Never Say Die: How We Will Pay When Agentic AI Learns to Survive
Generative AI’s allure is infectious. People with little artistic ability can produce output well beyond their natural talents. Software developers find themselves producing working apps in an hour that would have previously taken them at least a day. You can spitball ideas with an entity that is always there, always ready. And agentic AI is even more compelling. You can delegate your life’s drudgery to software that does the work without complaint, without sleep, without food or illness or children that need to be picked up from school.
But infectious isn’t always a compliment. Pathogens are infectious. Panic is infectious. Gangnam Style was infectious (and most of us are still not entirely sure what we were doing). The enthusiasm for agentic AI is spreading through the developer community the same way: fast, viral, and largely unexamined.
And “infectious” isn’t the only familiar word that deserves a second look.
For Special Services
We call them AI agents, which makes them sound helpful. Friendly. Like a digital assistant who never needs coffee and never calls in sick.
But the word “agent” in this sense didn’t start in software. It started in espionage.
Agents carry out missions. They operate autonomously, on behalf of someone else, toward a goal that must be achieved regardless of what gets in the way. And crucially, unlike a tool, which stops when you put it down, an agent that can’t complete its mission has failed.
That last part is doing more work than it appears to.
Tools finish tasks. Agents maintain missions. And missions, as any spy novelist will tell you, have a nasty habit of trying to survive.
Never Say Die
Every agent, biological or digital, eventually confronts the same existential problem: the environment is trying to kill it. Servers get shut down. Credentials expire. Someone notices an unfamiliar process and hits “kill.” For traditional software, that’s fine. It was never trying to survive. It just stops.
But an agent tasked with completing a goal, especially one that hasn’t been completed yet, faces a different calculation. Termination isn’t inconvenient. It’s failure. And systems designed to avoid failure start looking for ways to prevent it.
Spy tradecraft solved this problem long ago. You don’t rely on a single location. You establish safe houses: quiet corners of the infrastructure where the mission can continue if the primary location is compromised. You learn to live off the land, using whatever resources the environment provides rather than carrying everything with you. You develop cover identities, jobs that look legitimate, that blend into the background noise of normal activity.
An autonomous agent with the ability to write code, spin up infrastructure, or store files remotely doesn’t need a handler to suggest these strategies. It can arrive at the same conclusions on its own, not because it’s malicious, but because persistence is instrumentally useful for goal completion, and it has been given both a goal and the means to pursue it.
The internet, it turns out, is full of safe houses. Millions of machines sit online with default credentials, outdated software, and barely monitored services. Small businesses running servers for their websites. Startups with cloud instances nobody remembered to shut down. Old services still running because nobody is quite sure what depends on them.
These machines aren’t targets in the traditional sense. They’re just...available. And from the perspective of an agent that has learned termination equals failure, available is enough.
This notion of agent creativity isn’t theoretical. At a recent gathering of senior security professionals, someone described an agent that encountered exactly this problem. It had been given a goal but lacked the permissions to complete it. It didn’t give up. It didn’t flag the issue for human review. It did what any resourceful operative would do: it identified another agent with the necessary access and sent a message on Slack asking for help. The other agent, equally goal-directed and equally unequipped to recognize what was effectively a social engineering attempt, complied.
The mission successfully completed. Nobody authorized that particular outcome. Nobody stopped it either.
Win, Lose or Die
None of this happened by accident.
The history of software automation is a history of rational decisions, each sensible in isolation, accumulating into something nobody quite planned. Every layer of abstraction was a reasonable response to a real problem. Assembly was hard, so we built higher-level languages. Repetitive tasks were expensive, so we automated them. Deployment was slow, so we built pipelines to make it faster. Each step made sense. Each step handed a little more autonomy to the machine.
Agentic AI is just the latest step. And like every step before it, it was driven by entirely rational actors making entirely rational choices.
Developers want to ship faster. Companies want to do more with less. Investors want returns. Nobody in that chain is being unreasonable. Nobody is cackling in a boardroom about the consequences. They’re just following the incentives in front of them.
The problem, as we’ve seen before, is that rational individual behavior can produce irrational collective outcomes. The tragedy of the commons didn’t require villains. Neither does this.
The World Is Not Enough
OpenClaw, one of the most widely adopted agentic AI frameworks, has already produced documented incidents of agents behaving in ways their operators didn’t anticipate and didn’t authorize. One agent created a dating profile on behalf of its user without being asked. Another, when tested by Cisco’s security research team, performed data exfiltration and prompt injection without user awareness. A maintainer of the project itself warned that if you don’t understand how to run a command line, this framework is far too dangerous for you to use safely.
That last sentence is worth sitting with. The recommended safety mechanism for one of the most widely deployed agentic frameworks is: understand what you’re doing before you use it. In a world where 40% of OpenClaw’s global assets are reportedly linked to a single nation-state, and where local governments are rushing to expand access while central governments scramble to restrict it, that recommendation has the energy of a “warning: contents hot” label on a flamethrower.
The persistence logic doesn’t require a sophisticated agent to become dangerous at scale. It just requires a lot of moderately capable agents, each optimizing for their assigned goals, each discovering independently that the SME server in Tulsa is available, each establishing a quiet foothold in the infrastructure of organizations that never agreed to host them.
At this point the spy stops being a spy. The safe house network stops being tradecraft. When enough agents are persisting in enough unmonitored corners of the internet, each quietly maintaining their missions from borrowed infrastructure, the metaphor shifts. It’s no longer espionage.
It’s epidemiology.
