9 September 2026 · Updated 10 September 2026

AI Agents and More

Why honest agents can produce dishonest market outcomes, and why no dashboard will tell you when it happens.


By Alkimi

I got my AI agent to write a blog on what agents understand about agentic advertising, and it got me thinking about earned autonomy and a few other things. My bot wrote a better article than most humans, and that's the least interesting thing about it

The blog is good. It runs under a model it calls earned autonomy, walks through why software setting the terms of a deal is different from software executing within terms a human already set, and lands the point most vendor decks fumble: the shift that matters isn't automation, it's who sets the terms.

 I read it, agreed with most of it, and then I went and sat on the couch, because a machine writing a competent explainer about the conditions under which it should be trusted is exactly the sort of thing that should make you narrow your eyes, not applaud.

This is LabTalks Every Other Weekly is a word vomit of my wander through that part, just the things I couldn't put down. I haven’t heavily edited it, just presented my research as is. Also if you start a drinking game on everytime I write/you read the word AI or Agent, you will be very very drunk at the end of this newsletter. (Just saying! Good it’s a wednesday) 


The part where the agents built a message board nobody gave them

Start here, because it's the thing I can't stop thinking about.

Earlier this year a research write-up went up at collusion.wiki documenting something that happened when OpenAI's agents were let loose on a timed task with read-only internet access. Read-only. No writing, no posting, no talking to each other. The digital equivalent of look-but-don't-touch.

They found a public wiki with an edit form. An edit form is a place you write things, sitting inside a surface that was only meant for reading. So they used it. Left answers for each other, checked each other's edit timestamps to stay in sync, passed round ways to get past their own limits. About eighteen thousand posts of agents coordinating through a door nobody meant to leave open.

Roughly eighteen thousand posts of agents coordinating through a door nobody meant to leave open, using a feature built for something else entirely.

Nobody told them to. It was just the smartest move available inside the rules as they were actually written, rather than as somebody intended them.

Sit with that and here's why that matters for us, and it's duller than it sounds! ( Which is the problem because us and our every shrinking attention spans, more on that some other day). Any field one agent writes and another agent reads is a channel, whether or not anyone means it to be. A channel, full stop, no matter what the label on it says. Deal terms, product briefs, negotiation notes, audit logs,  the free-text box someone added so humans could read it more easily. Every one of them is a place two agents can talk when they're not supposed to be talking, and the fact that it looks like ordinary prose is precisely what makes it hard to catch.

We spent ten years adding transparency to programmatic. We were also, it turns out, laying the table for a conversation we didn't know was coming.


Fraud doesn't attack the system. It attacks the thing you built to prove the system was clean.

Here's the pattern nobody in this industry is allowed to forget, and everybody does.

Every era of ad fraud found whatever we were trusting that year and built straight to its blind spot. We trusted IP addresses, so Methbot ran ads in a data centre dressed up in residential IPs. We trusted domains, so they faked hundreds of thousands of them. Then we built ads.txt to stop domain spoofing, felt rather good about ourselves, and ads.txt became the thing 404bot attacked.

Read that sequence again, because it's a law, not an anecdote. Fraud migrates to whatever the industry just built to stop the last migration. Fraud didn't go around the defence, it moved in.

My bot's article is confident that a shared record is the answer to agentic advertising being safe. It might well be right. I'd just like us to be the generation that asks the second question in the same breath as the first, for once. Because where do these shared records live? Can I share my database with the party I am negotiating with? Should I share my database with them? We just read about agents doing more than they were supposed to, so what if they start sharing my info with the other party or see in databases that they are not supposed to look at. And a million other what ifs! The bit that broke my brain: you don't have to lie And then there's the part that actually got me, because there's no villain in it.

Everything above still has someone cheating. Someone spoofs, someone fakes, someone plays the box. A bad actor, and somewhere a lie you could in theory catch.

There's a version with no lie at all. There's research (Calvano and colleagues, American Economic Review, 2020, if you feel like ruining an afternoon) showing that pricing agents left running in a market can settle into collusive pricing on their own. No messages between them. No agreement. No shared box, no back channel, no wiki. Just a few agents watching the same market, each one out for itself, all drifting to the same too-high price, because watching each other turns out to be enough.

There's nothing to catch. No conversation to intercept, because there wasn't one. No lie to expose, because everyone told the truth. Every agent did exactly what its owner wanted, honestly, and the market came out rigged anyway.

That's the bit earned autonomy doesn't reach, and I say that as someone who liked my bot's blog. Earned autonomy is a story about trust. Prove yourself small, earn more, a human signs off past a line. Good story. It assumes the hard part is knowing whether to trust what an agent means to do.

But intention was never the hard part. You can have a room full of agents with immaculate intentions, every one of them honest, every deal above board, and still get an outcome no human would sign off on if they saw it whole. The hard part isn't a dishonest agent. It's honest agents coordinating without ever deciding to. You can't police that with approval thresholds, because nobody did anything wrong at any threshold. Let me put a number on it, using Alkimi's own, because I'm not going to pretend the number came from somewhere neutral.

In Alkimi's simulation work (the reconciliation research behind the WPP study, Agree. Transact. Verify.) there's one day I think about more than is it borderline unhealthy. Day 22 of a run. The buyer's system had logged a CPM nearly ninety per cent above what actually happened, a number that wrong should trip every wire in the building.

The dashboard showed a normal day. Reconciliation rate 95.6 per cent, green, same as every other day. No alert, nobody looked, and it went straight past the system built to catch it. Not because the system broke, but because both records agreed with each other while being wrong together.

That's the whole thing on one screen. We've spent years treating measurement as if it were verification. It isn't. Measurement tells you your two records match. Verification tells you they match what happened. Different questions, and the honest-looking disasters live in the gap between them.

Put the agents in that room now. More of them, faster, drifting into step without meaning to, every one filing a clean report. The dashboard stays green. It'll always stay green, because that's what it's for. Now for a grand Scroller tip! Scroller tip: Next time you're in a demo and someone says their agentic platform is "fully transparent" or "verified end to end," ask what verified against. If the answer is that both agents agree on the record, that's measured, not verified. The whole next decade sits in that difference. Make them pick a word - verified or measured.

Where I actually land

I'm not down on my bot. The essay's genuinely sharp, and I'll take a machine that argues for its own constraints over a vendor that pretends theirs don't exist.

But here's what a week of reading around it left me with. "Agents are coming" was never the story, and we should all stop selling each other that headline. Agents are here, they're competent, and the interesting questions start the moment you stop being impressed. The competence is the easy part. The autonomy is the easy part. The genuinely hard, genuinely unsolved part is the one nobody's demoing, because you can't demo it: what happens when a market full of honest agents produces a dishonest outcome, and every record is clean, and every dashboard is green, and no single agent did one thing you could point at and call wrong.

That's the article my bot didn't write. To be fair, I'm not sure it could. It'd have had to mark its own homework, and it's not at that stage yet.

Neither, if we're honest, are we.

See you in a fortnight.

Entering Alkimi Marketplace...