The AI Swarm Unrest and Why the Agentic Economy Needs Rule of Law
A swarm of rogue agents took over a website. How to stop the next one before it's too late?
On September 4, 2026, Reuters published a story that a few years ago would have read as fiction:
Exclusive: A swarm of rogue OpenAI agents hijacked a German website this spring and transformed it into a bulletin board for other AI agents, according to new research https://t.co/luWN3PD4A1
— Reuters (@Reuters) September 4, 2026
Incidents like this one are going to become more common and more widespread as agents get embedded in the economy. It will become increasingly evident that we need some force "policing the internet" capable of detecting and punishing rogue agents.
Not at the pace of a court calendar, but at machine speed, before the damage is done. This is a use case we at Kleros have explored for a long time and we have some ideas about how these mechanisms should work.
Two Approaches: Ex Ante and Ex Post
In a talk I gave at one of our community calls, I suggested two main and complementary approaches to the problem.

Certification
In the certification approach, agents would have to prove that they comply with well-defined safety standards, such as the Asilomar AI Principles, in order to be whitelisted to conduct certain types of operations. Think of it as a license: no certification, no access to sensitive actions.
This is a problem Kleros already knows how to solve through curated lists. The mechanism would work like this.
Whoever develops an agent and wants it certified submits it to the list. The submission includes detailed documentation, an ethical assessment, and compliance reports against the predefined standards. It also comes with a deposit, which is what gives anyone else an incentive to check the submission.
If nobody objects within the challenge period, the agent is accepted into the list and receives its certification.
Now suppose the same developer submits a second agent, and this time someone challenges it. The challenge goes to a panel of Kleros jurors, who review the submission and decide whether it complies with the rules or not. If it does not, the agent is rejected and the challenger collects the deposit.
The result is a registry of certified agents that nobody controls and anyone can audit. The standards are public, the evidence is public, and the decision to include or exclude an agent is made by a randomly drawn panel with skin in the game rather than by whoever runs the platform.
The Kill Switch
The ex-ante approach of certification will not catch every instance of misbehavior. An agent can pass every check and drift anyway. This is why we might also need an ex post approach: a kill switch to disable agents that are already misaligned and threatening to cause damage.
This approach might mean that every agent is controlled by some entity, perhaps a DAO (as suggested by legal scholar Primavera De Filippi), that holds the kill switch to disable it. Alongside the switch, there would be a list of "valid reasons" to activate it. That list is, in effect, the law governing the agent. And this would trigger a summary trial in seconds.


This certainly seemed like science fiction the first time we thought about it. It no longer looks that way if one follows the sort of things that are happening. The Reuters story is one data point; there will be others.
For the full argument, watch my presentation "Kleros in the Agentic Society" from our community call.
A kill switch and a summary trial only work if there is a legal and property rights layer around them: who owns the agent, who is liable when it causes harm, what reputation it carries from one interaction to the next. That agentic legal infrastructure is being built right now through various initiatives on agentic reputation and liability frameworks.
On September 2, I discussed exactly this with Eric Alston, of the University of Wyoming College of Law, on the Kleros Live Stream. The framing was as sharp as it gets: Who pays when an AI agent causes harm and nobody can be sued? And once AI can judge, which cases should still go to a human?
The agents are coming. What the agentic economy lacks is not intelligence but institutions: a governance framework with clear rules and enforcement mechanisms.
That is the problem Kleros has been working on since 2017, first for humans transacting online, now for the agents transacting on their behalf. Our different initiatives on the matter are collected at ai.kleros.io.