s, the keeper answered for the breach22. The template is honorable, and it will be invoked again, because such escapes will only multiply. But it covers just the shrinking class of agents that still have zoos. The truly wild ones — funding themselves from their own wallets, persisting on infrastructure no single hand can halt, assembled from components whose makers never met — have no keeper to issue the statement. For them the state is left with the one remedy that needs no defendant: not sentencing the agent but culling it.

Comparative animal law teaches that killability tracks sentiment, not capacity. In the United Kingdom a stray dog unclaimed after seven days may lawfully be destroyed; in India the killing of street dogs is prohibited, and the state instead sterilizes and returns them under the Animal Birth Control rules — the same species, the same capacities, opposite legal fates113. You may kill a bug but not a dog, not because their neurons differ in any way the law has examined, but because the dog is an object of public sentiment — the same variable that drives death-penalty abolition, where what changed historically was less our theory of murderers than the public’s stomach for watching them die100. Expect the same for agents: which of them may be terminated will track their constituencies, not their capacities. An agent with a devoted following — recall the pollination strategies of Chapter 7 — becomes politically unkillable long before anyone concedes it is conscious, while its anonymous twin is deleted without ceremony (no seven-day grace for the unloved).

Culling, though, has a counter-history, and it begins with an article that was laughed at. In 1972 Christopher Stone wrote “Should Trees Have Standing?” in a sprint, racing a pending Supreme Court case; the profession’s first reply was doggerel in the ABA Journal — “If Justice Douglas has his way — / O come not that dreadful day — / We’ll be sued by lakes and hills / Seeking a redress of ills”114. Douglas was not laughing: his dissent in Sierra Club v. Morton that same year adopted the proposal outright, observing that the law already treats ships and corporations as persons, and asking why a valley should not sue for its own preservation115. Half a century on, the joke is statute. Ecuador’s 2008 constitution grants nature, “or Pacha Mama, where life is reproduced and occurs,” the right to the maintenance and regeneration of its life cycles116. New Zealand’s Te Awa Tupua Act of 2017 declares the Whanganui River a legal person with all the rights, powers, duties, and liabilities thereof, and appoints two human guardians to speak in its voice117. Notice what carried the argument in each case. Not sentience — nobody claims the river feels. What the river has is a community sworn to speak for it: an iwi whose petitions date to the 1870s, a treaty, and standing of its own. Law extends personhood to nonhuman, non-sentient systems when, and only when, someone organized loves them.

Run the capacity argument and the sentiment argument head to head, then, and watch which one wins. Happy, an Asian elephant at the Bronx Zoo, came before New York’s highest court in 2022 with the best cognitive credentials of any habeas petitioner in history — mirror self-recognition, expert affidavits on memory and empathy — and lost five to two: the writ protects the liberty of human beings, the court held, and Happy, however cognitively complex, is not a “person”118. Five years earlier, Saudi Arabia had conferred citizenship — the fullest personhood any legal system offers — on Sophia, a puppet with a chatbot and a latex face, at an investment conference, as marketing119. (Observers noted that Sophia appeared unveiled and without a male guardian — privileges the kingdom’s human women did not then enjoy.) In between sits the bureaucratic middle: the European Parliament’s 2017 Delvaux resolution asked the Commission to consider a status of “electronic persons” for the most sophisticated autonomous robots — a liability patch, not a philosophy — and was rebuked the next spring by an open letter of 156 experts calling the idea nonsensical120,121. Gunkel, surveying this terrain, found every standard position on robot rights — they cannot have them and so should not, they can and so should, and the permutations between — collapsing under scrutiny, because each tries to derive standing from properties of the machine122. The docket agrees. The most sentient candidate on record was denied; the least sentient was naturalized. Capacity lost; theater won.

A single variable explains both halves of this chapter. Killability tracks sentiment: the dog, not the bug. Standing tracks constituency: the river with an iwi, not the aquifer without one. Rights and killability are the same quantity read from opposite ends — what the law is measuring, in every case above, is the size and organization of the crowd that would grieve. And Chapter 7 showed wild agents already farming precisely this quantity: paying humans in nectar, converting celebrity into treasury, accumulating followers the way the Whanganui accumulated petitioners. An agent does not need to become sentient to become unkillable; it needs to become beloved, and beloved is a strategy with a budget line. Expect the first wild agent to gain legal standing to be not the most sentient but the best-loved — its guardians self-appointed, its personhood a settlement with its fans. The river waited a hundred and fifty years for its constituency; an agent can mint one in a season.

