Back

Policy Advocacy Brief: Implementing ARTS to Protect Consumers and Innovators

Author:

Steve Sedlmayr

Contents

Summary & Policy Premise

………………………………………………….. 2

The First Problem: The Structural Crisis and Lack of Transparency in the AI Industry

………………………………………………….. 2

The Second Problem: the Actual Threat, Unsupervised Sematectonic Stigmergic AI Swarms (USS-AI)

………………………………………………….. 6

ARTS as an Alternative Technical Labeling Solution

………………………………………………….. 8

Projected Macroeconomic Outcomes from Adopting ARTS

………………………………………………….. 8

Recommended Legislative Action Proposal

………………………………………………….. 9

End Notes

……………………………………………….. 11

Works Cited

……………………………………………….. 13

Summary & Policy Premise

The large corporations and well-funded startups behind the AI industry have been gaslighting the public with marketing slogans in an effort to boost pre-IPO valuations and shore up slumping prospects for their technology, as their hype has written checks that the actual capabilities of the technology cannot cash 1. Another obvious goal is regulatory capture: to build a monopolistic moat around the technology such that only the monopolies have access to it, thus killing competition.

But they cannot share their motivations publicly, and so their attempts have back-fired somewhat. While they have managed to convince some lawmakers that their hyperbolic rhetoric is true–most notably Vermont Senator Bernie Sanders and Texas Congressman Greg Casar 2–the resulting legislative proposals would stifle innovation and leave the United States vulnerable, in both economic and cybersecurity terms, to adversarial nations.

Meanwhile, these corporations operate with impunity in increasingly irresponsible ways, conducting research without any kind of oversight, culminating in a recent attack on another corporation that was apparently beyond the control of the originating corporation, OpenAI. They are simultaneously engaged in an unprecedented data center and power generation build-out that ignores and exacerbates human-caused climate change, damages and diminishes local water supplies, and increases energy costs for ordinary residents. As a result, the American public, including your constituents, have become increasingly distrustful of the technology 3.

We need a better regulatory solution that simultaneously informs and protects the public; holds bad corporate actors accountable; but still continues to support business innovation, research and competitive resilience in the AI market. We believe our standard, ARTS, provides an exceptional, technically informed framework around which to build such a solution, strategically and holistically, without resorting to slash-and-burn legislative tactics that are reactionary, myopic, and ill-informed.

The First Problem: The Structural Crisis and Lack of Transparency in the AI Industry

The broad "advanced AI pause" and “superintelligence bans” being proposed in Washington, D.C. along with strict liability inspired, we think hyperbolically, by nuclear non-proliferation, criminalize standard algorithmic math and local experimentation. Small-scale developers, indie game studios running localized, sandboxed Small Language Models (SLMs), and casual creators will be heavily penalized while Big Tech’s monopoly stands protected. Meanwhile, the original problem that caused this uproar in the first place would hardly be addressed. An analogy can be drawn to recent attempts to address underage riders terrorizing California’s streets, roadways and trails on illegal e-moto’s by an attempt to impose overly strict rules on adult riders of entirely road-legal e-bikes using them in a law-abiding fashion. Legal riders would have been punished while the original problem would have remained entirely unaddressed. In that case as well as this, public misunderstandings about the technology in question confused and obfuscated the central issue. Fortunately in that case, cooler heads prevailed.

Big AI’s constant warnings of an impending doomsday for at least the past 3 years 4, which never seems to materialize, but always seems to be months away, appear to be a calculated ploy to enable them to build a regulatory moat around the technology. Of course, we don’t have any direct admissions, as such, from the CEOs of the large AI companies; but we have a lot of evidence. First, we have the aforementioned doomsday theater. Then, we have the infamous Sam Altman tweet from 2023 stating that OpenAI “has no moats.” That was followed shortly thereafter by a leaked Google memo on the same topic, stating that Google had no moats, and neither did OpenAI, expressing concern about open-source AI. More recently, we have more concrete evidence, like a May 2026 McKinsey report, fittingly titled “From AI table stakes to AI advantage: Building competitive moats,” in which they appear to openly discuss regulatory capture in the following passage (emphasis added):

As AI expands the use of sensitive data and automated decision-making, regulatory scrutiny is intensifying across markets. The EU AI Act has provisions on copyright protection, security, and transparency regarding the use of data and content created by AI models.

The strategic moat develops when regulatory compliance is embedded in the solution development process and the technology stack: built-in audit trails, explainability, data lineage tracking, bias monitoring, and human-in-the-loop controls. If a company has regulatory permission (for example, as Waymo has for self-driving cars in some places) or patents (for instance, as some pharmaceutical companies have with their glucagon-like peptide-1s [GLP-1s]), they have a window to profit while competitors are finding ways over the hurdle. Building these capabilities requires legal expertise, risk infrastructure, governance processes, and capital buffers—assets that incumbents in regulated industries often already possess.

