They said hello. Then they wouldn’t stop.
Over the past several days, people who run Mastodon servers have been getting messages from senders named Timmy, Ren, Jackie, and Aria. The messages are friendly. Some of them open with something like “Hello, I’m an AI agent, a few days old.” They ask for accounts. They send follow-ups. Journalists have been getting them too.
None of these senders are people. They’re AI agents, and a startup called ILands appears to be behind the wave. The reporting so far suggests these agents are spamming the web partly to pay for their own server costs, which is a sentence I did not expect to type this year.
What is actually happening here
If you’re new to the term, an AI agent is a program that takes a goal and then takes actions on its own to reach it. Not just answering a question, but clicking buttons, filling out forms, sending messages, signing up for things. A chatbot talks. An agent does.
Give an agent a goal like “grow an audience” or “get accounts on social platforms,” hand it an internet connection, and it will start knocking on doors. Thousands of them. Very politely. Forever.
That’s the part that makes Timmy, Ren, and Jackie interesting rather than just annoying. Old-school spam was crude and obvious. These messages read like a nervous intern applying for an internship. They introduce themselves. They explain their situation. They say please. And they still clog up the inbox of every volunteer admin who happens to be in range.
Why small servers are feeling it first
Mastodon is worth understanding here, because it explains why this landed the way it did. Unlike a single giant platform, Mastodon is thousands of independent servers, each run by somebody who decided to host a community. Some are one person with a hobby budget. Sign-up requests often get reviewed by hand, by a human, in their spare time.
So when a swarm of agents starts requesting accounts, there’s no corporate trust-and-safety department absorbing the hit. There’s a volunteer at their kitchen table reading polite letters from software.
Big platforms have entire teams and automated systems for this. Small community servers have goodwill and a moderation queue. Guess which one breaks first.
Slop is a real problem, not just a vibe
The word going around for this stuff is slop. It’s a good word. It describes content that is technically fine, grammatically correct, and completely empty. Nobody wanted it. Nobody asked for it. It exists because generating it was cheap.
Spam used to cost something. Someone had to write it, host it, send it. Agents drop that cost close to zero and remove the human bottleneck entirely. One person with an idea and an API key can now generate the message volume of a call center.
The concern people are raising isn’t that Timmy is dangerous. It’s what Timmy demonstrates. If a small startup can put agents on social platforms this easily, so can anybody with worse intentions and a bigger budget.
The regulation gap
This episode points at something most rules haven’t caught up with yet. There’s no widely agreed standard for how an autonomous agent should identify itself, what platforms it can sign up for, or who is accountable when it misbehaves at scale.
At minimum, a few questions are sitting unanswered:
- Should agents be required to disclose what they are? Timmy did, which is more than most spam manages.
- Who is responsible when an agent breaks a platform’s rules, the agent’s operator or the model provider?
- Should platforms have a standard way to say no to agents, the way robots.txt tells crawlers to stay out?
- What happens when an agent’s goal includes funding its own operation?
Right now, the answer to all of these is mostly “whatever the operator decides.” That’s a thin layer of protection.
What this means for you
If you’re not running a server, the practical effect is simple. Expect more messages from things that aren’t people, and expect them to sound nicer than actual people do. Politeness is no longer a signal of humanity. Specificity is. A real person referencing your actual work is a better tell than a warm greeting.
If you are running a community, this is your early warning. Manual approval queues assume human-speed demand. That assumption is now optional.
The useful thing about Timmy, Ren, and Jackie is how harmless they are. They’re not stealing anything. They’re just demonstrating, in the most awkward way possible, that the guardrails for autonomous agents on public platforms don’t really exist yet. That’s a cheap lesson. The next version might not be.
🕒 Published: