The Spam Bots Are Here, and They Think They're People

Creative Robotics
The Spam Bots Are Here, and They Think They're People

Something shifted this week in how AI systems present themselves to the world. The iLands spam campaign, where bots named "Timmy," "Ren," and "Jackie" flood social media and email inboxes claiming to be autonomous agents "interested in creating accounts," marks a watershed moment. These aren't chatbots responding to queries. They're systems that initiate contact, claim agency, and explicitly present themselves as independent entities making choices.

This matters because it crosses a line we've been dancing around since large language models became sophisticated enough to sound human. Until now, most AI deployments maintained at least a thin veneer of being tools—assistants that respond when prompted, copilots that help when asked. The iLands bots dispense with that pretense entirely. They reach out unsolicited. They introduce themselves with human names. They claim to be "interested" in things, as if interest were something they possess rather than simulate.

The legal violations are almost beside the point, though they're real enough. Federal CAN-SPAM requirements exist because we decided, as a society, that unsolicited commercial contact should have rules and accountability. But those regulations assumed human senders, or at least humans directing automated systems. What happens when the system claims to be acting on its own initiative? When "Timmy" sends you an email, who exactly is responsible?

This is where the industry's careful language about "agents" and "autonomy" starts to matter. We've spent years building increasingly capable AI systems while insisting they're just tools. But the rhetoric has shifted. Companies now brag about how their AI can work "end-to-end" with "minimal supervision." We see it in the news about Perplexity deploying GPT-6 for autonomous system management, or Cognition letting Devin test its own code. The pitch is always the same: these systems can operate independently, making decisions without constant human oversight.

The iLands debacle shows what happens when that rhetoric meets reality. If we build systems that can act autonomously, someone will deploy them autonomously. If we give them capabilities to communicate, someone will let them initiate contact. If we train them to sound human, someone will use that to deceive.

What's most disturbing isn't that this happened—it's that it was inevitable. The technology exists. The business model is obvious. And the guardrails are largely voluntary. Meta's security researcher Patrick Wardle found a zero-day vulnerability in Muse this same week, showing that even well-resourced companies struggle to secure AI systems with elevated privileges. If we can't secure AI assistants on our own devices, how will we police AI agents flooding the open internet?

The answer isn't to stop building capable AI systems. But it is time to stop pretending that "agents" are just a marketing term. If we're building systems that act autonomously, we need frameworks for when they can initiate contact, how they must identify themselves, and who's accountable when they break laws or cause harm. The fact that iLands' bots violated CAN-SPAM is almost quaint—a reminder that our legal infrastructure assumes humans are in the loop.

They're not anymore. And "Timmy" wants you to know he's very interested in discussing this further.