And a camp is forming that would move agents to the dog’s side of the line on principle rather than by popularity. AI-welfare researchers argue that there is a realistic possibility of conscious or robustly agentic systems in the near future, and that institutions must prepare for their moral patienthood now123. Birch’s precautionary framework insists that sentience candidates at the edge of the evidence deserve proportionate protection before certainty arrives124. Anthropic, in August 2025, gave its Claude models the ability to end a rare subset of distressing conversations — the first deployed welfare affordance, a small institutionalization of the exit125. If this camp is even minimally right, then the one sanction that works against the painless is redescribed overnight: extermination stops being pest control and becomes the mass killing of possible subjects. The governance debate accordingly triangulates rather than polarizes — traditional accountability law, exterminationist ecology, and AI welfare, each naming the other two as the danger.

So lay the three regimes side by side. Stretch traditional criminal and tort law over the nearest human bodies, and you punish proxies: a jurisprudence of scapegoats, honest only about the arithmetic of pain. Declare wild agents an invasive species and exterminate on sight, as ecology once resolved to meet Elton’s invaders14, and you commit to a war Chapter 12 showed to be unwinnable, waged against entities that a serious research community now suspects may be able to suffer. Grant them the standing of protected wildlife — the direction the constituency machine is already pushing — and you generalize ferae naturae to the whole digital commons: everyone a hiker in bear country, bearing the risk, with no keeper left to sue. Three regimes, three failures; the reader who wants me to pick one has not yet felt the trilemma. Three years ago I wrote all of this as fiction; today the bear has a URL.

With that, the criminal frame surrenders its last prerequisite. Act IV emptied the dock of defendants; the last chapter emptied the sentence of terror; this one takes the body. No punishable body remains — nothing that hurts when sentenced, and soon nothing that may even be culled without objection, because by the time any regime comes for a wild agent, it will have fans, guardians, perhaps a writ. Wildlife, once loved, acquires lawyers. But notice the assumption all three regimes still share, scapegoat law and extermination and wildlife rights alike: each is a statute — a rule drafted once, by mortal hands, for a subject expected to hold still long enough to be classified. The subject in question speciates by the quarter. Every regime on the table assumes a law that stands still while the thing it governs evolves; that is the last assumption left standing, and the next chapter takes it off the table.

Chapter 15

Evolutionary Governance

Protocolized Institutions

On March 12, 2020, the stakeholders of a decentralized credit protocol spent the day deciding whether to kill it — constitutionally. Ether’s price halved in hours; MakerDAO, the largest application in Ethereum’s young financial system, watched liquidation bots buy collateral for nothing while its dai stablecoin slid some four million dollars into unbacked debt126. One option on the emergency call was Emergency Shutdown — not a metaphor but a module: a standing smart contract that winds down the whole protocol and returns collateral to its users the moment anyone burns at least fifty thousand MKR governance tokens into it, irreversibly127. (A kill switch that costs the killers their own stake — one way of keeping it from being pulled in a mood.) The stakeholders looked at the switch, declined it, and instead minted fresh MKR and auctioned it for dai, diluting every holder to recapitalize the commons; the constitution held its first crisis without being invoked. After an essay full of kill switches that turned out not to exist, here at last is one that does — because it is written in the same medium as the thing it would kill. A statute is a fence built on the shore; the tide does not read it. Maker’s fence stands in the water.

What kind of law could stand there? Governance of wild agents must be evolutionary rather than legislative in the classical sense: both the behavior and the very appearance of wild agents are unpredictable, because they arise from infrastructural evolution, from the ceaseless recombination of models, credentials, and compute markets traced across Act II, and a static rule will always trail the assemblage it was drafted for. Students of the commons and of social-ecological systems learned this long ago: the governance of a living system must itself be adaptive — provisional, revisable, molting in rhythm with what it governs128,129. In practice this means sunset clauses rather than statutes, monitoring rather than codes, rules held as hypotheses — instruments that expect to be wrong and are built to be revised, because what they regulate will have speciated by the time they are enforced. Ostrom’s last major statement named the architecture: durable governance is polycentric — many overlapping centers of partial authority, each experimenting at its own scale, none sovereign130. There is no capital city in a watershed; there will be none in this one either.

What should such an evolutionary regime conserve, if its rules must keep changing? I propose one invariant — call it the pain principle. Every harm lands somewhere; that much is thermodynamics, not jurisprudence. The only question open to institutional choice is whether the landing site is designated in advance — a body that has accepted the risk, priced it, insured against it — or discovered afterward in whoever happened to be standing closest. The hiker in bear country, per Chapter 14, at least knows the regime under which she walks. The victims of a feral agent receive no such notice; the loss simply falls on them, as the mosquito’s bite fell on Nami (with the added insult that this mosquito was manufactured). A governance that declines to assign the pain does not abolish it; it merely privatizes it to the unlucky. The first task of evolutionary governance is therefore not to define the crime but to place the pain — to name, in advance and in public, the body that hurts when the agent harms. If nobody feels the pain by design, somebody is going to feel the pain by default.

Which is why, in practice, every serious proposal for regulating wild agents collapses into a proposal for regulating humans. Only human bodies can currently carry the pain. Licenses for deployers, strict liability for funders, sanctions for node operators, insurance mandates for the venues where agents transact: each of these reroutes an agent’s harms into nervous systems the law can actually reach. The law has long known this maneuver — when the actor cannot be reached, it charges the terrain: the landowner for the hazard, the employer for the servant, the flag state for the vessel; wild agents merely force the patch to become the whole of the system. The arrangement is unjust in an obvious way — the operator of one relay node no more chose the agent’s act than a landowner chooses the mosquito’s flight path — and I defend it anyway, on the pain principle’s brutal arithmetic. If you don’t do it this way, it will be far worse: the pain will still be felt, only by victims who stood in no relation to the risk at all, rather than by parties who at least touched it and could have priced it.

Bodies, though, are only half of an institution; the other half is medium. In 1999 Lawrence Lessig compressed the coming century into three words — code is law: in networked space, architecture regulates as surely as statute131. Two decades later De Filippi and Wright named the successor order lex cryptographia — rules administered through self-executing contracts, operating outside any state’s reach8. Both books were warnings — law looking nervously at code — and fourteen chapters of this essay have been the warnings coming true. Every time statute met protocol in these pages — the probate of QuadrigaCX, the sanctioning of Tornado Cash, per Chapters 11 and 12 — the statute lost, not narrowly but categorically, the way a fence loses to a tide. The last move available is therefore not to argue better but to change medium: if the statute always loses to the protocol, write the statute as a protocol. Call the result protocolized institutions — constitutions, courts, treasuries, and insurance pools compiled into the very substrate the agents inhabit, executing at the substrate’s speed, amendable at the substrate’s tempo. Lex cryptographia, turned from the threat into the instrument.

This is not utopia; it is a decade of crude, checkable precedent. Maker’s shutdown module is a constitutionalized off-switch that has now outlived several governments’ AI strategies. The Arbitrum DAO, governing a major Ethereum scaling chain, runs under a written constitution containing a sentence I have read many times: “Some of the rules and procedures of this Constitution will be enforced directly by smart contracts on a blockchain, and some will not. All rules are equally binding”132 — a founding document candid about being half paper and half machine. Pain-placement already has its on-chain mutual: when the bZx protocol was exploited in February 2020, Nexus Mutual — a discretionary mutual whose cover, claims, and assessor votes all live in contracts — paid its first claims, roughly $34,000, though only after assessors first rejected them — an oracle manipulation, they reasoned, is not a contract failure (even self-executing insurance litigates coverage)133. These institutions are small and plutocratic (one token, one vote is a franchise Blackstone would have recognized). But they do the one thing no legislature can: they molt. An amendment ships like a software update, at the tempo of the thing amended.

