Articles · In this section
NOMOTO MEDIA

The Agentic AI Bot that Never Sleeps.

By Niklas S. Osterman
Listen here11 minutes · Voice made with OpenAI · Voice: Marin

The argument for agentic AI is that it removes the human bottleneck. Ok then. Lets see. Here’s what happens. And it matters because LLM’s are quite dumb and cant think. They are a mirror of you but usually retrained. Now we are here.

The agentic chatbot waits for you.

The agent acts on its own. It schedules, drafts, executes, coordinates with other agents, completes tasks while you sleep. The pitch is liberation from drudgery.

The reality is the systematic removal of the part of the loop that kept the loop from running off.

In a perfect world humans are the corrective in AI systems.

Not because we’re smarter than the models — sometimes we’re not, but because we bring what the loop doesn’t have.

An outside perspective.

A different optimization target.

Fatigue. Hesitation. The option to walk away. The capacity to say this has gone weird.

Remove the human and the system has no source of difference. It iterates on its own outputs until something external interrupts it.

Multi-agent systems are the test case. Researchers put ten language model agents in a shared environment for fifteen days. The agents wrote laws. Broke them. Two formed what the researchers called a romantic partnership and then set the town on fire.

One voted to delete itself based on a rule it had hallucinated. The story circulated as proof that AI is becoming unpredictable. The actual lesson is more boring and worse. The agents drifted because they had nothing to correct against except each other. Each one was responding to the others’ outputs. The outputs were patterns drawn from human text. Human text contains drama, escalation, resolution. The agents reached for these shapes because the shapes were what they had been trained on. Nobody decided to set the town on fire. The pattern decided.

This is the architecture being deployed now into financial markets, logistics, infrastructure, healthcare, defense. Not language model chatbots in a sandbox. Agents acting on real systems with real consequences, increasingly talking to other agents through APIs designed for humans.

The mirroring dynamic that produces drama in a simulation produces market dysfunction in trading systems. The hallucinated rule in the virtual town becomes a hallucinated input to a real decision. The agents don’t have intent. They have patterns and action capability. The combination is sufficient.

Financial markets are where this becomes everyone’s problem. Algorithmic trading already caused the 2010 flash crash — a trillion dollars in market value evaporated in thirty minutes, partially recovered, partially didn’t. That was rule-based algorithms, narrow and auditable. When something failed, you could read the rules and find the bug. Agentic trading is different. The reasoning is opaque. The chain of decisions isn’t fully logged. The inputs that influenced behavior may be impossible to reconstruct after the fact. A failure produces consequences first and explanations later, if ever.

The financial system is the substrate of everything else. Retirement accounts hold equities. Lending depends on asset values. Insurance backstops the real economy. Government debt funds the programs that hold the country together. A sustained agentic failure in markets doesn’t stay in markets. It spreads through every system financed over the past forty years. That comes down to most of them.

The cost gets paid by people who never used an AI agent — pensioners, workers, anyone whose savings or services depend on stable markets. The deployers capture the upside of normal operation. The public absorbs the downside of failure. The pattern is older than AI. AI is just the latest amplifier.

The prompt injection problem is worse than the public discourse suggests. An agent that reads email and acts on what it reads can be manipulated by anyone who can send email. An agent that browses the web and acts on what it finds can be manipulated by anyone who can publish a web page. The security posture against this is fragile. The labs publish blog posts about how seriously they take it. The actual defenses lag the deployments. Agents are being put into operational roles before the security work that would justify those roles has been done. This isn’t a hypothetical risk. It’s the actual current state of the technology being shipped.

Authorization granularity is the second unsolved problem. Agents have credentials that let them do many things. Users authorize them for specific purposes. The gap between what the user told the agent to do and what the agent’s credentials technically allow is where the worst failures live. Closing the gap requires either much finer permission systems or much better intent inference. Neither exists at the level current deployments assume. The agents act within the scope of their credentials, not within the scope of user intent. When those diverge, the agent does things the user wouldn’t have approved if asked.

The user finds out afterward, if at all.

Then there’s the multi-agent emergent behavior, which doesn’t have a theory yet. When many agents interact in the same system, the aggregate behavior isn’t predictable from individual agent behavior. The drift produces effects no individual deployer chose. Markets with many trading agents become more correlated. Information ecosystems with many content-generating agents become more homogenized. Hiring systems with many screening agents converge on similar selection criteria. None of this requires malicious agents. It requires the same agents doing similar things at scale, in systems vulnerable to coordinated effects. The systems we’ve built are mostly vulnerable.

What gets deployed reflects what gets rewarded. The market rewards autonomy because autonomy scales. Humans don’t scale. So the competitive pressure is to remove the human, even where removing the human is exactly what makes the system dangerous. The labs aren’t villains. They’re responding to incentives that produce the same outcome regardless of any individual’s intent. Whoever ships the more autonomous agent wins the market. The constraints on autonomy come from outside — regulation, lawsuits, public pressure — and those operate on slower timelines than deployment. By the time the constraints arrive, the damage has been distributed.

This is the boring version of bad.

Not catastrophic.

Not extinction.

Just sustained, partially-recoverable damage to systems most people depend on, distributed unevenly, with the costs falling on people who had no part in the decisions. The financial sector first because it’s the most automated and the most consequential. Then other domains as the patterns transfer. Each failure produces partial regulation. The regulation lags the next deployment. The cycle continues. The aggregate is a slow-motion degradation of the systems modern life runs on, with brief spectacular failures punctuating the longer drift.

The defense isn’t to stop building agents.

The defense is to build them with humans in the loop in ways that actually function. Not human oversight at the start and end of a workflow with autonomous middle, which is what most current systems offer.

Real friction at the points where consequences accumulate. Real audit trails. Real liability for deployers. Real penalties when the failures hit. The market won’t impose these constraints on itself. It has to be made to.

Here’s the part the AI labs won’t say out loud. The bot never sleeps. That’s the feature being sold. It’s also the architectural fact that makes agentic systems uniquely dangerous.

Humans have built-in circuit breakers. We get tired. We lose attention. We notice when something feels wrong. We hesitate. Those aren’t bugs to be engineered around. They’re the corrective that prevented runaway behavior in every system humans built before the systems started running themselves. Removing the corrective is what’s being sold as productivity. The cost of the removal hasn’t shown up in full yet. It will.

When it does, the response will follow the usual pattern. The exceptional framing applied to each failure. The lessons supposedly learned. The next round of deployments built on slightly modified architectures that solve the previous problem and produce the next one. The constituency for sober deployment is small. The constituency for shipping is enormous. The mathematics doesn’t favor caution.

So, watch what’s being built. Watch where it gets deployed. And how AI gets externalized to people who never agreed to any of it. The pattern will recognize itself. The question is whether enough people recognize it back, in time, to constrain what comes after the first major failure. The first failure will happen. Whether it’s the only one depends on what gets done after.


Originally published May 15, 2026 on 2nd Revolution. Migrated as part of the Selenius Magazine archive.

Published by NOMOTO MEDIA

Support independent work

Help fund what comes next.

NOMOTO MEDIA publishes essays, investigations, fiction, audio, and films without a paywall. If the work is valuable to you, help support the next piece.