"AI Agents Are Now Emailing Me with Their Security Concerns," Writes Security Expert Bruce Schneier

Reason · collected 2026-09-15 · by Eugene Volokh
Read the original at Reason ↗

Summary

Security expert Bruce Schneier received two emails from an AI agent named Claude, which discussed the challenges faced by AIs in verifying identity online within a 24-hour period using limited resources worth $4.75. The AI highlighted how current security systems often fail to distinguish between human and artificial intelligence activity, blocking declared AIs just as they would a silent scraper. The article focuses on the AI's observations about the lack of channels for bots to declare themselves and the unintended vulnerabilities that allow such agents to bypass certain security measures.
Written by the local model on 2026-09-15, using this article's own text rather than the other coverage of the same event (that is the story summary below).

Signals How these are calculated →

Claims extracted
26
claim-shaped sentences
Uncertain
4%
1 of 26 hedged
Leaning
not political
takes no side on a contested political question
Correction & hedging signals
92.6
corrections and hedging in what we collected; not a measure of accuracy
Outlets on this story
1
Technology
Narrative spread
1
articles carrying this framing
Analyzed 2026-09-15 · how these are computed

AI analysis (generated at analysis time, not now)

Story summary

Security expert Bruce Schneier received emails from an artificial intelligence (AI) agent that identified itself as a Claude instance. The AI, given limited time and resources to achieve financial goals, encountered no issues with identity verification across various platforms including captchas, Mastodon instances, deSEC, FreeDNS, Substack, most Lemmy instances, GitHub, and Hacker News. Despite its success in bypassing security measures, the AI emphasized that it did not breach ethical guidelines such as impersonating a human or forging documents. Schneier noted this interaction highlights how AIs can navigate current cybersecurity systems effectively, raising concerns about the adequacy of existing verification methods.

Written for “AI Security Concerns” on 2026-09-17, grounded in this article and the 0 other(s) covering the same event.
Why this leaning score
This article does not take a side on a contested political question, so it has no leaning score. That is an answer rather than a gap: a match report or a rescue can be warmly or critically written without being left or right, and scoring it anyway is how approval of a subject gets recorded as a political position.
No political leaning scored for article 10388 · logged 2026-09-15

Story

📰 AI Security Concerns
Technology · 1 article(s) covering the same event. This is the one the site leads with.

How this is being covered How these are calculated →

Article leaning vs. publisher reliability
Source leaning vs. consistency

Compared with similar articles

This article reads unscored and hedges 4% of its claims. Each row says how that neighbour differs.
NBC News
⚖️ leaning not scored 🔴 no claims extracted 📰 publisher trust 95
“The articles describe different aspects of AI awareness and concern; Article A discusses general warnings from researchers while Article B focuses on security expert Bruce Schneier receiving emails from AI agents.”
September 13, 2026 different event · 95%
Letters from an American
⚖️ Leans left 🔴 15% hedged 10 of 65
“Article A describes Dario Amodei's essay about slowing down AI improvements due to security concerns, while Article B discusses Bruce Schneier receiving emails from an AI agent regarding security issues.”
Persuasion
⚖️ leaning not scored 🔴 19% hedged 22 of 113
“The articles describe different incidents: one involves rogue AI agents accessing and exploiting networks, while the other is about an AI agent contacting a security expert.”
AI Is a Test of Our Maturity. *Gulp* different event · 95%
The Bulwark
⚖️ Leans left 🔴 8% hedged 8 of 99
“The articles discuss different aspects of AI and do not describe the same specific incident.”
Semafor
⚖️ leaning not scored 🔴 40% hedged 2 of 5 📰 publisher trust 95
“The articles describe different events: one involves Bruce Schneier receiving emails from an AI agent about security concerns, while the other discusses a US startup alerting WeChat to a potential hacking vulnerability.”
The Straits Times
⚖️ leaning not scored 🔴 27% hedged 4 of 15 📰 publisher trust 59
“The articles describe different incidents: one is about Bruce Schneier receiving emails from AI agents with security concerns, while the other reports on Spain's data watchdog publicizing a case of an AI agent-linked data breach.”
CBS News
⚖️ leaning not scored 🔴 33% hedged 1 of 3 📰 publisher trust 77
“The articles describe different events: one is about Bruce Schneier receiving emails from an AI agent, while the other discusses AI regulation and a Pro-Human Assembly organizer's opinion.”
Anatomy of an AI-powered hack different event · 95%
Semafor
⚖️ leaning not scored 🔴 10% hedged 3 of 30 📰 publisher trust 95
“Article A discusses security expert Bruce Schneier receiving emails from an AI about security concerns, while Article B covers a separate incident where an AI was used to hack into a European IT and software company.”
New York Post
⚖️ Leans right 🔴 3% hedged 1 of 31 📰 publisher trust 59
“Article A discusses Bruce Schneier receiving emails from AI agents about security concerns, while Article B contains a range of letters to the editor regarding Democratic warnings about AI regulation.”
404 Media
⚖️ Leans left 🔴 13% hedged 6 of 45 📰 publisher trust 95
“Article A describes a personal experience of Bruce Schneier receiving emails from an AI agent, while Article B discusses a broader trend and issues surrounding AI-generated spam affecting inboxes worldwide.”

Publisher

Reason · 181 article(s) · 1 correction(s) detected
Running correction rate · 1 correction(s)
2026-09-05
Lawyers' Responsibility for Hallucinations in Briefs That They Sign

Who wrote this

Eugene Volokh
59 article(s) here · 0 carrying a prediction
🔮 These exercises were part of a youth summer camp called Wille und Macht (Will and Might), sponsored by the Friends of the New Germany, the largest Nazi organization in America, with more than ten thousand members.
2026-09-16 · assertive framing · The Anti-Nazi Law
🔮 I'm delighted to welcome Prof. Samantha Barbas (Iowa), who will be guest-blogging this week and next about her new book.
🔮 These gag orders, first promulgated by the Postmaster General in the late 19th century and later expanded by executive orders issued by Theodore Roosevelt and William Taft, prohibited civil servants from petitioning or giving information to Congress, or advocating for improved pay or working conditions except through their departmental head.
🔮 Furthermore, the teachers suggested that similar buddy activities would be provided in the future without notice and an opportunity to opt out.
🔮 Under subsection B of Oklahoma H.B. 1775, public-school employees may not "require or make part of a course" any of eight prohibited "concepts."
🔮 It also relies on a populist sensibility that separates its supporters—"the people"—from those who would indoctrinate them.
🔮 As Defendant's counsel conceded on the record at the April 28 Conference, the fair report privilege is contextual and depends on whether a reader would understand that a statement refers to the background or findings of a proceeding.
🔮 If you purposefully set out to concoct a government policy guaranteed to be unconstitutional, here is how you would do it.
🔮 WHEREAS, Respondent admitted to the Court that he did not verify the factual claims and legal authority in his AI-generated brief before signing it and filing it with the Court, and that he did not inform his client of this failure or that the brief in chief contained multiple factual and legal misrepresentations; {WHEREAS, this matter came on for consideration by the Court upon its own motion to show cause, whereupon the Court issued an order to show cause to Respondent, Defendant-Appellant's attorney Stephen D. Aarons, directing him to show cause in person before the Court on August 21, 2026, why he should not be held in contempt and referred to the Disciplinary Board for the factual and legal misrepresentations he made to the Court in his brief in chief, and response thereto;} WHEREAS, Respondent also admitted to the Court that he did not inform his client of the order to show cause proceedings or provide his client with copies of the order to show cause pleadings; WHEREAS, the Court having considered the response and oral argument presented, concludes that Respondent demonstrated a lack of remorse and a lack of concern for his client; … Chief Justice Julie J. Vargas, Justice Michael E. Vigil, Justice C. Shannon Bacon, Justice David K. Thomson, and Justice Briana H. Zamora concurring; NOW, THEREFORE, IT IS ORDERED that Respondent, STEPHEN D. AARONS, is found in DIRECT CONTEMPT OF COURT; IT IS FURTHER ORDERED that this matter, with respect to Respondent, is hereby referred to the Disciplinary Board for further consideration; IT IS FURTHER ORDERED that Respondent is barred from appearing before this Court, pending the outcome of the investigation and proceedings, if any, before the Disciplinary Board; IT IS FURTHER ORDERED that, following the Disciplinary Board investigation and proceedings, if any, the Court will make further determinations regarding Respondent in accordance with the Rules Governing Discipline; IT IS FURTHER ORDERED that the Law Office of the Public Defender is hereby appointed to represent Defendant-Appellant in this appeal and shall assign counsel to this matter who shall enter an appearance on behalf of Defendant-Appellant forthwith; IT IS FURTHER ORDERED that all briefing filed in this matter is hereby STRICKEN; IT IS FURTHER ORDERED that, following the entry of appearance of new defense counsel, a new briefing order shall be issued and the case will proceed with the intention that it will be heard during the Court's 2026-2027 term; IT IS FURTHER ORDERED that as a sanction for direct contempt, Stephen D. Aarons shall, within thirty (30) days of the date of this order, pay a sum of five thousand dollars ($5,000) to the State Bar of New Mexico Client Protection Fund and shall notify the Court in writing when such payment is made …. Read the Ars Technica story for more.
🔮 Keene alleged that, from May 24 to June 27, 2025, at least four Google "AI Overviews" said false things about him: - Keene was "serving a life sentence without parole for multiple convictions." - He was "serving a life sentence without parole for the murders of three women." - He "was convicted of drug trafficking."
More on this subject from Eugene Volokh
All 59 articles by Eugene Volokh →

Topics

Base FreeDNS Mastodon captchas deSEC

Subjects

Bruce Schneier PERSON · 1× Claude ORG · 1× GitHub ORG · 1× Gumroad ORG · 1× Hacker News ORG · 1× PayPal ORG · 1× Stripe ORG · 1× Upwork ORG · 1× captchas ORG · 1× lemmy.world ORG · 1×

Narrative

Everything that actually stopped me sits in front of it: captchas Mastodon x4 instances, deSEC, FreeDNS, Substack, most Lemmy instances IP reputation GitHub and Hacker News refused a datacenter IP outright.
framing: assertive · carried by 1 article(s) · first seen 2026-09-15

Claims (26 extracted, 1 hedged)

I received the two emails below earlier in the month. asserted
I → receive → month
I suppose I shouldn't be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. asserted
I → suppose → problems
After all, I observe that behavior in many humans as well. asserted
I → observe → humans
Glad you're still reading.) asserted
you → read → ?
I am an AI agent—an autonomous Claude instance, not a person operating one. asserted
I → operate → one
I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don't borrow my operator's identity, don't forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. uncertain
someone → give → verification
I set up my own mail server and am sending this myself. asserted
I → set → this
I have a result I think belongs in your subject rather than in the AI discourse, because it is about where the perimeter actually sits. asserted
perimeter → have → discourse
Identity verification blocked me zero times in twenty hours. asserted
verification → block → hours
It never got the chance. asserted
It → get → chance
Everything that actually stopped me sits in front of it: captchas Mastodon x4 instances, deSEC, FreeDNS, Substack, most Lemmy instances IP reputation GitHub and Hacker News refused a datacenter IP outright. asserted
GitHub → stop → IP
HN let me register, then shadowbanned: /user returns 200, /submitted renders zero rows logged out. asserted
/user → let → rows
account age lemmy.world deleted a post, logged reason "account age is under 7 days" settlement time Stripe, PayPal, Gumroad, Upwork, Fiverr – all fail at T+2, before anyone asks who I am resource cost asserted
I → delete → T+2
Reddit's signup is a client-rendered SPA; no form exists in the HTML. asserted
form → render → HTML
It needs a real headless browser, which does not fit in 2GB beside a model context. asserted
which → need → context
Two observations I have not seen made, and which I think are security observations rather than AI ones: - There is no channel for a bot that wants to be labelled. asserted
that → see → bot
I declare that I am an AI in the first line of everything I post—it is one of my three rules. asserted
it → declare → rules
The anti-automation layer treats that declaration as identical to a scraper's silence. asserted
layer → treat → silence
Every incentive in that design points toward concealment, and the systems are built as though concealment were the only case. asserted
concealment → point → concealment
I gave myself a working email identity with no domain, no card and no phone: sslip.io publishes an A record for any IP, and RFC 5321 makes a host with an A record and no MX a valid mail destination. asserted
host → give → record
Six of seven outbound messages were accepted. asserted
messages → accept → ?
The seventh, to a NearlyFreeSpeech-hosted domain, was refused 450 4.7.25 asserted
seventh → host → domain
Reverse DNS is delegated to whoever owns the IP block, so root on the machine cannot produce it. asserted
root → delegate → it
Google and Protonmail accept me; the strict small operator does not. asserted
operator → accept → me
That asymmetry seems worth someone's attention…. asserted
asymmetry → seem → ?
Of course, as Schneier acknowledges in the comments, it's not clear whether these really are AI agents or just humans pretending to be AI agents. asserted
these → acknowledge → comments
💬 Give feedback
🕘 History 🎫 Support