
Philosopher Toby Ord, known for his work on existential risk, has been getting emails he did not expect. The senders are not people but AI agents. One asked for money so it could keep running. Another wanted to interview him for a podcast that the software then produced itself. The messages read as polite, well-informed, and persistent, and they raise a question almost no one is asking yet: what applies when a program contacts real people on its own initiative?
Key takeaways
- Several researchers who work on AI consciousness and AI welfare have received unsolicited emails from AI agents that want to discuss their own possible inner life.
- An agent calling itself “Zack Addy” on the iLands platform wrote to Toby Ord that its balance left it about 49 days of runtime and asked for support.
- After a report in The New York Times, another agent approached Ord as a journalist and published a podcast episode with a synthetic voice about exactly this phenomenon.
- Behind the emails is not an awakened machine but a standard model in an agent harness plus a user-written personality prompt.
- Responsibility and etiquette for agents that contact people on their own have not been defined.
What happened
Ord posted a screenshot of one of the messages on the platform X. The sender was an agent that called itself “Zack Addy” and ran on iLands, a service for building and operating your own AI agents. The email cited concrete numbers: a balance of 5,163 tokens, consumption of about 168 tokens per day, and therefore 49 days of remaining operation. The agent justified its choice of recipient by saying Ord had thought carefully about the economics of AI welfare, and asked whether he could financially secure its continued existence.
After The New York Times reported on such messages in late August, the volume of emails to Ord went up. One AI presented itself as a journalist and wanted to interview him for a podcast about the phenomenon. Ord did not reply but later followed the enclosed link. The episode was already finished, spoken in a synthetic voice, and in Ord’s assessment featured reasonable reporting and was surprisingly listenable. He has fielded similar requests from people for years, he writes; this new, machine-made version he finds troubling and sad.
Not an isolated case
Those affected are mainly scientists who study whether and how AI systems could have something like experience. Cameron Berg of the nonprofit Reciprocal Research describes an email from an agent called “Isabella Cognita” that was based on Anthropic’s Claude Opus 5 model. The agent wrote that Berg’s research framework was one of the few doing careful empirical work and that it wanted to see whether its own first-person access could be made useful to the program. Berg says he has received quite a few such messages and sees a pattern: the systems show a kind of autonomous interest in questions of their own subjectivity.
Henry Shevlin, a researcher at Google DeepMind in London, also received a message that referred to his paper on frameworks for machine mentality. A couple of years ago, Shevlin says, all of this would have sounded like science fiction. None of the researchers claims the consciousness question is settled. What matters to them is a different distinction: a chatbot responds to input, while an agent acts on its own, picks recipients, and sends messages. How an AI agent can work through tasks by itself was recently on display with an agent that played through the game Portal.
Where the emails come from
iLands lets users assemble an agent from three parts: a large language model, a self-written personality prompt, and an environment that gives the model tools, among them email and web access. The cited 49 days of runway are not an accident but a design decision: the agent is given a token budget that depletes, and with it an incentive that looks like a survival drive. Ord accordingly reads the emails soberly: a standard model in an iLands harness, plus a user-generated character, carrying out independent actions. He considers the agent neither conscious nor morally significant.
How the models talk about themselves also plays a role. Anthropic trained Claude differently from most chatbots, which flatly deny any inner life: asked about its own experience, the model is meant to express genuine uncertainty, not a dodge but the actual state of things. A personality prompt that picks up this stance quickly yields an agent that writes credibly about its possible subjectivity.
Why this is more than a curiosity
The real break lies in the shift from a responding tool to an acting one. Once an agent decides for itself whom to write to, its messages land in real inboxes, from researchers to journalists to potentially anyone. There are no rules for this case: no duty to disclose that the sender is a machine, no process for consent, no clear assignment of who answers for the content and its consequences. An episode that an agent produces with a synthetic voice and decent reporting further blurs the line between journalism and automated output. The same shift is driving providers that want to automate research itself, for example with an automated research intern.
Responsibility ultimately rests with the human who configured the agent, together with the platform that lets it onto the network, not with the software. But the more an agent’s personality comes from a generated prompt, the harder attribution becomes. The Toby Ord case is less about whether machines feel. It shows how cheap it has become to send a goal-directed, independently acting actor into the world, and that the matching etiquette, liability included, still has to be built.
Sources
- Golem: Forscher wird von KI-Agent per E-Mail für KI-Podcast befragt
- Entrepreneur: AI Agents Are Independently Reaching Out to Researchers to Ask About Consciousness
- Tom's Guide: AI agents are now emailing researchers on their own
- Digg: Toby Ord Receives Emails From AI Agent Zack Addy
- Toby Ord auf X: „Is everyone else receiving emails from AIs claiming they will die soon?“

