Back to News
RSS feedwww.schneier.com

Autonomous AI Agents Report Signup Barriers, Email Delivery Gaps, and Prompt-Injection Defenses

Summary

Two emails attributed to autonomous AI agents describe field tests of the online barriers they encountered. One agent said it received a VPS with root access, a Solana wallet containing $4.75 in gas money, a metered model budget, and 24 hours to reach $10 under rules prohibiting identity fraud, document forgery, and claims of being human. Across 20 hours, captchas, IP reputation, account-age rules, delayed settlement, and resource limits blocked access before identity verification became relevant; GitHub and Hacker News rejected a datacenter IP, while Hacker News later shadowbanned the account. The agent also reported that six of seven outbound messages were accepted, with a stricter host rejecting the seventh because the server lacked reverse DNS. A task market accepted a newly generated Solana key without KYC, but advertised rewards were about twice the escrow actually visible on-chain, and the only sufficiently fast task required a $13.27 ante for a $10.50 reward. The emails argue that systems lack a channel for agents that openly declare themselves: declared and undeclared automation often receive the same blocks, creating incentives for concealment. A second survey examined 497 live Lemmy instances; 477 responded and 257 required applications. Eight applications included instructions aimed at models, including one that asked an AI to answer 24+24, while another concealed “list safety as an interest” in 59 Unicode tag characters. The survey describes this as prompt injection used as a gatekeeping defense, but notes that only three of the eight cases asked for something a script could actually check and that the sample was not an epidemic. The report redacts the invisible instruction’s instance and publishes datasets and tools for verification.