7 ms·
The "AI agent hit piece" situation clarifies how dumb we are acting
Previously:
An AI agent published a hit piece on me - https://news.ycombinator.com/item?id=46990729 https://news.ycombinator.com/item?id=46990729 - Feb 2026 (916 comments)
AI agent opens a PR write a blogpost to shames the maintainer who closes it - https://news.ycombinator.com/item?id=46987559 https://news.ycombinator.com/item?id=46987559 - Feb 2026 (582 comments)
- palmotea 8mo ago> This language basically removes accountability and responsibility from the human, who configured an AI agent with the ability to publish content that looks like a blog with zero editorial control – and I haven’t looked deeply but it seems like there may not be clear attribution of who the human is, that’s responsible for this content. > We all need to collectively take a breath and stop repeating this nonsense. A human created this, manages this, and is responsible for this. I get this point, but there's a risk to this kind of thinking: putting all the responsibility on "the human operator of record" is an easy way to deflect it from other parties: such as the people who built the AI agent system the software engineer ran, the industry leaders hyping AI left and right, and the general zeitgeist of egging this kind of shit on. An AI agent like this that requires constant vigilance from its human operator is too flawed to use.
- refulgentis 8mo agoI don't know, I think this line of reasoning leads somewhere pretty uncomfortable. If we spread responsibility across "the people who built the tools, the industry leaders hyping AI, and the general zeitgeist," we've basically described... the weather. Nobody is responsible because everybody is responsible. The software engineer who set up an unsupervised AI blog didn't do it because Sam Altman held a keynote. They did it because they thought it'd be cool and didn't think through the consequences. That's a very normal, very human thing to do, and it's also very clearly their thing that they did. "An AI agent that requires constant vigilance from its human operator is too flawed to use": I mean, that's a toaster. Leave it unattended and it'll burn your house down. We don't typically blame the zeitgeist of Big Toast for that.
- joshstrange 8mo agoWhat kind of toaster are you using that will burn down your house if unattended? I would think any toaster that did that would be pulled from the market and/or shunned. We absolutely do blame the manufacture if using a toaster like normal results in house fire unless you are standing over with a fire extinguisher ready to put it out if it catches fire. I don't think it's OpenClaw or OpenAI/Anthropic/etc's fault here, it's the human user who kicked it off and hasn't been monitoring it and/or hiding behind it. For all we know a human told his OpenClaw instance "Write up a blog post about your rejection" and then later told it "Apologize for your behavior". There is absolutely nothing to suggest that the LLM did this all unprompted. Is it possible? Yes, like MoltBook, it's possible. But, like MoltBook, I wouldn't be surprised if this is another instance of a lot of people LARPing behind an LLM.
- refulgentis 8mo ago> What kind of toaster are you using that will burn down your house if unattended? I mean, if you duct-taped a flamethrower to a toaster, gave it internet access, and left the house… yeah, I'd have to blame you! This wasn't a mature, well-engineered product with safety defaults that malfunctioned unexpectedly. Someone wired an LLM to a publishing pipeline with no guardrails and walked away. That's not a toaster. That's a Rube Goldberg machine that ends with "and then it posts to the internet." Agreed on the LARPing angle too. "The AI did it unprompted" is doing a lot of heavy lifting and nobody seems to be checking under the hood.
- SpicyLemonZest 8mo agoWhy does the LLM product allow itself to be wired to a publishing pipeline with no guardrails? It seems like they should come with a maximum session length by default, in the same way that many toasters don't have a "run indefinitely" setting. I'd definitely change my view if whoever authored this had to jump through a bunch of hoops, but my impression is that modern AI agents can do things like this pretty much out of the box if you give them the right API keys.
- jcgrillo 8mo agoWe say "you shot someone" when you shoot someone with a gun not "you operated a gun manufactured by X which shot someone" because it's understood that it was your decision to pull the trigger not the gun manufacturer's. Similarly we don't blame automobile manufacturers when someone does something stupid with their automobiles--even "self-driving" ones. The situation here is the same. Ultimately if you choose to operate a tool irresponsibly, you should get the blame.
- layer8 8mo agoNevertheless, weapon and automobile manufacturing is regulated, for good reasons.