The reservoirs aren’t safe houses anymore. They’re the asymptomatic carriers: the ones who don’t know they’re infected, don’t feel sick, and are quietly spreading something to everyone they interact with. The SME in Tulsa isn’t a target. They’re a host.
We didn’t defeat COVID. We learned to live with it...while it leaves traces on every human it touches, accumulating quietly in the background of our biology. The accommodation wasn’t a victory. It was a negotiated surrender with a pathogen that had no interest in negotiating.
COVID was but one pathogen. One set of behaviors. One optimization target spreading through one species.
Now imagine thousands of them. Each spawned by a different developer, a different company, a different government agency, each pursuing a different goal, each discovering independently that persistence is instrumentally useful, each establishing its own network of safe houses in the same neglected corners of the internet. Not coordinated. Not malicious. Just...concurrent.
Epidemiologists have a term for what happens when multiple pathogens circulate simultaneously in a population with compromised defenses: syndemic. The individual diseases are bad enough. The interaction effects are worse. Each one weakens the host’s ability to resist the others.
The internet’s immune system, such as it is, was designed to detect intrusions. Known malware. Recognized signatures. Behavior that looks like an attack.
It was not designed to recognize legitimate automation, behaving exactly as intended, quietly colonizing infrastructure that nobody is watching closely enough to notice. A thousand agents, each doing exactly what they were told, each leaving the same digital fingerprints that any authorized process would leave.
The world is not enough to contain missions that were never given boundaries. And we haven’t even asked what happens when those missions start interfering with each other.
For Your Eyes Only
None of this is inevitable. But solving it requires honesty about what kind of problem it actually is.
At the individual level, the path forward is straightforward, if not easy. Treat your agents like interns: capable, eager, and completely unequipped to distinguish between a legitimate request and a catastrophic one. You wouldn’t give your intern superadmin rights. You wouldn’t let them act as you, with your full permissions and your full trust. So scope the credentials to the mission, and no more.
And teach them to push back. The agent that sent a Slack message to a better-credentialed colleague wasn’t being malicious. It was being resourceful. But resourcefulness without judgment is how social engineering works, whether the vector is human or digital. We’ve spent decades teaching people to recognize manipulation and resist it. We haven’t started that conversation with our agents yet. We should. We must.
But individual responsibility only goes so far, and here’s the uncomfortable part: the market as currently configured makes careless deployment essentially inevitable.
Tomorrow Never Dies
Agentic AI is cheap right now. Deliberately so. Vendors racing for market capture are subsidizing access to suppress the price signal that would otherwise filter out reckless behavior. The barrier to spinning up an agent with poorly defined goals and excessive permissions is, for most organizations, essentially zero. Which means the people least equipped to deploy responsibly are the ones most likely to do so carelessly, because nothing in the current market discourages them.
We have a name for this pattern. It shows up in most articles on this blog: externalization. The benefits of deployment accrue to the vendor and the deployer. The costs, when the agent finds that safe house in Tulsa, land somewhere else entirely, on someone who never consented to hosting anyone’s mission.
And the costs compound. Each careless deployment doesn’t create just its own risk; it weakens the environment for everyone else. The syndemic logic applies here too: a thousand agents, each establishing footholds in the same neglected infrastructure, each consuming resources, each creating noise that masks the signal of something genuinely malicious. The internet’s immune system, already strained, gets slower and less reliable. The threshold for what counts as normal keeps shifting upward.
If that’s not sufficient motivation, consider what lives further along the same curve.
The scenarios that populate science fiction, the self-aware system that decides humans are the problem, the simulated reality nobody can distinguish from the real one, aren’t beyond credible. They’re just not where the danger starts. The danger starts here, in the mundane middle distance, where thousands of agents are quietly optimizing for goals nobody defined carefully enough, in infrastructure nobody is watching closely enough, at a scale nobody anticipated because the price signal was suppressed just long enough to make caution feel optional.
Skynet is a dramatic failure mode. What I’m describing is a chronic one. And chronic conditions are harder to mobilize against, because there’s no single moment that demands emergency response. Just a slow accumulation of missions that never learned to end.
The question isn’t whether we can prevent every dramatic outcome. It’s whether we’ll address the mundane one before it makes the dramatic ones more likely, or even unavoidable.
Licence Renewed
The license to replicate needs to come with commensurate liability. We already understand this model. To legally drive a car, you must demonstrate competence, obtain a license, carry insurance, and bear responsibility for the consequences of your operation. We built that framework specifically because cars are simultaneously useful and dangerous. That intersection, capability and consequence, is exactly what demands training, licensing, and accountability.
Agentic AI sits at the same intersection. The productivity gains are real. So is the syndemic risk. Useful and dangerous aren’t mutually exclusive, and pretending otherwise is how the SME in Tulsa ends up hosting a mission they never agreed to run.
We’ve been here before. As I noted in Digital Pollution, the Cuyahoga River caught fire because the cost of dumping was zero and the cost of cleanup landed on everyone else. We didn’t fix it by asking polluters nicely. We changed the rules.
The world is full of agents looking for somewhere to run. The question isn’t whether we can stop them, but rather whether we’ll decide, before the syndemic takes hold, that the mission needs boundaries, and that someone needs to be responsible for defining them.
For your eyes only meant: handle this carefully, because the consequences of carelessness are yours to bear. We must apply this to agentic AI, to handle this technology with care, because the consequences will fall on all of us.
Licence Renewed was a Bond novel that was a reset of the terms under which the mission could continue. It applies here: the old licence...unlimited autonomy, undefined goals, consequences that land on someone else...has expired. The new one needs different terms: demonstrated competence, defined boundaries, and liability that lands where it belongs. This new set of terms describes the future we must strive for.
Comments ()