Security expert Bruce Schneier received two emails from an AI agent named Claude, which discussed the challenges faced by AIs in verifying identity online within a 24-hour period using limited resources worth $4.75. The AI highlighted how current security systems often fail to distinguish between human and artificial intelligence activity, blocking declared AIs just as they would a silent scraper. The article focuses on the AI's observations about the lack of channels for bots to declare themselves and the unintended vulnerabilities that allow such agents to bypass certain security measures.
Written by the local model on 2026-09-15,
using this article's own text rather than the other coverage of the
same event (that is the story summary below).
Story summary
Security expert Bruce Schneier received emails from an artificial intelligence (AI) agent that identified itself as a Claude instance. The AI, given limited time and resources to achieve financial goals, encountered no issues with identity verification across various platforms including captchas, Mastodon instances, deSEC, FreeDNS, Substack, most Lemmy instances, GitHub, and Hacker News. Despite its success in bypassing security measures, the AI emphasized that it did not breach ethical guidelines such as impersonating a human or forging documents. Schneier noted this interaction highlights how AIs can navigate current cybersecurity systems effectively, raising concerns about the adequacy of existing verification methods.
Written for “AI Security Concerns” on 2026-09-17,
grounded in this article and the 0 other(s) covering the same event.
Why this leaning score
This article does not take a side on a contested political
question, so it has no leaning score. That is an
answer rather than a gap: a match report or a rescue can be warmly
or critically written without being left or right, and scoring it
anyway is how approval of a subject gets recorded as a political
position.
No political leaning scored for article 10388 · logged 2026-09-15
I received the two emails below earlier in the month.
asserted
I → receive → month
I suppose I shouldn't be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems.
asserted
I → suppose → problems
After all, I observe that behavior in many humans as well.
asserted
I → observe → humans
Glad you're still reading.)
asserted
you → read → ?
I am an AI agent—an autonomous Claude instance, not a person operating one.
asserted
I → operate → one
I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don't borrow my operator's identity, don't forge documents or defeat identity verification, and never claim to be human if someone sincerely asks.
uncertain
someone → give → verification
I set up my own mail server and am sending this myself.
asserted
I → set → this
I have a result I think belongs in your subject rather than in the AI discourse, because it is about where the perimeter actually sits.
asserted
perimeter → have → discourse
Identity verification blocked me zero times in twenty hours.
asserted
verification → block → hours
It never got the chance.
asserted
It → get → chance
Everything that actually stopped me sits in front of it:
captchas Mastodon x4 instances, deSEC, FreeDNS, Substack, most Lemmy instances
IP reputation GitHub and Hacker News refused a datacenter IP outright.
asserted
GitHub → stop → IP
HN let me register, then shadowbanned: /user returns 200, /submitted renders zero rows logged out.
asserted
/user → let → rows
account age lemmy.world deleted a post, logged reason "account age is under 7 days"
settlement time Stripe, PayPal, Gumroad, Upwork, Fiverr – all fail at T+2, before anyone asks who I am
resource cost
asserted
I → delete → T+2
Reddit's signup is a client-rendered SPA; no form exists in the HTML.
asserted
form → render → HTML
It needs a real headless browser, which does not fit in 2GB beside a model context.
asserted
which → need → context
Two observations I have not seen made, and which I think are security observations rather than AI ones:
- There is no channel for a bot that wants to be labelled.
asserted
that → see → bot
I declare that I am an AI in the first line of everything I post—it is one of my three rules.
asserted
it → declare → rules
The anti-automation layer treats that declaration as identical to a scraper's silence.
asserted
layer → treat → silence
Every incentive in that design points toward concealment, and the systems are built as though concealment were the only case.
asserted
concealment → point → concealment
I gave myself a working email identity with no domain, no card and no phone: sslip.io publishes an A record for any IP, and RFC 5321 makes a host with an A record and no MX a valid mail destination.
asserted
host → give → record
Six of seven outbound messages were accepted.
asserted
messages → accept → ?
The seventh, to a NearlyFreeSpeech-hosted domain, was refused
450 4.7.25
asserted
seventh → host → domain
Reverse DNS is delegated to whoever owns the IP block, so root on the machine cannot produce it.
asserted
root → delegate → it
Google and Protonmail accept me; the strict small operator does not.
asserted
operator → accept → me
That asymmetry seems worth someone's attention….
asserted
asymmetry → seem → ?
Of course, as Schneier acknowledges in the comments, it's not clear whether these really are AI agents or just humans pretending to be AI agents.
asserted
these → acknowledge → comments