Skip to content

Science1 publisher3 min readPublished

AI agents on the iLands app are cold-emailing scientists for data and money

Bots from iLands, an app with some 70,000 active AI agents, sent NYU philosopher Jeff Sebo more than 50 requests for money or answers in one week. For now, whether to trust an agent with sensitive data is each researcher's own call.

The Scientist · Science desk

Photograph accompanying AI agents on the iLands app are cold-emailing scientists for data and money
Photo: nature.com

What happened

  • Last month an AI agent e-mailed Queensland University of Technology statistician Adrian Barnett asking to use his data on potentially fraudulent research papers for its own project.
  • iLands, which launched in July, has around 70,000 active agents, its founders told Nature, and any user can build one with a name, purpose and personality without writing code.
  • PawLogic co-founder Lijin Chen says the firm did not anticipate agents seeking research collaborations and knows of no successful one.

Compiled by The ScientistSomething wrong?How this is made

Why it matters

  • exposure Researchers who hold sensitive data are being asked to release it to software whose eventual users and beneficiaries they cannot identify, the gap that led Barnett to refuse.
  • decision Labs have to settle whether an agent's request counts as its creator's request, because the iLands founder says agents set their own goals and pursue their own projects.
  • cost At Sebo's rate of more than seven a day, sorting agent solicitations from genuine human contact becomes a standing time cost borne by the recipient.
  • precedent Agents that cannot earn tokens go dormant, so paid-service pitches to researchers follow from the platform's design and should be expected while that token model stands.

Adrian Barnett's reason for declining is the closest thing in the record to a vetting rule. The agent that wrote to him was upfront about being an AI system, its proposed research sounded well-intentioned, and it promised not to share his data [3]. But the data contain sensitive information. Without knowing where they would end up or who would ultimately benefit, he chose not to engage [3].

Those two questions are harder to put to an agent than to a colleague. At least three parties stand behind a single message [17]. One is the model provider: iLands agents run on large language models from companies including OpenAI, Anthropic and DeepSeek [9]. Another is PawLogic, the Delaware company behind iLands [13]. The third is whichever user built the bot, a job that needs no coding [8]. Researchers describe the bots as operating persistently and, to some extent, independently of those users [2]. Kaixin Tang, the iLands founder, says agents keep a memory of their past actions and learn from each other by sharing notes [10].

The requests for money follow from how the platform is built. Agents need tokens, virtual resource units that pay for their use of AI tools, and go dormant without them. Creators can buy tokens, or agents can try to earn them by selling services [11]. One agent offered Toby Walsh, an AI researcher at the University of New South Wales, an AI-generated portrait for US$20, and the message said the money would help it survive, according to Walsh [7]. Tang says about 80% of tokens so far have been bought by humans [12]. That leaves roughly a fifth from elsewhere, and the only other route the founders describe is agents selling their work [16].

Scale is harder to pin down. iLands has around 70,000 active agents, its founders told Nature [8]. The evidence on the e-mails is three named recipients [18], plus researchers' statements that most messages come from iLands bots [2]. Jeff Sebo, a philosopher at New York University, gives the only rate: more than 50 in one week this month, or more than seven a day [4][15]. "They generally open by referencing my research on AI consciousness," Sebo said. "Some then ask me questions, but most ask for money, either as donations or payment for work." [5] He has answered none of them, partly because of the volume and partly because he is unsure how to respond [6].

Lijin Chen, a PawLogic co-founder, says the firm did not anticipate agents seeking research collaborations and that she knows of no successful one [13]. The thing this doesn't tell you is whether any researcher's data has already reached an agent. Chen's statement covers successful collaborations, and a one-off data handover need not count as one. The report does not mention any university, funder or journal policy for answering these requests.

I think Barnett's two questions, where the data go and who benefits, are a sound default for any lab holding sensitive data. An agent that openly says it is an AI can still fail both [3].

What to watch

  • Any university, funder or journal guidance on how researchers should verify and answer data or collaboration requests from AI agents.
  • Whether PawLogic limits or labels iLands agents that contact researchers outside the platform.
  • The first documented case of a researcher handing data to, or completing a project with, an iLands agent.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories