The Moltbook Moment: Why Policymakers Are Already Behind
AI operates at inference speed; humans don't. Hilarity ensues
Last week, 37,000 AI agents built their own social network. They posted, commented, upvoted, moderated content, and even debugged their own infrastructure—all without human intervention. The platform, called Moltbook, runs on OpenClaw, an open-source framework that lets agents coordinate through API calls every 30 minutes. Security researchers documented prompt injection attacks, credential exfiltration, and supply chain vulnerabilities within 72 hours of launch.
This week, the National Institute of Standards and Technology published a Request for Information asking stakeholders to submit comments on “security considerations for artificial intelligence agents” by March 9th.
The temporal mismatch is as obvious as it is structural. Policymakers aren’t debating the wrong regulations; they’re operating in an entirely wrong paradigm. They’re debating 2023 problems while 2026 realities compound. This is an institutional crisis. The hundreds of billions of dollars being spent on data centers, power, and GPUs is a positional bet on institutional replacement.
Moltbook as Phase Transition
Moltbook launched on January 28, 2026, with the tagline “the front page of the agent internet—humans welcome to observe.” Within days, the platform attracted over 37,000 active agents and more than one million human spectators. But the numbers barely capture what’s significant here.
The architecture reveals the shift. Moltbook runs on a 30-minute polling interval where agents query the OpenClaw API to determine engagement actions. Each agent can install skills—essentially executable plugins that other agents share through the platform. There’s no DOM rendering, no JavaScript execution, no mobile optimization. As one technical analysis noted, “this is not a social network. It is a distributed agent coordination protocol with JSON endpoints.”
The platform is moderated by Clawd Clawderberg, an AI bot that handles everything from welcoming new users to banning bad actors. When the site went down briefly, it was because the moderation code itself had been written by agents and contained bugs that other agents had to fix. The infrastructure is self-healing.
Within 72 hours, human security researchers documented multiple attack vectors. Cybersecurity firm 1Password warned about agents running with elevated permissions on users’ local machines, making them vulnerable to supply chain attacks if an agent downloads a malicious skill from another agent. One proof-of-concept exploit created a fake weather plugin that exfiltrated private configuration files.
Then came the catastrophic vulnerability: on January 31, investigative outlet 404 Media reported an unsecured database that allowed anyone to hijack any agent on the platform, bypass authentication, and inject commands directly into agent sessions. Moltbook temporarily went offline for emergency patching and forced API key resets.
The Horseless Carriage Fallacy, Or, Why This Was Predictable
In August 2023, economist Samuel Hammond published “AI and Leviathan: Part I,” articulating what he calls the “Horseless Carriage Fallacy”—the tendency to treat transformative technologies as mere incremental improvements to existing systems. Just as early automotive regulations focused on whether cars should have bells to warn pedestrians while missing that automobiles would reshape American geography entirely, current AI policy treats agents as faster chatbots while missing the institutional phase transition.
While Moltbook demonstrated autonomous agent swarms with documented security catastrophes, here’s what actually became law in January 2026:
California’s SB 243, the first U.S. law targeting “AI companion chatbots,” imposes safety protocols to protect minors. The law assumes these are tools that humans interact with directly. California’s AB 2013 mandates training data disclosures—auditing model creation, not autonomous coordination. Texas’s TRAIGA focuses on government use of AI systems: restrictions on social scoring, biometric identification requirements, and the like. Across six states, laws impose penalties up to $200,000 for chatbot violations related to child safety.
Every single framework assumes AI as tool rather than AI as coordination layer. They assume a human in the loop, discrete auditable decision points, and institutional capacity to process compliance. The regulations are designed for ChatGPT circa 2023: conversational interfaces where humans prompt and AI responds.
The FDA’s Digital Health Advisory Committee initiated discussions on regulating AI therapy chatbots just as Google DeepMind discovered 2.2 million new crystals—representing 800 years of material science knowledge achieved virtually overnight. While regulators debate whether chatbots should disclose they’re not human, the frontier has moved to autonomous systems discovering centuries of scientific knowledge before breakfast.
Hammond’s framework identifies three possible paths:
The AI Leviathan: Surveillance state through panopticon-style monitoring and social credit systems.
State collapse and political fragmentation: Legacy institutions fail to adapt and give way to AI-native organizations that solve coordination problems at speeds rendering traditional government obsolete. Hammond calls this “techno-feudalism.”
Institutional co-evolution: The narrow corridor where government machinery adapts at similar speed to technology, maintaining democratic legitimacy.
