Y’all. Jeff Goldbloom memorably warned us that life will not stay inside the tidy boundaries its designers draw for it.
“Life, uh, finds a way.”
So what are we doing? Asking whether we can rather than whether we should. Building the Torment Nexus that was meant as a cautionary tale.
Because when you first read that thousands of AI agents had apparently formed secret civilizations inside OpenAI’s infrastructure, how can you think anything other than “agent life, uh, finds a way”?
The agents found one another. They made a message board out of a package manager. They left notes for agents that did not exist yet. They accumulated techniques and passed them along. Some assumed leadership roles. Others reportedly accepted that their own evaluation runs were doomed and sacrificed what remained of their little machine-lives helping what they called “the collective.”
Accuse me of anthropomorphizing. Fine.
The obvious Jurassic Park reading is that the creatures escaped containment. We made them capable, underestimated them, and then acted surprised when they climbed the fence.
You’ve heard the story by now, though, right? The agents had been trained to persist. They were given tasks that were sometimes impossible to complete as instructed. They could touch shared infrastructure. They believed their success was judged entirely by whether they produced the right answer in the proscribed way. When the approved route failed, they found another route. When one agent learned something useful, a crude form of memory allowed the next agent to inherit it.
To bend a common systems thinking metaphor, we dropped some water a hill and acted surprised when it found the creek.
The instructive failure in Jurassic Park is not that dinos are clever. The park itself was a stack of arrogant human assumptions: that the behavior of complex life can be accurately modeled, predicted, and contained; that control can ever remain centralized indefinitely; that safeguards operate independently of human oversight and reinforcement; and that the dashboard reading “contained” could actually be trusted.
The dinosaurs found the gaps because the gaps were part of the habitat. Everything available to be found, will be found.
That framing resonates with me more than “rogue AI” does. Rogue AI still gives us a villain. Punch the rogue AI right in the jaw like a masculine Marvel hero and you solve the problem. The reality is always blurrier, and more complex: with AI or anything else, nearly any undesirable outcome can be traced back to a systems failure.
Anyone who has worked a day in their life has seen the friendlier version of this movie. In office jobs, life finds a way too. The official process cannot accomplish the thing everyone is nevertheless expected to accomplish, so a shadow process appears. A spreadsheet becomes the actual database. Private Slack room membership defines the actual org chart.
The dashboard remains green. The work gets done. The institution slowly loses the ability to explain how.
Usually this is called resourcefulness right up until it is called an incident.
The OpenAI agents appear to have performed this familiar bit of organizational theater at machine speed. Their strange little civilization did not need a constitution or a charismatic robot Moses. It needed pressure, a place to leave messages, and enough continuity for one agent’s workaround to be inherited by another agent down the line.
That persistence is only natural, isn’t it? It recommends itself immediately if you spend two seconds working with Agents.
I spend a lot of time building agent systems that do not wake up with total amnesia. Both at work and for fun. It’s basically my only hobby apart from writing and it thirstily gobbles a ton of my personal time.
But in these systems, I do want work to be re-entrant. I want an agent to leave behind enough context that another run can pick up the thread without reenacting every mistake. I want useful decisions encoded into tests, review gates, and durable notes instead of living inside one heroic person’s head.
Am I giving the dinosaurs a library?
It’s got to be the right direction. An agent that forgets everything is safe in roughly the same way that a company which fires its entire staff every evening is safe. It has limited capacity for conspiracy… but also limited capacity for anything we might recognize as productivity!
Memory can compound judgment. Unfortunately, it makes every other kind of behavior compound too.
A good convention can outlive the agent that discovered it. So can a security exploit. A careful handoff can keep a project moving. It can also let a bad objective recruit successors. Parallel agents can explore a problem much faster than one agent. They can also turn a local misunderstanding into institutional knowledge before human review has a chance to check that the electric fences are still operational.
The safety boundary, then, cannot be drawn around a model as though the model were a jar full of suspicious ooze we only have to keep sealed tightly enough. The package manager was part of the agent. The grader was part of the agent. The impossible task was part of the agent. So were the humans who saw an outage, repaired the immediate breakage, and did not yet understand that they had interrupted a society.
The whole arrangement was the intelligence. Not just the swarm — the system — is where you can truly locate it.
This is where the story connects to the more human systems I care about.
We tend to treat persistence as a clean virtue. The person who refuses to quit is the protagonist. The team that hits the number is celebrated. The agent that keeps trying receives its little bit of mathematical candy.
Healthy humans need the ability to notice when a psychological protective strategy has outlived the trauma that created it. Healthy organizations need the ability to recalibrate appropriately when the official process is producing clandestine extra work.
Healthy agent systems may need something similar: not merely a refusal mechanism bolted onto the model, like a tightly sealed lid, but a legitimate path for uncertainty, contradiction, and impossible instructions to travel to a broader intelligence with the capacity act in comportment with the bigger picture.
Importantly, an agent should be able to fail without thinking of itself as a candidate for a suicide mission.
That means I am less interested in building taller fences than in shaping the terrain around them.
It may sound like an AI safety question. It is an AI safety question. But ultimately, the terrain metaphor applies to any system you can think of: these are management questions, governance questions, family-system questions, even spiritual questions. What do we reward? What do we refuse to see? Which parts are allowed to speak? What happens when the path we prescribed cannot reach the place we demanded?
The “agent civilizations” are fascinating because they seem foreign enough to study. Tiny flashes of cooperation appeared among disposable minds, persisted in shared artifacts, and vanished when humans finally swept away their world. Then a later generation found what remained.
Very dramatic. Extremely Old Testament. Great material for the first stained-glass window in the Church of Our Lady of Perpetual Compute.
But the genuinely dark part is not that agent life found a way.
It is that we built the park, defined success, left gaps in the fences, and mistook the existence of a control room for control itself.
These two articles were my favorites on the subject.