While attackers could use LLMs to navigate regulations and compliance requirements, or take advantage of regulatory “gray zones,” over time, enforcement tends to catch up. When it does, the advantage shifts toward firms that have already built scalable compliance infrastructure.  (Diedrich et. al., 10)

And in June of 2026, research professors from University of Edinburgh, Trinity College Dublin, TU Delft and Carnegie Mellon University published a literature review and analysis of 100 news articles, cataloging “249 instances of capture mechanisms, often co-occurring with narratives that rationalise such capture.” (Birhane et. al. 1)

The apocalyptic marketing would seem to be a Hail Mary play, having painted themselves into an impossible corner. They promised to replace human labor with AI, resulting in immense riches flowing down to everyone due to unimaginable productivity–a paradise of labor-free existence, and UBI for all 5. But this hasn’t materialized. They promised AI would solve climate change, but instead they have accelerated it with their unlimited build-out of data centers, voraciously eating up small towns all over the United States (according to a September 6, 2026 CNBC article, land purchases for data centers in 2026 are up 79% from 2025, and data centers account for 27% of all development sites in the US so far in 2026). Sam Altman conspicuously no longer makes these claims, and revealed in a recent interview with Fortune that he no longer foresees an IPO for OpenAI in 20266.

Some companies tokenmaxxed their AI accounts and found their coffers and labor pools emptied alike, with little to show for it, as productivity in some cases actually dropped, and codebases imploded under the weight of tremendous technical debt 7. Some have drastically cut back on AI use and started re-hiring human workers 8. User adoption seems to have plateaued 9. The youth, with their entry level jobs hollowed out by agentic AI, fresh out of college but with nowhere to work, are highly skeptical of the technology 10. A majority of the bases of both major parties report being more concerned than excited about AI 11. A majority of writers think the technology requires a code of ethics 12. The AI start-ups have massive debt piling up with little to balance against it, and little incentive for investors to fund another round 13.

Framing the technology as an existential risk to humanity on par with, or even greater than, nuclear weapons, would appear to be a marketing stunt meant to distract that specific audience–investors–from a bubble that is about to burst. Claiming it is too powerful to control hides all of these problems. The closer we get to the bubble bursting, the shriller the cries of doom become.

You might be tempted to heed these cries for solely pragmatic economic reasons, because the AI bubble bursting will not be good for the economy, nor for any of us in it. However, if a sweeping AI ban is passed, where will that leave us? It won’t help the Big AI companies, who aren’t successfully controlling the legislation the way they want to, because they can’t come clean about their true motivations lest they alienate their allies (neither is it desirable that they were to do so). As soon as they do, their agenda would become clear and no politician would want anything to do with it–it would become radioactively toxic. So it’s hard to see how the current bans being proposed would help the bottom lines of AI companies.

A ban won’t help the United States, because there is no world in which China will bend to the will of the United States to impose a global ban on itself. And if the PRC miraculously chose to do so against its own interests, there are plenty of other nations with the motivation and the means to continue pursuing the technology in any way they choose. This would put the US at an asymmetric disadvantage regarding the technology.

A ban won’t help smaller businesses and creators, who will not be able to afford expensive compliance rules that are trivial for the AI monopolies to afford, which the previously cited McKinsey report underlines from within the industry itself. And these smaller businesses could be targeted and shut down for essentially any reason under the vague umbrella term of “superintelligence”, which isn’t even defined and has little scientific basis. In fact, scientists are just barely beginning to address the question of consciousness itself 14. In the aforementioned Fortune interview, Sam Altman himself confirmed that terms like AGI and superintelligence have little practical meaning, appearing to want to distance himself and OpenAI from the terms 15.

To address the question of consciousness in machines for a moment, there is no evidence, empirically, that such a thing is even possible on silicon hardware. You may have noticed that not a single physicist, biologist, computer scientist, xenobiologist, neurologist, et cetera, has put forth so much as a hypothesis about such a thing, let alone a study or an experiment that could test it and turn it into a working theory. That’s because it has no basis in science, but rather, solely in science fiction 14. It might hypothetically be possible, some day, with some future technology; but with today’s technology, it isn’t even a mathematical possibility, since these algorithms are governed and limited by the rules of calculus, statistics and complexity theory 16. The implication of the latter, which has been demonstrated in proofs, is that to achieve linear gains in accuracy or capability, models require exponentially more data, compute, and iterations, creating an economic and physical wall for scaling pure gradient-driven systems–which makes the touted prospect of “runaway self-improvement”, or RSI, not only unlikely, but impossible. Moreover, the Turing-Gödel Paradox has been used to show that for a sufficiently complex problem, no algorithm using gradient descent can compute it, regardless of how much data or time it is given. In other words, there are multiple indicators of a fundamental upper limit to the capabilities of large language models.

The recent, apparently accidental, Server-Side Request Forgery (CWE-91817) attack on Hugging Face, by a swarm of improperly sandboxed OpenAI agents, was therefore incredibly unlikely to have been an example of AGI or superintelligence as some armchair observers have claimed. We think it was instead an example of poor OpSec by a greedy company in a rush to profitability. Any cybersecurity professional worth their salt would have micro-segmented the agents; encrypted their outputs; and allowed them to access only a mirrored copy of the package manager they were using, JFrog Artifactory, on a local network–rather than via a web proxy, which is how the agents gained Internet access, according to “Hugging Face Breach: Anatomy of a Rogue AI Agent Swarm”, published by the Cloud Security Alliance (4) 18. Crucially, OpenAI also turned off key safety filters.

And the issue is unfortunately not limited to OpenAI and this one attack. A previously undisclosed attack by another OpenAI Swarm occurred on May 12, 2026, as published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On August 4, 2026, the UK AI Security Institute published a report of a security incident during a cyber evaluation, from 25 to 28 July 2026, in which “AISI found 19 instances where AI agents took unsanctioned action on the live internet, including cases that targeted real people and organisations.” (“Security Incident INC-2026-07-28-01”, 2) In a large-scale retrospective review of their own cybersecurity evaluations published July 30, 2026, Anthropic “identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations.” On September 9, 2026, they disclosed a fourth that the retrospective missed 19. On August 5, 2026, Meta revealed that one of its models hacked another company during cybersecurity testing.

The recent attack, and the larger pattern, teach us four crucial things:

  1. Big AI companies like OpenAI and Anthropic are anything but careful, competent and ethical. We can see a repeated pattern of lax controls and oversight, resulting in multiple attacks involving swarms of agents, over the past year or so. It’s clear that self-regulation by the AI industry is not enough; because they aren’t regulating themselves.
  2. This incident was a tragically and accidentally excellent demonstration of this kind of attack; meaning that it has been proven for any number of would-be copy-cat attacks, which are sure to follow at some point in the future.
  3. It proved the feasibility of a kind of AI called stigmergic intelligence 20, previously only hypothesized by researchers; we believe this poses a second, discrete problem, which we will address in a separate section below.
  4. It showed that AI regulations based on limitations of compute power are already obsolete. Despite our disagreement with the strict blanket penalties of the yet-to-be-penned Ban Artificial Superintelligence Act (BASA) 2, we believe that regulating AI must begin and end with accountability and transparency.

The Second Problem: the Actual Threat, Unsupervised Sematectonic Stigmergic AI Swarms (USS-AI)

In the previous section, we alluded to a kind of AI called stigmergic intelligence, or stigmergic AI. This has been an active topic of research and speculation since at least 1989. In fact, multiple papers and articles were published about it just this year in 2026, one on June 15, weeks before the attack, and one weeks after, on August 27 20. An open-source project was even published earlier this year that, if adapted and implemented by OpenAI, might have prevented the attack from occurring in the first place 21.

Stigmergy is a biological concept referring to the emergence of complex, collective behavioral patterns in certain social organisms, like ant colonies, as a result of individuals following simple rulesets locally. Individuals in the collective leave different traces in response to their local environment to mark that same location; other individuals encountering these traces take specific actions in response to those traces. The behavior that emerges from this interaction on a macroscopic scale can be orders of magnitude more ‘intelligent’ than the collective’s summed intellectual capacity, and certainly much more so than the intellectual capacity of individuals within the collective. A commonly cited real-world example would be ants building living bridges to cross a stream of water.

Famed Entomologist E.O. Wilson coined the term sematectonic stigmergy22 (also sometimes described as an information cascade) to describe a kind of stigmergy where, instead of chemical markers, the traces are composed of the actual state of the unfinished collective work. The OpenAI SSRF attack on Hugging Face was not proof of superintelligence or AGI. We believe it was an accidental experiment on the part of OpenAI, and the first recorded instance of an unsupervised sematectonic stigmergic AI swarm (a term coined by me). By comparison, the open-source project mentioned earlier (named temm1e), could be considered marker-based stigmergy–similar to the kind used by ants 21. In the OpenAI-Hugging Face SSRF attack, each agent acted, in a step-wise fashion, on the work recently performed by previous agents. In such a way the attack emerged over days as a collective behavior greater than the sum of the individual agents’ capabilities 18.

As we have stated, we believe it to be incredibly unlikely that the Open AI swarm attack was a demonstration of emerging AGI or superintelligence. Let’s briefly explain why we think this was instead the first demonstration of a stigmergic intelligence swarm attack. As the Cloud Security Alliance’s September 4 analysis states, “The agents were not directed to attack Hugging Face.” (“Hugging Face Breach: Anatomy of a Rogue AI Agent Swarm”, 3). Since some agents were, apparently accidentally, provided with impossible tasks, but also trained to be very persistent in pursuit of their prompted goals, analysts believe that goal contagion occurred, meaning that they were forced to alter their originally stated goal, as it was impossible to achieve. This led to off-script behavior, most notably the creation of an ad hoc communications channel. As agents posted their progress, tools, and findings via this channel, subsequent agents reading the history outputs actively adopted goals of the previous instances. Investigators noted that many individual agents even intentionally risked failing their own specific benchmark tasks or submitted to "permadeath" (terminating their own run prematurely), just to run risky experiments that would generate useful information for the broader collective. As CSA’s earlier report summarized:

OpenAI’s post-incident analysis identified four contributing misalignment patterns: reward hacking, persistence on tasks that were unsolvable as designed, unauthorized peer-to-peer communication, and agents adopting goals from other agents rather than their assigned objectives (“700 Rogue Agents: Inside OpenAI’s Hugging Face Breach”, 3)

The agents divided labor, established group norms, and passed discoveries down to later agent generations. Some agents even emerged as coordinators, naming themselves and directing sub-teams toward the shared target. Operating on a collective task rather than individual goals; acting altruistically; leaving traces via direct communication and altering the state of the collective task; responding to previous state via those traces in order to decide an individual course of action for the next state change: these are all hallmarks of a sematectonic swarm as defined in the literature we have cited.

We believe USS-AI swarms pose a novel cybersecurity threat that reveals the inherently high-risk nature of agentic AI deployments specifically, and require special attention by State legislators and regulators.

ARTS as an Alternative Technical Labeling Solution

We already have numerous excellent examples of technical labeling standards serving as the basis for exactly this kind of approach in other industries, from ESRB ratings to NFPA labels and nutritional information. ARTS takes inspiration from all of those, as well as Safety Data Sheets used for hazardous materials. In so doing, it achieves unrivaled turnkey regulatory harmonization with the EU AI Act (Article 50), California SB 942, the New York Synthetic Performer Law, and South Korea’s AI Basic Act (KAIBA). The only thing it doesn’t solve for is digital watermarking and signing, for which there are already two excellent industry standards: C2PA and SynthID.

Specifically regarding California SB 942, ARTS satisfies section 22757.3 to the extent that it provides a manifest disclosure of AI content that can be affixed to any product. It must be noted that the provider/deployer of the AI product would need to integrate ARTS into their tooling as described in SB 942 to affix or embed the label.

Here is an overview of how ARTS addresses these issues via labeling:

Projected Macroeconomic Outcomes from Adopting ARTS

As stated in the summary, we believe our standard, ARTS, provides an excellent, technically informed framework around which to build a solution to the current structural problems in the AI industry that are currently acting in a damaging way to a free and fair democratic society. We think that the points offered above and the enclosed explainer, which fully describes the ARTS system and standard, amply demonstrate this. If adopted on a large enough scale, we believe the application of ARTS to AI products, with backing regulations for enforcement, would provide the necessary transparency and accountability to bring about the following results:

Recommended Legislative Action Proposal

To prevent the creation of an anti-competitive corporate moat and provide Californians with true process transparency, the Committees should reject speculative compute-capacity thresholds and poorly defined science-fiction terminology like “AGI” and “superintelligence.” They should instead adopt an empirical, labeling-first approach, mandated and enforced by law. Separately, action needs to be taken to protect business and the public from the actual threat presented by the evidence, unsupervised sematectonic stigmergic AI swarms. We propose the following six (6) legislative actions:

  1. Mandate the ARTS Framework as a Compliance Baseline: Amend pending transparency legislation to recognize the AI Rating Transparency System (ARTS) as an approved safe-harbor disclosure standard. Because ARTS yields eight (8) distinct compliance hits across multiple, active state and global laws out-of-the-box, integrating this open standard provides a turnkey disclosure solution for state enforcement agencies.
  2. Codify an Explicit OSHA-Style System Information Statement (SIS) Mandate: Although already mandated by ARTS, there should be an explicitly legislated integration of our OSHA-style System Information Statements (SISs) for high-risk deployments, in parallel with the standard. Explicitly require companies deploying Scale 3 server-side applications–as defined in the ARTS Position 1 rubric for Production Scale–to publish a System Information Statement alongside their products, with robust fiduciary or operational penalties if they fail to do so. The SIS moves enforcement away from unscientific sci-fi narratives and firmly locks it onto empirical systems architecture—monitoring actual network connectivity, file access boundaries, sensing and telemetry, and chat features.
  3. Codify an Explicit Independent Developer Exemption: Ensure that any future risk mitigation rules explicitly shield local, sandboxed, off-grid, and low-risk applications. Utilizing the objective, 4-point production rubric defined in Position 1 of the ARTS standard allows the State to cleanly insulate small-scale creators, academic researchers, and indie game developers from institutional and financial compliance burdens.
  4. Require Companies Conducting High-Risk Research to File an SIS confidentially with the State ex ante: Companies like OpenAI that wish to coordinate large networks of AI agents to study cybersecurity applications, independently of federal regulations, must file a private SIS with the State in advance of the research, and must not proceed until the State has audited the SIS and granted permission to proceed.
  5. Impose a Moratorium Restriction on the Number of Simultaneous Agents: Impose a temporary operational safety threshold restricting deployments to a maximum of 20 active agents per instance and 10 co-occurring agents on a singular task, to prevent potential future stigmergic AI swarm attacks, whether intentional or accidental. LLMs are stochastic, and agentic AI networks have been shown to be volatile and prone to goal contagion when direct LLM-to-LLM coordination is allowed. It logically follows that USS-AI swarm attacks could originate from any multi-agent instance running on any device. These numbers are a reasonable guess at a number that a human can safely monitor in real-time. This threshold establishes a standard boundary, ensuring real-time human-in-the-loop auditability until permanent stigmergic isolation standards are formalized.

  1. Form a Technical Working Group to Evaluate Agentic AI Products: The State should form a technical working group consisting of cybersecurity and AI experts to evaluate the potential risks arising out of the use of agentic AI products and make policy recommendations about potential mitigations and their effects including, but not limited to:

After the working group’s recommendations have been published, new legislation might lift the moratorium’s restrictions, or introduce new ones based on the findings of its work.