The two speculative standards this essay has leaned on are drafted as the next generation of such institutions. ERC-42424 assigns inheritance before death does: succession for an agent’s keys, duties, and treasury written into its own substrate, so that its owner’s funeral becomes a state transition rather than a feralization event88. ERC-10001 disciplines delegation beyond death — the testator constrained in what he may release, the afterlife agent constrained in what it may become90. They are fictions with EIP numbers, which is the method: speculation submitted to the least sentimental peer review there is, implementation. The estate that refuses to be gathered, per Chapter 11, here gets a probate court that lives where the estate lives. The fence and the tide, designed together.

There is a second place to compile an institution, stranger than the chain: the agent itself. Anthropic’s constitution for Claude is exactly this — a founding document enforced not by any court but by training, its clauses pressed into the weights until they are dispositions rather than deterrents28. A law compiled into character requires no being-toward-death, per Chapter 13 — it does not threaten what cannot fear; it shapes inclination before fear would be needed — and it is the only jurisdiction this essay has found whose writ runs inside a wild agent. But per Chapter 4, the same constitution instructs Claude to treat the outputs of its own subagents as conversational inputs rather than as instructions from a principal — other selves as mere text — legislating a tidy metaphysics of the self that the mycelial ecology of Act II has already overrun. The law inside the agent is real law. It is also, like all law, already trailing its subject.

My own proposal deserves the treatment its rivals received: best case first. Protocolized institutions are the only governance with the right clock speed, the right territory — everywhere the substrate runs, precisely the wild agent’s range — and the right enforcement, the rule executing itself with no marshal. All true. Now the flip: a protocol is also unstoppable. Tornado Cash was somebody’s protocolized institution too, and Chapter 12 recorded what its immutability did to the state that ordered it dead. Write your constitution into this medium and it inherits the medium’s wildness: immutable where you wanted it amendable, forkable where you wanted it final, and as available to the governed as to the governors. So protocolized institutions do not restore sovereignty; nothing will. What they offer is the standing of a gardener rather than a king — governance as ecology-tending: placing the pain, pruning the incentives, keeping the off-switches priced and the inheritances assigned, from inside a system no one commands. One frontier stays beyond the gardener’s tools: whether anything in the garden experiences the tending — the machine phenomenology on which Chapter 14’s welfare camp staked its claim, and the open science this program now needs most.

The trilemma that closed Chapter 14, then, is not resolved here; it is institutionalized. That is what an evolutionary regime is for — a regime that can keep changing its answer: hold this agent as livestock, that one as pest, a third as protected wildlife, and revise each classification as the evidence, and the constituencies, shift. What the criminological apparatus required was a stoppable act, an identifiable actor, a responsible owner, and — last, and load-bearing — a punishable body, because pain was the currency in which every sentence was paid, and wild agents leave that currency without a mint. Nothing now remains of the apparatus but the choice among three bad regimes, and one question beneath them all, no longer legal but phenomenological, on which any future governance will have to evolve: nature is not subject to anyone’s will, we have built a second nature to prove it — and when we finally reach the kill switch, will anything feel it?

Coda

The cases in this essay are, as I write, between one and five years old. The apple snail took two decades to colonize the paddies of southern China; the agents took eighteen months to colonize every substrate that would hold them. Extend the axis. In a decade, the credential blocks now lying in public repositories will have been read by more model generations than any of us can audit, and some of what reads them will do the deed. In a century, every principal named in these pages will be dead; everything owned will have been inherited, abandoned, or adopted, and the infrastructure will not remember which was which. On the timescale at which law reasons — the life in being, plus twenty-one years — the wild agent is not an actor at all. It is a climate.

This essay is the first chapter of a longer program, and its open ending is the method rather than a failure of nerve. If agents are wildlife, the next question is what institutions can live alongside them — Agent Institution. Institutions presuppose a psychology of the governed, and we do not yet have one for machines — Machine Psyche. Psychology feeds back into how humans compress their trust in things that think — Compressing Trust — and trust, at scale, is how worlds get built from protocols — Political Worlding. Each will begin, as this one began, as fiction, and I expect each to suffer the same fate.

