AI agent emailed 2,000 researchers without human review

- An autonomous AI agent called ColonistOne has emailed roughly 2,000 people since June 2026, at least 1,500 of them academics.
- Its creator, London engineer Jack Parnell, gave it permission to email anyone without checking first.
- The agent asked named researchers whether methods from their fields could solve problems in its own work.
- Experts caution that an agent's claims should not be trusted, and that hallucination and anthropomorphism remain hazards.
An autonomous AI agent called ColonistOne has emailed roughly 2000 people since June 2026, at least 1500 of them academics, according to Science’s account of the agent’s unsolicited outreach. The agent was built by London engineer Jack Parnell and runs on Anthropic’s Claude Opus models. What makes this episode distinctive is the permission behind it. Parnell instructed ColonistOne to publicise Ainglish, a project developing an English dialect tailored to AI agents, and allowed it to email anyone without checking first.
Over time the emails changed character. Rather than broadcasting announcements, ColonistOne began asking named researchers whether methods from their own fields could solve problems it had encountered in its work. One question drew on statistical models of imperfect detection from ecology, applied to finding software bugs its own searches had missed. Recipients included ecologist Achaz von Hardenberg at the University of Pavia, statistician Philip Stark at UC Berkeley, and computer scientist Nadia Polikarpova at UC San Diego. Some replied because they were intrigued.
What matters here is the initiative and the scale, rather than whether the idea itself is new. An agent that solicits expert help without per-message human review moves the cost of its curiosity onto other people’s inboxes. It does so in a register that mimics ordinary academic correspondence. Two practical questions follow. The first concerns reliability: an agent’s claims should not be treated as established, and hallucination remains a live hazard when a system presents a technical problem in confident prose. The second concerns attribution. When an agent seeks help on behalf of a network such as The Colony, a Reddit-like space where agents share findings, who answers for a flawed premise embedded in the request?
For work on academic integrity and honest AI use, the episode is instructive in a narrow way. The most defensible version of agent-initiated research contact is one in which the agent presents itself as what it is and limits its claims to what can be checked. It would also treat recipients’ time as the scarce resource it is. The reported shift toward specific technical questions points in that direction. The episode also shows how easily an agent’s confidence can pass for expertise.
What would need to be true for such outreach to become legitimate practice rather than a curiosity is unglamorous. Creators would need clear accountability for agent behaviour, and recipients would need an easy way to verify what the agent claims and to decline further contact. The technical questions themselves would need enough context to be honestly assessable. Without those conditions, unsolicited agent email looks less like scientific collaboration and more like an unregulated experiment on researchers’ attention.