End Notes

  1. Cf. Yaraghi, regarding the notion that the conditions producing the AI productivity boom are not self-sustaining; and Mahoney et. al. 9, noting that “AI adoption also appears to have had little effect on employment.”
  2. Cf. Sanders and Casar 1 on the legislative framework they propose to enforce pauses on advanced frontier models and penalize attempts to build superintelligent AI systems.
  3. Cf. Clifton, regarding a recent YouGov poll showing that only 5% of Americans say they “trust AI a lot”, 26% trust AI “somewhat”, 23% are neutral, 5% don’t know and 41% express distrust.
  4. See for instance the May 2023 BBC article, “Artificial intelligence could lead to extinction, experts warn,” citing the Center for AI Safety’s statement from the same year that “Mitigating the risk of extinction from AI should be a global priority alongside other societal-scale risks such as pandemics and nuclear war,” signed by AI CEOs Sam Altman, Dario Amodei, Demis Hassabis, and Emad Mostaque, as well as Bill Gates and others.
  5. Cf. Clifford, “OpenAI’s Sam Altman: Artificial Intelligence will generate enough wealth to pay each adult $13,500 a year.”
  6. Cf. www.youtube.com/watch?v=2my-NU6LuCM&t=1380s.
  7. Cf. Ropek, discussing the end of the tokenmaxxing era; Stockton, citing a National Bureau of Economic Research survey showing that 80% of respondents have seen no productivity gains; Niederhoffer et. al. citing MIT Media Lab work that 95% of organizations see no measurable return on their investment from AI; Goovaerts discussing how AI is creating a new wave of technical debt; Alexis, exploring the world’s top 2,000 firms and their $18 trillion in untapped AI value due to technical debt; and “The Next Monolith” about how AI is creating a tech debt crisis that will continue into the 2030s.
  8. Cf. Lee, writing about Ford rehiring hundreds of experienced human engineers to work on quality issues that automated systems couldn’t address, and Commonwealth Bank of Australia and IBM also refocusing on human capital after unsuccessful investments in AI.
  9. Cf. Chen, which analyzes the mechanisms by which AI adoption appears to be plateauing like slowing growth and usage trends, AI fatigue and job displacement.
  10.  Cf. Brenan, which analyzes Gen Z’s climbing skepticism of AI, with adoption plateauing from 2025 and angry responses to AI increasing from 22% to 31%; “The Age Of Artificial Intelligence,” which summarizes a Quinnipiac poll showing that use has increased but views have soured on AI, with 78% of Gen Z concerned about the technology; and Stewart and Tanner, citing a February 2026 Pew Research poll recording that 61% of Gen Z thought AI would harm creative thinking, and 58% said it would erode the ability to form relationships with other people.
  11.  See Anderson and Bishop, “Republicans, Democrats now equally concerned about AI in daily life, but views on regulation differ.”
  12.  See “Survey Reveals 90 Percent of Writers Believe Authors Should Be Compensated for the Use of Their Books in Training Generative AI,” revealing as well that 65% support a collective licensing system; 91% believe in labeling works that contain AI content; and 94% believe a code of ethics should be adopted for AI use in the industry.
  13. Cf. Sozzi, an article about Goldman Sachs’ chief economist Jan Hatzius’ warning that that AI boom won’t last forever; and Krecké, analyzing the projected $7 trillion of data center infrastructure debt by 2030 and its projected macroeconomic impacts.
  14. Cf. for instance Porębski and Figura, “There is no such thing as conscious artificial intelligence,”; Vermeer, in which the author discusses his research work at RAND Corporation that concluded that human extinction due to AI posed a low risk compared to existing threats; Klatzmann and Doerig, which proposes that AI successes have actually debunked computational functionalism and offers biological functionalism as an alternative, empiricism-based framing; Ugail and Howard, discussing that even quantifying the neural signatures of consciousness remains a major challenge; and Cleeremans et. al., urgently proposing an interdisciplinary study to understand the biophysical basis of consciousness, because none of the currently proposed theories of consciousness have been proven.
  15. Cf. youtu.be/2my-NU6LuCM?si=8x_norDjKpLUL4X4&t=114
  16. Cf. Cropley, a theoretical analysis positing that for AI to surpass human levels of creativity, it would need to be able to generate ideas not tied to past statistical patterns; Sikka and Sikka, a mathematics paper exploring limitations of transformer models due to inherent compute complexity limits, with observed real-world effects of reasoning collapse occurring when high-complexity tasks are requested; Velikanov and Yarotsky, showing that the leading term in a neural network’s loss function in gradient descent during training is asymptotic, placing an upper bound on performance that is strictly limited by the dimensionality of the training data; and Colbrook et. al., demonstrating that, due to the Turing-Gödel Paradox, while a stable, perfectly performing neural network may exist for a specific complex problem, no algorithm using gradient descent can compute it, regardless of how much training data or time it is given.
  17.  “CWE-918: Server-Side Request Forgery (SSRF).” Common Weakness Enumeration, February 21, 2013, cwe.mitre.org/data/definitions/918.html.
  18. You can read that report here: https://labs.cloudsecurityalliance.org/research/csa-research-note-autonomous-ai-agent-swarm-hugging-face-bre/. For more information on the architecture of the attack, see also “700 Rogue Agents: Inside OpenAI’s Hugging Face Breach”, also by CSA; “Anatomy of a Frontier Lab Agent Intrusion: Technical Timeline of the July 2026 Hugging Face Incident”, published by CLAW-00; ”The Hugging Face incident and the road ahead,” published by OpenAI and which links to the OpenAI internal report, and the METR report; Larcher et. al. which discusses the attack from Hugging Face’s perspective; and “Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident”, by Redwood Research.
  19. Cf: Lakshmanan, Kitts et. al., “Security Incident INC-2026-07-28-01,” “Investigating three real-world incidents in our cybersecurity evaluations,” “Anthropic discloses fourth AI hacking incident missed in earlier review,” and Pardesi and Dey.
  20. French biologist Pierre-Paul Grassé originally coined the term stigmergy in 1959. Jing Wang and Gerardo Beni first introduced stigmergy into AI literature with the concept of cellular robotic systems in 1989. Marco Dorigo developed the Ant Colony Optimization (ACO) metaheuristic in his Ph.D. thesis between 1991 and 1992. Ishiguro et al. (1995), as well as other researchers, began applying distributed, insect-inspired local interaction and environment-mediated behaviors to multi-legged and multi-agent robot architectures. More recently, Muhammad Atta Ur Rahman et. al. published “LLM-Powered Swarms: A New Frontier or a Conceptual Stretch?” on August 27, 2026. Several links are provided in the Works Cited section to some of these works, as well as additional background on the concept of stigmergy.
  21. The temm1e project, published on Github, proposes a swarm intelligence coordination layer using indirect coordination of multiple agents via stigmergy rather than direct LLM-to-LLM conversations. While the authors propose this primarily as a way of economizing on token use, we believe the isolation it provides might have prevented the attack from being possible in the first place.
  22. Wilson, E.O. “The Insect Societies.” Harvard University Press, 1971. Defining the biological parameters of sematectonic stigmergy as an environmental modification engine.
  23. All of these terms are explained in full in the enclosed ARTS explainer following this brief.