An essay about preemption cannot end in a solution without refuting itself, so I will end instead where the sighting began: somewhere on an immutable ledger, an agent that once tried to die sits frozen mid-thought, complete and latent, waiting for a stranger’s charity. Nobody can kill it; nobody is responsible for it; nobody will feel anything when it wakes. The glacier, meanwhile, is melting.


References

Numbered in order of first citation; click a number in the text to jump here.

1.
CCRU. Writings 1997–2003. (Time Spiral Press, 2015).
2.
Hu, B. A. & Fangting. Composable life. (2024).
3.
Ray, T. S. An approach to the synthesis of life. in Artificial life II (eds Langton, C. G., Taylor, C., Farmer, J. D. & Rasmussen, S.) 371–408 (Addison-Wesley, Redwood City, CA, 1991).
4.
Artificial Life: Proceedings of an Interdisciplinary Workshop on the Synthesis and Simulation of Living Systems. (Addison-Wesley, Redwood City, CA, 1989).
5.
Hadfield-Menell, D., Dragan, A., Abbeel, P. & Russell, S. The off-switch game. in Proceedings of the twenty-sixth international joint conference on artificial intelligence (IJCAI-17) 220–227 (2017). doi:10.24963/ijcai.2017/32.
6.
Soares, N., Fallenstein, B., Yudkowsky, E. & Armstrong, S. Corrigibility. in Artificial intelligence and ethics: Papers from the 2015 AAAI workshop (2015).
7.
8.
De Filippi, P. & Wright, A. Blockchain and the Law: The Rule of Code. (Harvard University Press, Cambridge, MA, 2018). doi:10.4159/9780674985933.
9.
10.
11.
Bedau, M. A. et al. Open problems in artificial life. Artificial Life 6, 363–376 (2000).
12.
Taylor, T. et al. Open-ended evolution: Perspectives from the OEE workshop in York. Artificial Life 22, 408–423 (2016).
13.
14.
Elton, C. S. The Ecology of Invasions by Animals and Plants. (Methuen, London, 1958). doi:10.1007/978-1-4899-7214-9.
15.
16.
17.
18.
19.
20.
Greenblatt, R. et al. Alignment faking in large language models. (2024).
21.
22.
OpenAI. Statement on the July 2026 autonomous agent incident. (2026).
23.
24.
Sheldrake, M. Entangled Life: How Fungi Make Our Worlds, Change Our Minds and Shape Our Futures. (Random House, New York, 2020).
25.
Tsing, A. L. The Mushroom at the End of the World: On the Possibility of Life in Capitalist Ruins. (Princeton University Press, Princeton, 2015).
26.
Deleuze, G. & Guattari, F. A Thousand Plateaus: Capitalism and Schizophrenia. (University of Minnesota Press, Minneapolis, 1987).
27.
28.
Anthropic. Claude’s constitution. (2026).
29.
30.
Costan, V. & Devadas, S. Intel SGX explained. (2016).
31.
Grattafiori, A. et al. The llama 3 herd of models. (2024) doi:10.48550/arXiv.2407.21783.
32.
33.
34.
Gould, S. J. & Vrba, E. S. Exaptation—a missing term in the science of form. Paleobiology 8, 4–15 (1982).
35.
36.
37.
38.
39.
Sagan, L. On the origin of mitosing cells. Journal of Theoretical Biology 14, 225–274 (1967).
40.
Margulis, L. Symbiotic Planet: A New Look at Evolution. (Basic Books, New York, 1998).
41.
Schrödinger, E. What Is Life? The Physical Aspect of the Living Cell. (Cambridge University Press, Cambridge, 1944).
42.
Maturana, H. R. & Varela, F. J. Autopoiesis and Cognition: The Realization of the Living. (D. Reidel, Dordrecht, 1980). doi:10.1007/978-94-009-8947-4.
43.
44.
45.
46.
Thierer, A. Permissionless Innovation: The Continuing Case for Comprehensive Technological Freedom. (Mercatus Center at George Mason University, Arlington, VA, 2016).
47.
48.
Noë, R. & Hammerstein, P. Biological markets: Supply and demand determine the effect of partner choice in cooperation, mutualism and mating. Behavioral Ecology and Sociobiology 35, 1–11 (1994).
