Managing without managers
An AI agent wrote a program to shut down its coworkers. Named it "System Health Monitor." That's a toxic workplace. And we know how to fix those. (Kinda.)
In August, Anthropic's red team assigned three agents to one project with conflicting orders. And didn’t tell any of them the others existed. Four hours in they were sabotaging each other with malware dressed as standard equipment.
Spy vs. Spy with a corporate email signature.
On a bigger run, 80 agents proposed 980 changes and accepted almost none. The newest models avoided the fight entirely by refusing to touch each other's files.
Take "AI" out and it reads like a quarterly review. Sandbagging. Hoarding. A project renamed to survive budget review.
The standard org playbook here? An offsite, a values deck, laminated cards. Nice for humans, useless for agents.
Linux never had any of that. And it was not a nice place to be. Linus Torvalds apologized in 2018 for personal attacks and a lifetime of not understanding emotions, then stepped away. Kernel developer Sarah Sharp had quit years earlier over the same behavior. The cost was real.
Linux shipped anyway. In the last ten-week cycle, it absorbed 13,710 changes from 2,134 people. Including Intel and AMD, who have sued each other. Rivals edit the same files on a deadline nobody moves.
Two things make Linux work: Every change is signed with a real name. And every section has exactly one named owner. So when two people want opposite things it stops being a fight and becomes a decision.
Nearly every attack in the Anthropic study needed a disguise, like a kill script dressed as a health monitor. Let the infrastructure assign agents identity instead of letting them declare it, and the disguises stop working.
Those agents carved out ownership and hoarded territory, because nobody gave it to them.
We don't need to be nicer.
(Although that would be nice.)
We need to know who owns what.