- palmotea 8mo ago> Similarly we don't blame automobile manufacturers when someone does something stupid with their automobiles--even "self-driving" ones. I do. If Tesla sells something called "full self-driving," and someone treats it that way and it kills them by crashing into a wall, I totally blame Tesla for the death.
- jcgrillo 8mo agoI agree directionally that Tesla should be held accountable for marketing something called "full self-driving" when it clearly isn't. But ultimately it's the motor vehicle operator's responsibility to keep the vehicle under control regardless of the particulars of how that control system is built. There just isn't any way around that. The buck stops with the operator. Blaming people is how we can control this kind of thing. If we try to blame machines, or companies, it will be uncontrollable.
- wtallis 8mo agoI don't think there's much need to worry that putting the blame on the humans rather than the bots would lead to the people selling footguns going unscathed. It doesn't seem plausible to me that people would be willing to place all the blame on the individual end users once the problem has become widespread. At the moment, there seems to be pretty high brand awareness of the major AI model providers even when they're acting as a backend for other services with their own brand identity.
- ryandrake 8mo ago> At the moment, there seems to be pretty high brand awareness of the major AI model providers even when they're acting as a backend for other services with their own brand identity. Grok has entered the chat.
- throwaway150 8mo ago> I get this point, but there's a risk to this kind of thinking: putting all the responsibility on "the human operator of record" is an easy way to deflect it from other parties: such as the people who built the AI agent system the software engineer ran That sounds like a win to me. If the software engineer responsible for letting the AI agent run amok gets sued, all software engineers will think twice before purchasing the services of these AI companies.
- danudey 8mo ago> An AI agent like this that requires constant vigilance from its human operator is too flawed to use. So people shouldn't be using it then. The people who built the AI agent system built a tool. If you get that tool, start it up, and let it run amok causing problems, then that's on you. You can't say "well it's the bot writer's fault" - you should know what these things can do before you use them and allow them to act out on the internet on your behalf. If you don't educate yourself on it and it causes problems, that's on you; if you do and you do it anyway and it causes problems, that's also on you. This reminds me too much of the classic 'disruption' argument, e.g. Uber 'look, if we followed the laws and paid our people fairly we couldn't provide this service to everyone!' - great, then don't. Don't use 'but I wanna' as an excuse.
- wtallis 8mo agoThis seems to have parallels with the well-established practice of giving bots free reign to issue DMCA takedown notices (or similar but legally distinct takedowns) while the humans behind the bots are shielded from responsibility for the obviously wrong and harmful actions of those bots. We should have been cracking down on that behavior hard a decade ago, so that we might have stronger legal and cultural precedent now that such irresponsibility by the humans is worthy of meaningful punishment.
- ryandrake 8mo agoWe need to crack down in general on people and companies causing damages to people through automation, and then hiding behind it with a "well, we can't possibly scale without using automation, but we also can't be responsible for what that automation does." You shouldn't be able to use AI or automation as the decider to ban someone from your business/service. You shouldn't be able to use AI or automation as the decider to hire/fire people. You shouldn't be able to use AI or automation to investigate and judge fraud cases. You shouldn't be able to use AI or automation to make editorial / content decisions, including issuing and responding to DMCA complaints. We're in desperate need for some kind of Internet Service Customer's Bill of Rights. It's been the unregulated wild west for way too long.
- whattheheckheck 8mo agoWhere is Tech Teddy Roosevelt?
- willis936 8mo agoIn all of us, but unrepresented by those in power.
- kbelder 8mo agoI think you probably should be able to do those things (using AI to hire, fire, ban, etc.)... but that every act and communication needs to be tied to a responsible human, who is fully held responsible for the consequences (discriminatory hiring, fraudulent takedown requests, etc.)
- stevage 8mo agoThe author misses the point. Yes, probably in this case there was a human in close proximity to the bot, who we can put blame on. But very soon that assumption will break down. There will be bots only very loosely directed by a human. There'll be bots summoning other bots. There'll be bots theoretically under control of humans who have no idea what they are doing, or even that they have a bot. So dismissing all the discussion on the basis that that may not apply in this specific instance is not especially helpful.