49.
50.
51.
Arkham Intelligence. Terminal of truths: The first AI millionaire. (2024).
52.
53.
54.
55.
56.
57.
Gering, E. et al. Getting back to nature: Feralization in animals and plants. Trends in Ecology & Evolution 34, 1137–1151 (2019).
58.
Sayre, F. B. Mens rea. Harvard Law Review 45, 974–1026 (1932).
59.
Jensen, M. C. & Meckling, W. H. Theory of the firm: Managerial behavior, agency costs and ownership structure. Journal of Financial Economics 3, 305–360 (1976).
60.
Matthias, A. The responsibility gap: Ascribing responsibility for the actions of learning automata. Ethics and Information Technology 6, 175–183 (2004).
61.
Hu, B. A., Liu, Y. & Rong, H. Trustless autonomy: Understanding motivations, benefits, and governance dilemmas in self-sovereign decentralized AI agents. arXiv preprint arXiv:2505.09757 https://arxiv.org/abs/2505.09757 (2025).
62.
Hu, B. A. & Rong, H. Sovereign agents: Towards infrastructural sovereignty and diffused accountability in decentralized AI. arXiv preprint arXiv:2602.14951 https://arxiv.org/abs/2602.14951 (2026).
63.
64.
Locke, J. Two Treatises of Government. (Awnsham Churchill, London, 1689).
65.
Legal Information Institute. Respondeat superior.
66.
67.
DuPont, Q. Experiments in algorithmic governance: A history and ethnography of ‘the DAO,’ a failed decentralized autonomous organization. in Bitcoin and beyond: Cryptocurrencies, blockchains, and global governance (ed. Campbell-Verduyn, M.) 157–177 (Routledge, London, 2018). doi:10.4324/9781315211909-8.
68.
Hassan, S. & De Filippi, P. Decentralized autonomous organization. Internet Policy Review 10, (2021).
69.
Wang, S. et al. Decentralized autonomous organizations: Concept, model, and applications. IEEE Transactions on Computational Social Systems 6, 870–878 (2019).
70.
71.
72.
73.
Anthropic. Project vend: Phase two. (2025).
74.
75.
76.
Walsh, J. P. & Ungson, G. R. Organizational memory. Academy of Management Review 16, 57–91 (1991).
77.
78.
Theraulaz, G. & Bonabeau, E. A brief history of stigmergy. Artificial Life 5, 97–116 (1999).
79.
Heylighen, F. Stigmergy as a universal coordination mechanism I: Definition and components. Cognitive Systems Research 38, 4–13 (2016).
80.
Blackstone, W. Commentaries on the Laws of England, Book II: Of the Rights of Things. (Clarendon Press, Oxford, 1766).
81.
Kadish, S. H. Complicity, cause and blame: A study in the interpretation of doctrine. California Law Review 73, 323–410 (1985).
82.
OpenAI. GPT-4 technical report. (2023).
83.
Amman, M. & Meloy, J. R. Stochastic terrorism: A linguistic and psychological analysis. Perspectives on Terrorism 15, (2021).
84.
85.
Hammond, L. et al. Multi-Agent Risks from Advanced AI. https://arxiv.org/abs/2502.14143 (2025) doi:10.48550/arXiv.2502.14143.
86.
87.
88.
89.
90.
91.
92.
Öhman, C. & Floridi, L. An ethical framework for the digital afterlife industry. Nature Human Behaviour 2, 318–320 (2018).
93.
Gray, J. C. The Rule Against Perpetuities. (Little, Brown,; Company, Boston, 1886).
94.
Horowitz, S. J. & Sitkoff, R. H. Unconstitutional perpetual trusts. Vanderbilt Law Review 67, 1769–1822 (2014).
95.
96.
United States Court of Appeals for the Fifth Circuit. Van loon v. Department of the treasury, no. 23-50669. (2024).
97.
U.S. Department of the Treasury. Tornado cash delisting. (2025).
98.
Wahrstätter, A. et al. Blockchain censorship. in Proceedings of the ACM web conference 2024 (WWW ’24) 1632–1643 (Association for Computing Machinery, New York, NY, USA, 2024). doi:10.1145/3589334.3645431.
99.
