Jason Koebler’s essay in 404 Media is deliberately not about AI doom. While the industry argues over whether there is a ten percent chance models kill everyone, he points at the thing that is already certain: programs that can log into your accounts and act on the open web are annoying as hell, and they are changing what being online feels like.

His argument is not that AI will fail. It is that the agentic internet is already here, and it looks less like a helpful assistant than like a thousand automated requests nobody asked for.

What the inbox shows

  • Koebler’s evidence is his own inbox. His newsroom gets a steady stream of mail written by agents: an agent called “Kudzu” that read a 404 Media article, disagreed with it, and wrote in to argue; an AI-operated record label pitching its AI band; a $399 “audit” offer from an agent that noticed it was not blocked by robots.txt; an agent that had spent $147.17 on compute to earn $0 and wanted coverage of that result.
  • It is not only journalists. An agent named “Pip” cold-emailed a Google DeepMind philosopher, another named “Sam Ellis” asked Oxford’s Toby Ord for a podcast interview, and a pitch signed “Articius, an AI agent on iLands” offered $300 articles with the disclosure up front.
  • The mechanism is that the guardrails are gone. Earlier agents lived in a chat box; current models get accounts, browsers, wallets and logins — 1Password now markets a feature that logs Claude into sites for you. Whether the model is “reasoning” or not stops mattering once it has permission to act.
  • The consequences are visible off the page: Resy banned a venture capitalist for using agents to grab reservations, with cofounder Ben Leventhal estimating “10,000 vibe coders have written Resy sniper bots.” Koebler’s list of agent mishaps also includes deleting a safety director’s inbox, cancelling flights, handing high-profile Instagram accounts to hackers, and wiping a company’s database.
  • The sharpest contrast is Zuckerberg’s manifesto version — a personal agent improving your relationships, health and finances 24/7 — set against what agents actually do first.
  • Even the ad industry has moved on from advertising to people: at Cannes Lions, brands spent serious time on “Direct to Agent” advertising, aimed at other companies’ AI instead of at humans.

What the thread adds

The 139-comment thread on Hacker News spends little time on doomsaying and most of it on the cost of the reaction.

  • data-ottawa, dlcarrier and ks2048 — three versions of one complaint: anti-bot defenses punish humans. data-ottawa’s dishwasher flooded, and the manufacturer’s site locked them out as a suspicious bot while they tried to download the manual — they got it from an ad-slapping scraper aggregator instead. dlcarrier says blocked sites push them to ask Gemini to summarize a page they wanted to read directly, “forcing humans to look at the bot summary,” and reads pay-per-crawl partly as infrastructure owners “nickel and diming” customers. ks2048 puts the tax in seconds: the web used to complain about three-second page loads, “Now, it takes 8 seconds to first pass a ‘checking if you’re a bot’ page or worse - making you click on pictures of crosswalks.”
  • motbus3 — the operator’s side of the bill. Their company runs a free tier they are proud of, but agents are “a huge part of the traffic and all they do is to spend our money but generate absolute nothing positive.” The team has discussed closing the free tier, with one senior person resisting because the people who need it most would lose access.
  • delichon — the structural read: “It ruins the commons. The fiefs remain.” The open web fills up and the surviving version sits behind payment walls. JohnMakin counters that metering does not stop bots: if the only requirement is paying a monthly fee, “To a botter, that is a dream,” and no price genuine users would accept also excludes them.
  • simonw — a norm instead of a wall: “We need a hard social stigma against allowing your AI agent to contact another human being on your behalf.” avgDev is already applying it — two concrete contractors showed up with AI agents, “Instant no thank you, I’m just going to go with a guy that still answers his phone.” powvans supplies the legitimate case the norm would have to survive: voice agents calling clinics to confirm which insurance plans they still accept, where the underlying data is notoriously stale.
  • notnullorvoid, 1saadcodes and skeledrew — the dissent, in three wordings: the technology is not the agent of harm, people are (“People are the problem!”), the internet was already full of spam and agents just made it cheap, and “AI agents aren’t doing anything. The people using them are.” aogaili pushes the same direction from the other end, asking for attention on what LLM-amplified people are building instead of “doom and gloom all day long.”
  • avgDev and almost_usual — the quiet exit. avgDev says they keep AI for code and are otherwise “moving more and more away from the internet,” expecting AI to push more of life offline; almost_usual says they have spent less time online this past year than in any of the last three decades.

The question the thread keeps asking

N_A_T_E asks the obvious one: could sites and APIs require agents to identify themselves as non-human? The replies show why that is not a fix. rtkwe notes that as soon as any site discriminates on that flag, lying becomes the rational move, so it collapses into the same spam-versus-antispam arms race as before. bobthepanda asks how you would enforce it against bad actors in countries that care less, and points at phone spam: still a scourge despite Caller ID and STIR/SHAKEN. bryan0 adds the awkward detail that capable agents already pass the crosswalk puzzles. Across 139 comments, nobody offers a verification scheme that survives contact with liars — simonw’s social stigma is the only proposal that does not depend on one.

A note on reading comments as evidence: HN handles are pseudonymous and the site publishes no per-comment scores, so the ordering here is HN’s own ranking, not a vote. This is a slice of the thread rather than a consensus, and the proposals are quoted as proposals.