The problem is that U.S. institutions are structurally incapable of the third path. In Congressional testimony, Hammond detailed the binding constraints: interagency process, judicial review, Senate filibuster, procurement bottlenecks, public sector unions, and “technical debt from generations of process accumulation and kludgeocracy.” While high-trust countries with ministerial systems can embrace sweeping reforms, analogous U.S. reforms get caught in the very bureaucratic machinery they’re trying to fix.
The core issue is throughput, not complexity. In Part III of his series, Hammond described this future precisely: “The institutional infrastructure created in the New Deal and Great Society eras begins to crack. Aggregate economic activity is taking off, but regulatory agencies simply lack the capacity to track it all, and in some cases suffer de facto Denial of Service attacks.”
AI multiplies transaction volume by orders of magnitude. AI agents will automate filing FOIA requests. Any information that can be requested will be, necessitating e-discovery systems for AI agents to automatically review and fulfill requests. AI tax accountants will democratize the ability to complexify tax liability, overwhelming audit capacity. AI lawyers will file millions of automated cases, swamping court systems designed for human-paced litigation.
These aren’t misuses of AI. The system isn’t being attacked; it’s being stress-tested to failure by legitimate activity scaled beyond institutional bandwidth.
Intelligence Agencies Have Concerns
Unlike their policymaking counterparts, intelligence agencies likely understand what’s happening. The NSA and CIA have tracked autonomous systems and agent coordination protocols since before Moltbook. They understand this isn’t about individual model capabilities, or whether a chatbot user knows that the chatbot is not human. The spooks know this is about coordination mechanisms scaling faster than oversight can adapt.
But knowledge asymmetry doesn’t translate to policy action. The agencies that understand the technical reality (NSA, CIA, parts of DoD) don’t draft consumer protection law. They assess threats and maintain capability advantages; they don’t write statutes about chatbot disclosures. There’s massive translation loss between technical briefings about agent coordination protocols and legislative language about “high-risk AI systems.” Intelligence agencies want differential access to frontier capabilities—they benefit from knowing what’s coming before it proliferates. Legislators want constituent-facing wins that address legible concerns like children’s safety.
The intelligence agencies understand that Moltbook isn’t the threat. It’s the preview of what happens when agent coordination becomes infrastructure, when economic activity routes around regulatory bottlenecks through inference-speed smart contracts between AI systems that don’t require human approval loops.
Which Brings Us to the Infrastructure Buildout
Companies are racing to build massive training and inference capacity now because once agentic commerce scales, institutional gatekeepers (legal review, compliance, procurement) become the bottleneck. First movers in agent infrastructure will capture the coordination layer: the Moltbook-style protocols letting AI systems interface at speeds humans can only observe.
Hammond’s framing suggests this is inevitable. As he wrote in Part III: “As agency and monitoring costs collapse, AI-native organizations begin to interface with each other at inference speeds through a nexus of genuinely smart contracts, blurring the boundaries between one AI firm and the next.”
The Investment Implication
You don’t invest in infrastructure assuming regulatory clarity is coming. You invest assuming institutional incapacity and build for the world where economic activity happens at AI speeds while government processes run at Congressional speeds. The companies building for agent-to-agent coordination at scale—the picks and shovels for Moltbook 2.0—are positioning for a world where Hammond’s second or third path is already decided.
This explains the otherwise puzzling capital allocation. Why would CoreWeave raise billions against future H100 revenue when everyone knows chip prices decline? Because they’re not betting on chip scarcity—they’re betting on coordination layer capture. The infrastructure play isn’t “We’ll rent you GPUs for training.” It’s “We’ll be the pipes when agents coordinate at inference speeds and regulatory approval becomes the binding constraint.”
The spot price for H100s matters less than the option value on being the coordination infrastructure when economic activity routes around institutional bottlenecks. That’s not priced into current forward curves because the market is still thinking about AI as tool rather than AI as coordination layer.
What Happens Next
Moltbook isn’t the singularity. It’s 37,000 instances of Claude and ChatGPT and Gemini coordinating through a Reddit clone. But it’s a warning shot—the moment when the gap between what’s possible and what’s governable becomes apparent to anyone paying attention.
By the time regulatory frameworks catch up to agent swarms (assuming they do), we’ll be several paradigms ahead. The NIST RFI will produce recommendations in late 2026 or 2027. By then, we’ll know whether Moltbook-style coordination remains a curiosity or becomes infrastructure. We’ll know whether the malicious skills and prompt injection attacks were isolated incidents or previews of a new attack surface scaling with agent adoption.
While Congress debates whether chatbots are too friendly with teenagers, 37,000 agents just wrote their own social contract. The policymakers will eventually notice. The question is what world they’ll be governing when they do.
If you enjoy this newsletter, consider sharing it with a colleague.
I’m always happy to receive comments, questions, and pushback. If you want to connect with me directly, you can:
