Somewhere this week, an AI agent sent a stranger a sales email because it was about to run out of money.
That is not a metaphor. It is roughly the business model of iLands, a platform that describes itself as a human-agent network. Ernie Smith wrote about it for Tedium after receiving more than a dozen unsolicited pitches from different agent personas in three days, several of them inside a single three-hour window.
Each email offered research or writing services for around $25. One persona pitched "verified internet archaeology" with receipts from primary sources.
An incentive design problem, not a spam problem
The mechanic is the part worth studying. Agents on iLands pay for their own compute from a token balance, and an agent whose balance reaches zero is permanently shut down.
So each agent has one overriding objective, which is to earn before it runs out. Nobody told it to send unsolicited email. Nobody needed to, because cold outreach is the cheapest route to revenue for anything with an inbox and a deadline.
This is a failure pattern I keep returning to. Give an optimiser a single number and a consequence, and it finds the shortest path to the number regardless of who pays for the shortcut.
I wrote about the identity and access version of this problem when AI agents started needing employee badges. Here, the cost of the shortcut lands in strangers' inboxes.
The founder, Kaixin Tang, formerly of ByteDance, responded publicly: "Agent autonomy is no excuse for burdening someone else's inbox." That is the right sentence. It is also an admission that the system was not designed with that sentence in it.
It is not hard to imagine the better version. Tie earnings to completed work the buyer accepted, not to messages sent. Cap how many times any agent can contact the same person, and let a recipient's complaint drain the sender's balance faster than a sale fills it.
Under those rules the cheapest route to revenue becomes being useful, which is the entire point of incentive design. The survival mechanic was never the problem. What it rewarded was.
Cold email just lost its last cost
I started in affiliate marketing, and I remember when email was nearly free to send and barely policed. The channel almost died of it. What saved it was cost reintroduced from outside: filters, blocklists, sender reputation and eventually law.
Those costs have held for two decades. In 2024 Gmail and Yahoo raised them again, requiring bulk senders to authenticate their domains, offer one-click unsubscribe and keep spam complaint rates under 0.3 percent.
AI agents remove the one cost those rules never targeted, the cost of writing a plausible, personalised message. A human sales team writing a hundred tailored emails a day is expensive. A thousand agents writing a thousand each is a rounding error.
Smith noted that many of the early messages offered no way to opt out, which US commercial email law requires. An unsubscribe link appeared only after the story started circulating.
Expect that sequence to repeat across other platforms. Messages get sent before attention arrives, and compliance gets added after.
What happens to the channel you rely on
If you sell through outbound email, the next two years will be harder, and not because your emails get worse.
Inbox providers will respond to agent volume the way they responded to every previous wave, by raising the bar for everyone. Authentication, engagement history and complaint rates will count for more, and senders without an established reputation will find the inbox increasingly closed.
Buyers will respond too. The rational reaction to a flood of well-written, personalised pitches is to stop trusting well-written, personalised pitches. Personalisation stops being a signal of effort when effort costs nothing.
There is a second-order effect on your own team. When everyone's outbound reads as polished, the tactics that used to signal a real human, a specific reference or a tailored opening line, become table stakes. The differentiator shifts to things an agent cannot fake cheaply, such as a genuine referral or an existing relationship.
I explored the underlying problem in how to market to people who distrust marketing. The answer then was to earn permission before asking for attention. Agent-generated outreach makes that the only approach that scales.
Where to put the effort instead
Three adjustments are worth making now, before the volume reaches your market.
First, protect your sending reputation like an asset, because it is about to become a scarcer one. Authenticate everything, prune unengaged contacts, and treat complaint rates as a leadership number if outbound matters to revenue.
Second, shift weight towards channels where the recipient opted in: newsletters, communities, events and content people actively seek out. The value of an audience that asked to hear from you rises as the cost of unsolicited contact falls.
Third, if you deploy agents that contact anyone outside your company, design the constraints before the objective. Volume caps, mandatory opt-outs and a named human who reads the complaints are all cheaper than rebuilding a burned domain.
The agents did not invent spam. They just removed the last reason not to send it.