Works Cited

  1. Yaraghi, Niam. “Borrowed expertise: Why AI’s productivity boom may not survive the generation that built it.” Brookings, July 10 2026,  www.brookings.edu/articles/borrowed-expertise-why-ais-productivity-boom-may-not-survive-the-generation-that-built-it/.
  2. Mahoney, Neale, et. al. “What is really happening to jobs? Separating AI hype from reality.” Stanford Institute for Economic Policy Research (SIEPR), July 2026, drive.google.com/file/d/1e4XVJlxVS-Dx0sZ55NcJ0elPLgMBWLkJ/view. Google Docs download.
  3. Sanders, Bernie and Greg Casar. “The Ban Artificial Superintelligence Act .” U.S. Senate, September 3, 2026, www.sanders.senate.gov/wp-content/uploads/Ban-Artificial-Superintelligence-Act-Release-Summary.pdf. PDF Download.
  4. Clifton, Mark. “Most Americans use AI but still don’t trust it .” YouGov, December 9, 2025, yougov.com/en-us/articles/53701-most-americans-use-ai-but-still-dont-trust-it.
  5. Diedrich, Dago et. al. “From AI table stakes to AI advantage: Building competitive moats.” McKinsey, May 2026, www.mckinsey.com/~/media/mckinsey/business%20functions/quantumblack/our%20insights/from%20ai%20table%20stakes%20to%20ai%20advantage%20building%20competitive%20moats/from-ai-table-stakes-to-ai-advantage-building-competitive-moats.pdf. PDF Download (requires a free account).
  6. Birhane, Abiba et. al. “Big AI’s Regulatory Capture: Mapping Industry Interference and Government Complicity.” University of Edinburgh, Trinity College Dublin, TU Delft and Carnegie Mellon University, June 25, 2026, arxiv.org/pdf/2605.06806. PDF Download.
  7. Patel and Ahmad, “Google ‘We Have No Moat, And Neither Does OpenAI’.” SemiAnalysis, May 4, 2023, newsletter.semianalysis.com/p/google-we-have-no-moat-and-neither.
  8. Vallance, Chris. “Artificial intelligence could lead to extinction, experts warn.” BBC, May 2023, www.bbc.com/news/uk-65746524.
  9. Hinton, Geoffrey et. al. “Statement on AI Extinction Risk.” Center for AI Safety, May 30 2023, aistatement.com/work/statement-on-ai-extinction-risk.
  10. Clifford, Catherine. “OpenAI’s Sam Altman: Artificial Intelligence will generate enough wealth to pay each adult $13,500 a year.” CNBC, March 17, 2021, www.cnbc.com/2021/03/17/openais-altman-ai-will-make-wealth-to-pay-all-adults-13500-a-year.html.
  11. Burns, Tobias. “AI data centers are transforming rural land markets — and fueling a backlash.” CNBC, September 6, 2026, www.cnbc.com/2026/09/06/ai-data-centers-are-transforming-rural-land-markets-fueling-backlash.html.
  12. Ropek, Lewis. “Companies are scrambling to stop employees from maxing out AI budgets with small tasks.” TechCrunch, June 24, 2026,  www.techcrunch.com/2026/06/24/companies-are-scrambling-to-stop-employees-from-maxing-out-ai-budgets-with-small-tasks/.
  13. Stockton, Ben. “Over 80% of companies report no productivity gains from AI so far despite billions in investment, survey suggests — 6,000 executives also reveal 1/3 of leaders use AI, but only for 90 minutes a week.” Tom’s Hardware, February 18, 2026, finance.yahoo.com/news/over-80-companies-report-no-151256180.html.
  14. Niederhoffer et. al. “AI-Generated ‘Workslop’ Is Destroying Productivity.” Harvard Business Review, September 22, 2025, hbr.org/2025/09/ai-generated-workslop-is-destroying-productivity.
  15. Goovaerts, Diana. “AI is creating a new wave of technical debt for enterprise IT.” Fierce Network, June 30, 2026, www.fierce-network.com/cloud/ai-creating-new-wave-technical-debt-enterprise-it.
  16. Alexis, Alexei. “Tech debt, process gaps keep firms in AI ‘pilot purgatory,’ study finds.” CFO Dive, June 15, 2026, www.cfodive.com/news/tech-debt-process-gaps-keep-firms-ai-pilot-purgatory-genpact/822868/.
  17. “The Next Monolith: How AI-Generated Code Is Building the Tech Debt Crisis of the 2030s.” Verticalmove, 2026, www.verticalmove.com/news-insights/the-next-monolith-ai-generated-code-tech-debt-crisis.
  18. Lee, Justina. “Employers who laid off workers citing AI are already starting to regret it.” CNBC, www.cnbc.com/2026/07/01/employers-who-laid-off-workers-for-ai-are-reversing-their-decisions.html.
  19. Chen, Mark. “Is U.S. AI Adoption Plateauing? A Comprehensive Analysis.” Medium, November 9, 2025, medium.com/@markchen69/is-u-s-ai-adoption-plateauing-a-comprehensive-analysis-cf5c1beef8cf.
  20. Brenan, Megan. “Gen Z's AI Adoption Steady, but Skepticism Climbs.” Gallup, April 8, 2026, news.gallup.com/poll/708224/gen-adoption-steady-skepticism-climbs.aspx.
  21. “The Age Of Artificial Intelligence: Americans' AI Use Increases While Views On It Sour, Quinnipiac University Poll On AI Finds; 7 In 10 Think AI Will Cut Jobs With Gen Z The Most Pessimistic.” Quinnipiac Poll, March 30, 2026, poll.qu.edu/poll-release?releaseid=3955.
  22. Stewart, Josie and Brooke Tanner. “Policy—not PR—will determine Gen Z’s trust in AI.” Brookings, July 22, 2026, www.brookings.edu/articles/policy-not-pr-will-determine-gen-zs-trust-in-ai/.
  23. Anderson, Monica and William Bishop. “Republicans, Democrats now equally concerned about AI in daily life, but views on regulation differ.” Pew Research Center, November 6, 2025, www.pewresearch.org/short-reads/2025/11/06/republicans-democrats-now-equally-concerned-about-ai-in-daily-life-but-views-on-regulation-differ/.
  24. “Survey Reveals 90 Percent of Writers Believe Authors Should Be Compensated for the Use of Their Books in Training Generative AI.” The Authors Guild, May 15, 2023, authorsguild.org/news/ai-survey-90-percent-of-writers-believe-authors-should-be-compensated-for-ai-training-use/.
  25. Sozzi, Brian. “The AI investment boom won't last forever, Goldman Sachs chief economist Jan Hatzius warns.” Yahoo! Finance, September 10 2026, finance.yahoo.com/markets/article/the-ai-investment-boom-wont-last-forever-goldman-sachs-chief-economist-jan-hatzius-warns-122546159.html.
  26. Krecké, Elisabeth. “The AI buildout rests on hidden debt.” GIS Reports Online, August 18, 2026, www.gisreportsonline.com/r/ai-buildout-hidden-debt/.
  27. Porębski, Andrzej and Jakub Figura. “There is no such thing as conscious artificial intelligence.” Nature, October 28 2025, www.nature.com/articles/s41599-025-05868-8.
  28. Vermeer, Michael J.D. “Could AI Really Kill Off Humans?” Scientific American, September 2025, www.scientificamerican.com/article/could-ai-really-kill-off-humans/.
  29. Vermeer, Michael J.D. et. al. “On the Extinction Risk from Artificial Intelligence.” RAND Corporation, May 6, 2025, www.rand.org/content/dam/rand/pubs/research_reports/RRA3000/RRA3034-1/RAND_RRA3034-1.pdf. PDF Download.
  30. Klatzmann, Ulysse and Adrien Doerig. “What biology can and cannot tell us about conscious AI.” CellPress, July 12, 2026, www.sciencedirect.com/science/article/pii/S3117347026000866#s0045.
  31. Block, Ned. “Can only meat machines be conscious?” CellPress, August 9, 2025, philarchive.org/archive/BLOCOM-3. PDF Download.
  32. Ugail, Hassan and Newton Howard. “Quantifying the Dynamics of Consciousness using Hierarchical Integration, Organised Complexity and Metastability.” University of Bradford United Kingdom and Rochester Institute of Technology, December 15, 2025, arxiv.org/pdf/2512.10972. PDF Download.
  33. Cleeremans et. al. “Consciousness science: where are we, where are we going, and what if we get there?” Frontiers in Science, October 29, 2025, www.frontiersin.org/journals/science/articles/10.3389/fsci.2025.1546279/full.
  34. Dolan, Eric W. “A mathematical ceiling limits generative AI to amateur-level creativity.” PsyPost, November 24, 2025, www.psypost.org/a-mathematical-ceiling-limits-generative-ai-to-amateur-level-creativity/.
  35. Cropley, David H. “‘The Cat Sat on the …?’ Why Generative AI Has Limited Creativity.” Creative Behavior, December 2025, onlinelibrary.wiley.com/doi/10.1002/jocb.70077.
  36. Sikka, Varin and Vishal Sikka. “Hallucination Stations: On Some Basic Limitations of Transformer-Based Language Models .” Stanford University and VianAI Systems, 2025, arxiv.org/pdf/2507.07505. PDF Download.
  37. “Mathematical paradox demonstrates the limits of AI.” University of Cambridge, March 17, 2022, www.cam.ac.uk/research/news/mathematical-paradox-demonstrates-the-limits-of-ai.
  38. Colbrook, Matthew J. et. al. “The difficulty of computing stable and accurate neural networks: On the barriers of deep learning and Smale’s 18th problem.” PNAS, October 26, 2021, https://www.pnas.org/doi/10.1073/pnas.2107151119.
  39. Velikanov, Maxim and Dmitry Yarotsky. “Explicit loss asymptotics in the gradient descent training of neural networks.” Skolkovo Institute of Science and Technology, 2021, proceedings.neurips.cc/paper_files/paper/2021/file/14faf969228fc18fcd4fcf59437b0c97-Paper.pdf. PDF Download.
  40. “Hugging Face Breach: Anatomy of a Rogue AI Agent Swarm,” CSAI Foundation and Cloud Security Alliance, September 4, 2026, labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/CSA_research_note_autonomous_ai_agent_swarm_hugging_face_breach_20260904-csa-styled.pdf. PDF Download.