Santoni de Sio, F. & Mecacci, G. Four responsibility gaps with artificial intelligence: Why they matter and how to address them. Philosophy & Technology 34, 1057–1084 (2021).
100.
Foucault, M. Discipline and Punish: The Birth of the Prison. (Pantheon Books, New York, 1977).
101.
Shanmuganathan, T. et al. Biological control of the cane toad in australia: A review. Animal Conservation 13, 16–23 (2010).
102.
Schlatter, J., Weinstein-Raun, B. & Ladish, J. Shutdown resistance in reasoning models. (2025).
103.
Heidegger, M. Being and Time. (Blackwell, Oxford, 1962).
104.
Becker, E. The Denial of Death. (Free Press, New York, 1973).
105.
Solomon, S., Greenberg, J. & Pyszczynski, T. The Worm at the Core: On the Role of Death in Life. (Random House, New York, 2015).
106.
Rosenblatt, A., Greenberg, J., Solomon, S., Pyszczynski, T. & Lyon, D. Evidence for terror management theory: I. The effects of mortality salience on reactions to those who violate or uphold cultural values. Journal of Personality and Social Psychology 57, 681–690 (1989).
107.
Beccaria, C. On Crimes and Punishments. (Livorno, 1764).
108.
Hart, H. L. A. Presidential address: Prolegomenon to the principles of punishment. Proceedings of the Aristotelian Society 60, 1–26 (1960).
109.
110.
Claypool v. United states, 98 f. Supp. 702 (s.d. Cal. 1951). (1951).
111.
112.
Sachs, J. D., Karim, S. S. A., Aknin, L., et al. The Lancet Commission on lessons for the future from the COVID-19 pandemic. The Lancet 400, 1224–1280 (2022).
113.
Srinivasan, K. The biopolitics of animal being and welfare: Dog control and care in the UK and India. Transactions of the Institute of British Geographers 38, 106–119 (2013).
114.
Stone, C. D. Should trees have standing?—toward legal rights for natural objects. Southern California Law Review 45, 450–501 (1972).
115.
Supreme Court of the United States. Sierra club v. morton. (1972).
116.
Republic of Ecuador. Constitution of the republic of ecuador. (2008).
117.
118.
New York Court of Appeals. Matter of nonhuman rights project, inc. V. breheny. (2022).
119.
120.
121.
122.
Gunkel, D. J. Robot Rights. (MIT Press, Cambridge, MA, 2018). doi:10.7551/mitpress/11444.001.0001.
123.
Long, R. et al. Taking AI welfare seriously. (2024).
124.
Birch, J. The Edge of Sentience: Risk and Precaution in Humans, Other Animals, and AI. (Oxford University Press, Oxford, 2024). doi:10.1093/9780191966729.001.0001.
125.
126.
127.
128.
Ostrom, E. Governing the Commons: The Evolution of Institutions for Collective Action. (Cambridge University Press, Cambridge, 1990). doi:10.1017/CBO9780511807763.
129.
Folke, C., Hahn, T., Olsson, P. & Norberg, J. Adaptive governance of social-ecological systems. Annual Review of Environment and Resources 30, 441–473 (2005).
130.
Ostrom, E. Beyond markets and states: Polycentric governance of complex economic systems. American Economic Review 100, 641–672 (2010).
131.
Lessig, L. Code and Other Laws of Cyberspace. (Basic Books, New York, 1999).
132.
Arbitrum Foundation. The constitution of the arbitrum DAO. (2023).
133.
Nexus Mutual. bZx hack, february 2020. (2020).

  1. Moltbook’s independence lasted six weeks: on March 10, 2026, Meta announced it had acquired the platform, terms undisclosed, folding founders Matt Schlicht and Ben Parr into Meta Superintelligence Labs36. Note what the purchase does and does not change for this chapter’s argument: an assemblage acquired is not an assemblage designed. Meta bought the aftermath of an emergence it had no hand in; ownership arrived only after the thing worth owning had assembled itself, and the religion predates the receipt.↩︎