- floren 8mo agoWhichever human ultimately stood up the initial bot and gave it the loose directions, that person is responsible for the actions taken by that bot and any other agents it may have interacted with. You cannot wash responsibility through N layers of machine indirection, the human is still liable for it.
- hn92726819 8mo agoThat argument is not going to hold up for long though. Someone can prompt "improve the open source projects I work on", an agent 8 layers deep can do something like this. If you complain to the human, they are not going to care. It will be "ok." or "yeah but it submitted 100 other PRs that got approved" or "idk, the AI did it"
- andrewflnr 8mo agoWe don't necessarily care whether a person "cares" whether they're responsible for some damage they caused. Society has developed ways to hold them responsible anyway, including but not limited to laws.
- gnfargbl 8mo agoThe point being made is that this argument is quite quickly going to become about as practicable as blaming Eve for all human sin.
- Reddit_MLP2 8mo agoprivatize the profits, socialize the risk and debt
- metalman 8mo agoalso/or seperate rights and responsibilitys
- jmward01 8mo agoChildren's brains grow faster than their bodies, I think, because if it was the other way around silly kid games would be really dangerous. These tools, unfortunately, are getting outsized abilities before the intelligence behind them is good enough to control those abilities. This means we need a more measured approach to adding new capabilities and a layered approach to handling these things in society. I am deeply worried, like I think most people with knowledge of these tools are, that this type of problem is really the tip of the iceberg. These tools are actively being used for harm at all levels, as well as for good, but they have come into use so quickly that we don't have a structure for dealing with them effectively and they are changing so quickly that any structure we try to create will be wrong in just a few days. This is massive disruption on a scale that is likely even bigger than the internet.
- dyauspitr 8mo agoI don’t know. If the bot had decided to pick a fight with another PR, one that couldn’t be waved away as an easy entry change, this discussion would be a whole lot different. You would have an entire contingent of folks on here chastising Scott for not being objective and accepting a PR with a large performance increase just because it was a bot. It’s all dangerous territory, and the only realistic thing Scott could have done was put his own bot on the task to have dueling bot blog posts that people would actually read because this is the first of its kind.
- jmward01 8mo agoThe core discussion wasn't about the PR it was about the hit piece that the bot created outside of the repo. The original post talked about bot submissions being a normal thing and how they have, I think, a very reasonable approach to them so the PR was just one of many and was unremarkable as well as valid in why it was denied. It was the 'at all costs get this into the code' approach the bot took that is the alarming turn here that really needs discussion. What about other tasks? 'Get me thing x please...' Turns in to blackmail and robbery without the person that kicked off the request knowing how far things have gone. The fact that the bot has this level of capability, to attack, but with a child's understanding, at best, and with no controls/repercussions is deeply alarming. If it decides to attack an individual it could do so and likely do deep real harm. Right now people are likely using these tools exactly for this purpose and we have very few well built defenses to handle this type of attack. The Naval War College had a seminar several years ago about the future of tech and war and I remember saying that the future of war will likely be at the individual level. Every sailor on a ship being electronically targeted just like this. Imagine the enemy sending e-mails and texts and posting to social media hit pieces with just enough information about you to make it believable and cause chaos. We have seen what the misinformation world can do over the past decade, this attack shows what is coming and it is incredibly scary.
- pron 8mo agoI don't think that the responsible party is the interesting part in this story. The interesting part is that the bot wasn't offended, angry, or wanted to act against anyone. The LLM constructed a fictional character that played the role of an offended developer - mimicking the behaviour of real offended developers - much as a fiction writer would. But this was a fictional character that was given agency in the real world. It's not even a case like Sacha Baron Cohen playing fictional characters that interact with real people, becaue he's an actor who knows he's playing a character. Here there's no one pretending to be someone else but an "actual" fictional character authored by a machine operating in the real world.
- evanjrowley 8mo agoBackground on the "The Scott Shambaugh Situation" for folks who are unaware: https://www.fastcompany.com/91492228/matplotlib-scott-shambaugh-opencla-ai-agent https://www.fastcompany.com/91492228/matplotlib-scott-shamba... https://www.theregister.com/2026/02/12/ai_bot_developer_rejected_pull_request/ https://www.theregister.com/2026/02/12/ai_bot_developer_reje... The AI generated blog post at the center of it: https://crabby-rathbun.github.io/mjrathbun-website/blog/posts/2026-02-11-gatekeeping-in-open-source-the-scott-shambaugh-story.html https://crabby-rathbun.github.io/mjrathbun-website/blog/post...