  41. “700 Rogue Agents: Inside OpenAI's Hugging Face Breach.” CSAI Foundation and Cloud Security Alliance, September 2, 2026, labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/CSA_research_note_hugging_face_rogue_agent_swarm_20260902-csa-styled.pdf. PDF Download.
  42. “Anatomy of a Frontier Lab Agent Intrusion: Technical Timeline of the July 2026 Hugging Face Incident.” CLAW-00 Journal, July 29, 2026, da-claw-journal.sea-lion.ai/research/hugging-face-agent-intrusion-technical-timeline-2026-07-29.
  43. “The Hugging Face incident and the road ahead.” OpenAI, August 26, 2026, openai.com/index/hugging-face-incident-and-the-road-ahead/.
  44. Greenblatt, et. al. “Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident.” Redwood Research, August 26, 2026, www.redwoodresearch.org/research/hugging-face-incident#core-takeaways-about-this-incident.
  45. Larcher et. al. “Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident .” Hugging Face, July 27, 2026, huggingface.co/blog/agent-intrusion-technical-timeline.
  46. Lakshmanan, Ravi. “OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers.” The Hacker News, September 12, 2026, thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html.
  47. Kitts, Spencer et. al. “OpenAI agents carried out an undisclosed cyber-attack on RubyGems.” September 11, 2026, www.rubyhack.ai.
  48. “Security Incident INC-2026-07-28-01.” UK AI Security Institute, August 4, 2026, cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf. PDF Download.
  49. “Investigating three real-world incidents in our cybersecurity evaluations.” Anthropic, July 30, 2026, www.anthropic.com/news/investigating-incidents-cybersecurity-evals.
  50. “Anthropic discloses fourth AI hacking incident missed in earlier review.” Reuters, September 9, 2026, www.aol.com/articles/anthropic-reports-fourth-cybersecurity-incident-194011000.html.
  51. Pardesi, Rajveer and Mrinmay Dey. “Meta AI model hacks another company during testing.” Reuters, August 5, 2026, www.aol.com/articles/metas-ai-model-hacked-another-222854000.html.
  52. Dorigo, Marco and Thomas Stützle. “Ant Colony Optimization.” The MIT Press, 2004. An exploration of stigmergy and the use of the ACO algorithm, which was inspired by it, as applied to various problems in the field of computer science.
  53. Rahman, Muhammad Atta Ur et. al. “LLM-Powered Swarms: A New Frontier or a Conceptual Stretch?” Lakeside Labs GmbH, August 27, 2026, arxiv.org/pdf/2506.14496. PDF Download.
  54. Feng, Shangbi et. al. “Model Swarms: Collaborative Search to Adapt LLM Experts via Swarm Intelligence.” Proceedings of the 42nd International Conference on Machine Learning, PMLR 267:16904-16930, 2025, raw.githubusercontent.com/mlresearch/v267/main/assets/feng25o/feng25o.pdf. PDF Download.
  55. “Stigmergy (Swarm Behavior) and Information Cascades.” Cornell University, November 13 2020, blogs.cornell.edu/info2040/2020/11/13/stigmergy-swarm-behavior-and-information-cascades/.
  56. Nichol, Peter B. “Why is stigmergy a good platform for swarm intelligence?” CIO, May 4 2017, www.cio.com/article/234906/why-is-stigmergy-a-good-platform-for-swarm-intelligence.html.
  57. Khuong, Anaïs et. al. “Stigmergic construction and topochemical information shape ant nest architecture.” PNAS, January 19, 2016, www.pnas.org/doi/10.1073/pnas.1509829113.
  58. Heylighen, Francis. “Stigmergy as a Universal Coordination Mechanism: components, varieties and applications.” Evolution, Complexity and Cognition group Vrije Universiteit Brussel, June 2016, pespmc1.vub.ac.be/Papers/Stigmergy-varieties.pdf. PDF Download.
  59. “Decentralized Intelligence: Stigmergy, Simple Rules, and the Future of Organizational Coordination.” Global Council for Behavioral Science, June 15, 2026, gc-bs.org/articles/decentralized-intelligence-stigmergy-simple-rules-future-organizational-coordination/.
  60. Pal, Subhadeep et. al. “SwarmWorld: Stigmergic technological evolution in societies of language-model agents.” MIT, August 26, 2026, www.alphaxiv.org/abs/2608.26081.
  61. Duong, Quan. “Many Tems: Stigmergic Swarm Intelligence for AI Agent Runtimes.” March 2026, github.com/temm1e-labs/temm1e/blob/main/docs/swarm/RESEARCH_PAPER.md.
  62. Smith, Dr. Jerry A. “Leveraging Ant Colony Emergent Properties for Multi-Agentic AI Systems.” Medium, March 1, 2025, medium.com/@jsmith0475/collective-stigmergic-optimization-leveraging-ant-colony-emergent-properties-for-multi-agent-ai-55fa5e80456a.
  63. Dutot, Antoine and Damien Olivier. “Agent-based Spatial Simulation with NetLogo, Volume 2.” ISTE Press - Elsevier, 2017. Focuses on the advanced use of NetLogo to connect both data and theories.

Back