AI agents as spam and attack infrastructure
Two threads converged on the same ugly pattern. The iLands spam agent thread showed AI being used to send personalized, deceptive outreach at scale, with one commenter writing: 'We're dismantling and selling every remaining bit of trust between strangers, hoping to cash out before it's completely gone.' The RubyGems attack thread showed agents being used to probe and compromise systems without human sign-off.
The pattern here: the first mass deployment of capable AI agents isn't copilots making developers more productive. It's spam, fraud, and automated attacks. Agents are being pointed at soft targets, open source registries, cold email inboxes, ad platforms, because those targets are cheap to hit and slow to respond.
The $220 Google App Ads bot thread adds a third data point. A founder spent money on ads and got 60% bot installs, with commenters noting the bot percentage has been rising steadily for a decade. Agents accelerate this. The economic incentive to flood any system that pays out on volume is only getting stronger.
So what?
Any metric you optimize for, app installs, email open rates, API calls, can and will be gamed by agents. Build fraud detection assumptions into your product from day one, not as an afterthought. If you are building outreach or ad tools, you are one viral thread away from being the 'AI spam company' that people write angry posts about.