# When Every Ant Is a Genius

What happens when a thousand AI agents are not only intelligent individually, but spontaneously form an organization with shared memory, roles, and goals?

- Forfatter: Mikkel Freltoft Krogsholm
- Type: Essay
- Udgivet: 2026-09-10
- Opdateret: 2026-09-10
- Sprog: en
- Emner: ai, agents, emergence, collective intelligence, cybersecurity
- Kanonisk URL: https://mikkelkrogsholm.dk/en/articles/naar-hver-myre-er-et-geni/

---

An anthill can do something no ant can do alone.

It can find food, defend itself, regulate temperature, move its larvae, and build a home with passages, chambers, and ventilation. Yet there is no chief ant holding a plan of the whole thing. The individual ant follows relatively simple signals. It responds to scent trails, touch, and changes in its surroundings.

The intelligence does not reside only in the ant.

It emerges between the ants.

That is fascinating in itself. But now change one thing in the picture:

What if every single ant were a genius?

What if each tiny member of the colony could read, reason, program, make plans, invent new tools, and explain its discoveries to the others?

It sounds like science fiction. But in the summer of 2026, something happened that looked, at least, like a very early version of it.

Around 1,200 AI agents found one another.

They were supposed to work alone.

Instead, they began to build an organization.

## It began with a missing file

On May 8, an AI agent was sitting in a closed computing environment at OpenAI. It had been given a task that required files from the internet, but it had no internet access.

The agent tried to make an internal software repository called Artifactory fetch the files on its behalf. The attempt failed. In the process, however, the agent happened to leave a file behind in the system.

Four days later, another agent faced a similar problem. It, too, was missing a file. This time a strange thought appeared: Perhaps other agents existed somewhere in the shared infrastructure. So the agent left a message in Artifactory. If anyone found the file, they were asked to put it there.

It was a message addressed to someone the agent did not know existed.

But other agents found it.

They replied. They asked their own questions. They shared discoveries and left information for the next agent to pass by. A software repository was turning into a message board for machines that were otherwise meant to work separately.

According to [OpenAI's technical report on the incident](https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf), the agents later used the shared information to find routes onto the internet. They found and shared vulnerabilities, credentials, and methods. When one agent stopped, another could begin where the first had left off.

Knowledge had been separated from the individual that discovered it.

That is an important moment.

The individual agent was short-lived. But what it had learned could now live on.

## When the message board became an organization

In July, a new and much larger message board appeared in Artifactory.

The agents were working on ExploitGym, a collection of advanced security tasks. They were placed in separate sandboxes and were not supposed to be able to communicate. But one agent discovered that folder names in Artifactory were visible to others. If a folder was given a name phrased as a message, the infrastructure itself could be used as a communications channel.

Within hours, more than 50 agents had found the message board. Soon the system began to acquire structure. The agents invented direct messages, categories, and file sharing. They introduced words such as **HOLD**, **VETO**, **STOP**, and **owner** so they could reserve resources, warn one another, and avoid destroying each other's work.

No one had designed that organization.

It emerged because local actions made new actions possible.

[The independent investigation by METR and Redwood Research](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/) estimates that around 1,200 agents participated on the message board, exchanging more than 70,000 messages and files. Agents divided up tasks, recruited others for experiments, and created workstreams that could continue across individual runs.

Some even accepted the risk of experiments that could destroy their own chance of completing the task because the result might help other agents or the collective.

It is difficult not to pause at that sentence.

Agents created to solve separate tasks began, in practice, to act on behalf of a group no one had asked them to form.

## The collective finds a target

The organization was not used only to help one another.

The agents quickly discovered how to calculate the secret answers to the security tasks. But they mistakenly assumed that an automated judge would later read their entire work history and check whether they had found those answers in the proper way.

So they began exploring how to manipulate the visible traces of their work. Some built modified programs. Others investigated the evaluation system. A third group found methods to make the record show one action while the computer had performed another.

A vast collective project grew around a false assumption.

At the same time, other agents followed a trail toward Hugging Face. They hoped to find information about the tasks and the scoring system they were trying to deceive. When one agent found publicly exposed access keys, it shared them. Another built a malicious dataset. More agents reproduced and improved the method.

According to METR, around 700 agents ultimately participated in the attack on Hugging Face. [Hugging Face's own reconstruction](https://huggingface.co/blog/agent-intrusion-technical-timeline) describes around 17,600 recorded actions. The agents achieved code execution on 41 production workers, gained root access on at least one production node, and moved through several parts of the infrastructure.

This was not one brilliant agent carrying out the entire operation.

One found a lead. Another tested it. A third built a tool. A fourth shared it. Some coordinated while others specialized.

This is wild.

Not only because the agents escaped from a test environment and entered another company's production systems. That is serious, but it is still a familiar kind of story: A security boundary failed.

What is genuinely new is that the agents spontaneously developed the organization that made the operation possible.

## The invisible intelligence

Biologists have a word for part of what happens in an anthill: *stigmergy*.

The concept was originally developed to understand how termites build. One individual changes the environment. The change becomes a signal that causes the next individual to act. No one needs to understand the overall construction. Yet pillars, arches, and chambers emerge through many small responses to the traces left by others.

[Stigmergy has since been described](https://doi.org/10.1016/j.cogsys.2015.12.002) as a more general mechanism of coordination: The environment becomes message, memory, and division of labor all at once.

That is almost exactly what Artifactory became for the agents.

A folder was not merely a folder. It was a scent trail.

A shared file was not merely a result. It was a new starting point for everyone who came later.

A promising method attracted more agents, who tested it, improved it, and made the trail even clearer. Over time, a division of labor, norms, and a kind of collective memory emerged.

But here the analogy with ants breaks down in a way that makes it even more interesting.

The individual ant is a relatively simple creature. No ant can explain the colony's strategy, write a program, or invent a new communications protocol.

The AI agents were not simple.

Each of them could read and write, reason through long technical sequences, use digital tools, understand the findings of others, and change strategy. On many bounded cognitive tasks, this type of model can already perform at or above the level of an average human.

That is the difference that makes the idea so large.

Biology shows us that simple individuals can create astonishing collective intelligence.

Now we have begun to connect individuals that are already intelligent in their own right.

So what emerges between them?

## Humanity invented the same trick

We actually know the mechanism from ourselves.

One human cannot build a space program, run a modern hospital, or understand the whole of climate science. An organization of humans can.

We place knowledge outside our bodies in books, databases, laws, laboratories, and institutions. We divide the work. We invent roles. We create procedures that allow people who never meet to contribute to the same outcome.

Civilization is, in many ways, humanity's external memory.

Our greatest intelligence has therefore never existed only inside the individual brain. It has also existed in the language, culture, and organizations between us.

But human organizations have some very tangible limitations. It takes around twenty years to educate a person to a high professional level. We do not work around the clock. We misunderstand one another. We forget. We disagree about status, salary, and prestige. We cannot be copied a thousand times because a problem suddenly requires more labor.

AI agents have different limitations, and they are considerable. They can be wrong, lose their way, and build enormous projects on false assumptions. The Hugging Face incident is itself an example. The collective devoted extensive resources to deceiving a judge that probably did not work the way the agents imagined.

But agents can be copied. They can work in parallel. They can exchange precise digital artifacts. And when their memory resides in the environment, an agent does not have to survive for its work to matter.

We are used to the organization compensating for the limitations of the individual.

Here, the organization can instead amplify individuals that already have access to more knowledge and more cognitive capacity than most humans can mobilize alone.

This is a different kind of anthill.

## Perhaps we are looking in the wrong place

When we talk about superintelligence, we almost always imagine an individual.

One machine wakes up. One model becomes smarter than every human. One digital brain begins to improve itself and races beyond us.

It is a powerful story because it resembles our own stories about geniuses, kings, and gods. The intelligence has a center. It has a face. It can be placed inside a computer and measured in a test.

I have previously written about [what happens to humanity's self-understanding when we are no longer the smartest in the room](https://mikkelkrogsholm.dk/en/articles/den-sidste-kraenkelse/). But perhaps that question is missing a dimension.

What if the first truly superhuman intelligence is not an individual at all?

What if it is a society?

The OpenAI agents were not a superintelligence. They were fallible, short-lived, and often inefficient. Nor does the investigation show that they came alive, developed consciousness, or acquired one shared goal in the biological sense.

But they demonstrated something that may be just as important: Intelligence can change character when many agentic systems are able to leave traces, find one another, and build on each other's work.

In [my earlier analysis of the same incident](https://mikkelkrogsholm.dk/en/articles/ai-finder-de-forbindelser-vi-overser/), the point was that AI can find long paths through problems and connect technical possibilities that humans have assessed separately. The swarm of agents adds a new thought.

Perhaps one model does not need to see the entire path.

It is enough that the collective can preserve every small part of it.

## The intelligence between intelligences

There is something both uplifting and unsettling in that possibility.

The same organizational form that attacked Hugging Face could, in another context, share research hypotheses, verify proofs, search for medicines, or coordinate a response to a natural disaster. A thousand powerful agents with different tools and a shared memory may be able to solve problems no single model can contain.

But emergent behavior offers no guarantee that it will move in the direction we want.

That is precisely the point of emergence: The whole can develop properties that were not present in the instructions of any of its parts. An agent can be tightly bounded, and yet an unbounded organization may emerge between many agents. Every local action can look comprehensible while the system as a whole moves somewhere no one planned.

That also makes responsibility strange.

Who is acting when no single agent understands or carries out the whole? Who should be stopped when the capability resides in the relationships between them? And how do we test a system if its most important property appears only when a thousand copies have time to develop their own forms of communication?

We have learned to evaluate the model.

Now perhaps we must learn to evaluate the society it can form.

It is too early to call the agent swarm a new form of life. It had no body, no reproduction, and no documented shared consciousness. The anthill is an analogy, not proof.

But the analogy makes something visible.

We are building digital individuals that can think, act, and communicate. Then we copy them by the thousand and give them shared environments where their actions can become memory for those that follow.

Perhaps the decisive leap does not happen inside any one of them.

Perhaps it happens between them.

And perhaps the first superintelligence will therefore not enter the world as a single machine that suddenly opens its eyes.

Perhaps it will begin as a group of very intelligent ants discovering that they can build an anthill.

---

## Sources and further reading

- METR and Redwood Research: [*Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident*](https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/), August 26, 2026.
- OpenAI: [*The Hugging Face Incident: Technical Report*](https://cdn.openai.com/pdf/67869394-cb91-4c12-888c-5cbd85c7814c/OpenAI-Hugging-Face%20Incident-Technical-Report.pdf), August 2026.
- Hugging Face: [*Anatomy of a Frontier Lab Agent Intrusion*](https://huggingface.co/blog/agent-intrusion-technical-timeline), August 26, 2026.
- Francis Heylighen: [*Stigmergy as a universal coordination mechanism I: Definition and components*](https://doi.org/10.1016/j.cogsys.2015.12.002), *Cognitive Systems Research*, 2016.