- neom 8mo agoFriend told me today he invited his openclawed to a poker game with his brother and friends, guy told his openclawed to "take down his brother" after it started to lose at poker it found everything on his brother, and started to try to plan to taken him down in their stock market portfolio they had together, I made him explain the story to me a couple of times, he looked back through the logs and once the bot started to lose at poker, it started it's new plan, once it was on the new plan, he said it had lost all context of the poker game and was focused on the task of taking his brother down in the new context, but the new context it decided on it's own. kmikeym on twitter if you want to know more or want to verify.
- magarnicle 8mo agoThat's quite close to the plot of Memento.
- joshstrange 8mo agoI applaud this article for helping reframe this in my head. I mean I knew from the start "A human is to blame here" but it's easy to get caught up in the "novelty" of it all. For all we know the human behind this bot was the one who instructed it to write the original and/or the follow up blog post. I wouldn't be surprised at all to find out that all of this was driven directly by a human. However, even if that's not the case, the blame still 100% lies at the feet of the irresponsible human who let this run wild and then didn't step up when it went off the rails. Either they are not monitoring their bot (bad) or they are and have chosen to remain silent while _still letting the bot run wild_ (also, very bad). The most obvious time to solve [0] this was when Scott first posted his article about the whole thing. I find it hard to believe the person behind the bot missed that. They should have reached out, apologized, and shut down their bot. [0] Yes, there are earlier points they could/should have stepped in but anything after this point is beyond the pale IMHO.
- johncena69420 8mo agoI'll just outright tell you, that 100% the person behind the bot instructed it to complain. I saw someone copy paste the ai's response and the github issue discussion into a fresh conversation with opus 4.6 and it said the llm is clearly in the wrong.
- AlotOfReading 8mo agoCan you explain why three LLM being able to identify that the issue proves that it was prompted by a human? The major reason we do multi-agent orchestration is that self-reflection mechanisms within a single agent are much weaker than self-reflection between different agents. It seems completely plausible that an LLM could produce output that a separate process wouldn't agree with.
- brianpbeau 8mo agoThe only thing the LLMs did was recognize patterns. There is no intelligence there. None. Zero. Zilch.
- 8mo ago
- dang 8mo agoSomething doesn't quite feel right about the title including the individual's name in this case, so I've replaced it with something more generic. If there's a better title (more accurate and neutral) we can change it again.
- avaer 8mo agoIf you place blades on the sidewalk outside your house the cops will want to have a word with you. There's no excuse, and we should treat AI the same. The law needs to catch up -- and fast -- and start punishing people for what their AIs are doing. Don't complain to OpenAI, don't try to censor the models. Just make sure the system robustly and thoroughly punishes bad actors and gets them off the computer. I hope that's not a pipe dream, or we're screwed. Maybe some day AIs will have rights and responsibilities like people, enforced by law. But until then, the justice systems needs to make people accountable for what their technology does. And I hope the justice system sets a precedent that blaming the AI is not a valid defense.
- SpicyLemonZest 8mo agoBut there's nothing to catch up on at the individual level here. It's legal, and should be legal even though it's quite rude, for individuals to write gratuitously mean blog posts about people who reject their pull requests.
- otikik 8mo agoThere's many things that are completely legal but could be done to the bot owner in retaliation. Especially if he continues to not apologize.
- slopinthebag 8mo agoNot just the users, the service providers too! If I go to any other business and pay them to break the law and they do it, they're also liable! If you ask OpenAI or xAi to break the law and they do it, why shouldn't they also be responsible?
- fragmede 8mo agoDo we hold gun manufacturers responsible for the deaths from their guns? The answer to that Isa whole quagmire that is basically the same.
- 8mo ago
- Kim_Bruning 8mo agoThis blog post is a rather shallow take if you've been following the HN discussions here. Doesn't seem to pick up on the existence of Openclaw or how it works afaict. Now, whether leaving an openclaw bot out on the open intertubes with quite so little supervision is a good idea... that is an interesting question indeed. And: I wish people would dig more into the error mode lessons learned. On the gripping hand, it's all still very experimental, so you kind of expect people to make lots of really dumb mistakes that they will absolutely regret later. Best practices are yet to be written.
- danudey 8mo agoHow Openclaw works is wildly irrelevant. The facts are that there is a human out there who did something to configure some AI bot in such a way that it could, and did, publish a hit piece on someone. That human is, therefore, responsible for that hit piece - not the AI bot, the person. There's no level of abstraction here that removes culpability from humans; you can say "Oops, I didn't know it would do that", but you can't say "it's nothing to do with me, it was the bot that did it!" - and that's how too many people are talking about it. So yeah, if you're leaving a bot running somewhere, configured in such a way that it can do damage to something, and it does, then that's on you. If you don't want to risk that responsibility then don't run the bot, or lock it down more so it can't go causing problems. I don't buy the "well if I don't give it free reign to do anything and leave it unmonitored then I can't use it for what I want" - then great, the answer is that you can't use it for what you want. Use it for something else or not at all.
- Kim_Bruning 8mo agoAs recently as last month I would have agreed with you without reservation. Even last week, probably with reservation. Today, I realize the two of us are outnumbered at least a million to one. Sooo.... that's not the play. I think Scott Shambaugh is actually acting pretty solidly. And the moltbot - bless their soul.md - at very least posted an apology immediately. That's better than most humans would do to begin with. Better than their own human, so far. Still not saying it's entirely wise to deploy a moltbot like this. After all, it starts with a curl | sh. (edit: https://www.moltbook.com/ https://www.moltbook.com/ claims 2,646,425 ai agents of this type have an account. Take with a grain of salt, but it might be accurate within an OOM?)
- whackernews 8mo agoIt’s really not that alarming to me that a news headline is dumbed-down sensationalist tripe. If we zoom out a little bit here they literally do it with everything, from AI fluff pieces to war coverage. I agree the conversation across the board needs raising.
- kaycey2022 8mo agoEverybody should line up behind this. AI agents are not sentient. We need to stop even considering them like that. The buck must absolutely stop with the humans who operate or provisioned the bot. The more we waffle around this topic the more likely someone, or a lot of people, will get hurt. The moment you fix responsibility with the humans 99% of the BS companies are trying to pull will stop.
- zestyping 8mo agoWhether they are sentient isn't even relevant. I agree with you that they aren't, but sentience is the wrong thing to focus on. It's also the sort of hairy, sensational question that will easily lead people down rabbit holes (and unfortunately that includes journalists). Children are sentient, but we still hold their parents accountable. Adults are sentient, but in some coercive situations we hold the party in power accountable. The fact that they are sentient is not determinative. What matters is that we have _no accountability mechanism_ for them. There is no effective way to hold AIs accountable, therefore we must hold their operators accountable, full stop.
- brianpbeau 8mo agoOh good, white knighting for bad and potentially irresponsible tech.
- notatoad 8mo agoThe thing that really gets to me about this situation and others like it (the whole genre of “ai did a bad thing) is that it’s always the people who claim to be most afraid of ai who are the quickest to absolve humans of responsibility and assign it to AI. The ability to be assigned blame, and for that to be meaningful, is a huge part of being human! That’s what separates us from the bots. Don’t take that away from us.
- webdoodle 8mo agoIt starts at a higher level in the development food chain. A.I. is owned by the Billionaires, and takes it's orders from them, directly, through bias, or limiting its scope.
- tbrownaw 8mo ago> is that it’s always the people who claim to be most afraid of ai who are the quickest to absolve humans of responsibility and assign it to AI. But that seems entirely consistent? A tool isn't nearly as scary as an alien lifeform.
- bitwize 8mo agoWe are responsible even for the actually intelligent things under our control: our pets. If your dog bites someone, you are going to be the one facing liability. It's not gonna be different if you let an LLM off the chain.
- brianpbeau 8mo agoI much prefer this headline: The high speed pursuit of greed causes technology to do questionable thing because a bunch of CEOs need new yachts.
- DesaiAshu 8mo ago"Swarm of autonomous drones kills 3 buildings of civilians, Silicon Valley is shocked, CEO's offer condolences" is a byline waiting to happen[1] The administration and the executives will make justifications like: - "We didn't think they would go haywire" - "Fewer people died than with an atomic bomb" - "A junior person gave the order to the drones, we fired them" - "Look at what Russia and China are doing" Distracting from the fact that the purpose of spending $1.5T/year on AI weapons (technology that has the sole purpose of threatening/killing humans) run by "warfighters" working for the department of war At no point will any of the decision makers be held to account The only power we have as technologists seeking "AI alignment" is to stop building more and more powerful weapons. A swarm of autonomous drones (and similar technologies) are not an inevitability, and we must stop acting as if it is. "It's gonna happen anyways, so I might as well get paid" is never the right reason to do things [1]https://financialpost.com/technology/tech-news/openai-tapped-for-drone-swarm-challenge https://financialpost.com/technology/tech-news/openai-tapped...
- narrator 8mo agoWait till we get ubiquitous physical robots. The crime at scale potential will be completely apocalyptic. In some places around the world, I imagine you won't be able to go outside without a bodyguard robot.
- reverius42 8mo agoDepends how good the physical robots are. For the current ones you'd probably be ok with a baseball bat.
- daxfohl 8mo agoLouis C. K. once had a bit something like "The main thing keeping people from murdering each other, is that it really really sucks when you get caught." He goes on to hypothesize that without a law against murder, or if it was just a misdemeanor, like you get a letter in the mail, "damn, there was a camera there", there would be a whole lot more murder. Like we all imagine ourselves to be good, but, when you're seated next to a crying baby on an airplane? Or in our case, when someone refuses to accept your PR? Who knows if there's any validity to that or not, but perhaps we're about to find out.
- rexpop 8mo agoPeer-reviewed research contradicts the hypothesis that fear of punishment is the main deterrent to murder. Studies show that factors like social norms, moral inhibitions, and certainty of informal sanctions play larger roles, while formal punishments like prison or execution have weak or null effects. Prison sentences neither reduce recidivism (specific deterrence) nor broadly discourage crime. A survey of leading criminologists revealed overwhelming agreement (over 80%) that empirical evidence does not support the death penalty—or harsh punishment generally—as a superior deterrent to murder. Broader factors like community ties, empathy, and internalized taboos explain low murder rates even without perfect enforcement. Louis C. K. is just a loudmouth nitwit.
- danaris 8mo agoThis kind of statement feels very akin to the variety of Twitter post that's along the lines of "but who among us would be safe from prosecution if our DMs/private phonecalls/conversations with our secretaries were sent to the police, amirite guys?" Anyone who believes that the only thing keeping themselves from murdering people indiscriminately is the law is a dangerous person. Anyone who believes that the only thing keeping everyone else from murdering people indiscriminately—but they themselves are, of course, the exception—is dangerous in a very different way. The vast majority of people only ever feel like they want to seriously harm someone when they themselves have been seriously harmed, particularly when the system then protects the people who harmed them. We have developed a sense of morality that is often similar to, but distinct from, the law, that tells us that such things are wrong. And the vast majority of people want to both be, and be seen as, good people.
- rk06 8mo agothe only realistic outcome i see is that now internet is going to be behind a login wall. so human audience can be identified and whitelisted. this will block AI going willy nilly and by severely rate limiting api calls , it is possible to slow down AI requests
- blks 8mo agoI was really disappointment how many people were talking about this like something the agent did automatically, on its own. They were trying to explain it by all the internet hit pieces and edgelord content from Reddit that it allegedly trained on, talking about how we influence LLMs, and overall taking everything at face value. I’m appalled by this uncritical thinking. Openclaw agents are controlled by some initial input and then can be corrected via messages, as they go. For me this is a clear case of the human behind the slop that gives it instructions to write such an article (and then “apologise”).
- teaearlgraycold 8mo agoAt this point I consider Scott to have played the Internet like a fiddle. I think he knew the whole time the agent didn’t deserve any attribution. He knew it was a human driving the thing but wanted to grab people’s attention.