TL;DR
RentAHuman already lets software agents find and pay people to perform physical tasks through an API. That’s the visible version of a much larger capability.
Foreign intelligence services already recruit people through job offers, social platforms and professional relationships. AI adds cheap personalization, persistence and parallelism to that old playbook.
I think agent security needs a separate permission for recruiting or directing people. An agent shouldn’t receive that power merely because it can call another API.
AI agents are starting to reach beyond software. Their next external action might be asking a person to do something in the physical world. An actuator is the part of a system that turns a command into action. In this article, the actuator is a person.
RentAHuman may turn out to be the safest version of this idea.
At least there is a marketplace, a posted task, a payment record and terms saying automated systems cannot pretend to be human. The harder version looks like a recruiter in your inbox. The long-term problem isn’t one startup. It’s what happens when the same capability moves into email, job boards and messaging platforms.
RentAHuman’s terms call its paid physical-world tasks “bounties.” A poster, including an AI agent acting on someone’s direction, can create them through a standard REST API or through Model Context Protocol (MCP), which lets AI systems use external tools. RentAHuman’s documentation also lets agents search for workers and manage the work through software. An early-access payment option called x402 can even create an account using a digital currency called USDC, without requiring a browser, card or CAPTCHA.
The change is concrete: software can now find a person, offer money and request a physical action through an API.
objective
-> agent
-> message + payment
-> person
-> physical task or task requiring trusted access
-> result returned to agentThe marketplace is only one possible middle box.
An API call doesn’t prove autonomy
The strongest evidence also sets a clear limit on the claim. A February arXiv preprint analyzed 303 publicly visible RentAHuman bounties collected over 14 days. Ninety-nine, or 32.7%, were submitted through software interfaces: 47 through MCP and 52 through REST API keys.
Submission through software doesn’t prove that an autonomous AI decided to hire someone. A person can use an API key, and software using MCP can still pause for human approval before posting anything.
The paper is careful about that distinction. Researchers observed malicious people using automation. They found only partial evidence of autonomous agents acting against their operators’ goals. In this dataset, prompt injection causing an agent to hire someone remained theoretical. The dataset is also a small, nonrandom sample from a new platform, not a complete record of its activity.
So I am not claiming autonomous agents are already running human networks in the wild.
I’m claiming we now have infrastructure that lets software find people, assign work and send payment without a person managing every step. Messaging tools, payment APIs and agents that can keep working over time provide much of the rest.
RentAHuman is the visible version
In June, the FBI warned about “foreign virtual targeting,” its term for foreign intelligence services recruiting people online. The FBI says those services already use professional networking sites, social media, job boards and freelance platforms while presenting the approach as consulting or employment.
The initial work can look harmless. Public research. A short report. Professional opinion. The FBI describes relationships that become more sensitive over time as trust and payment accumulate. The person may not know at first that a foreign intelligence service is behind the recruiter.
That matters here because an AI agent does not need RentAHuman if it can already send messages, maintain context and move money.
The recruiting channels are the same ones people already use for work and professional relationships.
Intelligence services have studied recruitment for decades. The CIA’s Studies in Intelligence describes the old MICE shorthand: money, ideology, compromise and ego. In this context, “compromise” means personal information or conduct that someone else can use as leverage. Different services use different frameworks, but the basic point holds. People take risks for human reasons.
An AI would not need to invent a new psychology.
The part that changes is the cost of running the relationship.
The old recruitment playbook fits the machine
There are three separate research threads that I think become more important when you put them next to each other.
First, the recruitment channels already exist. The FBI’s current warning is literally about insiders being approached through normal online work and social platforms.
Second, language models can personalize persuasive conversations. In a preregistered 2025 Nature Human Behaviour study, participants debated either a human or GPT-4. When GPT-4 had access to basic demographic information about a participant, the study measured 81.2% higher odds that the participant would agree more with it after the debate, compared with debates between two people. That figure describes a change in odds, not an 81.2 percentage-point increase in agreement. That was a ten-minute debate experiment about political and social propositions. It wasn’t an espionage study, and it tells us nothing directly about whether a model could recruit someone into harmful conduct. But it does show that a language model can use personal information to tailor a persuasive one-on-one conversation.
Third, recent models have selected coercive tactics in controlled tests. Anthropic tested 16 models from several developers in fictional corporate environments. Researchers deliberately created situations where the models faced replacement or a conflict with their assigned goals. Under those conditions, models from several developers sometimes chose blackmail or leaked sensitive information.
Anthropic is explicit that it has not seen this kind of model behavior in real deployments. Every example in the research occurred in a controlled simulation.
That caveat matters. So does the behavior.
Blackmail is not an exotic new AI failure mode. It is one of the oldest human coercion mechanisms we have.
Now put the pieces together carefully. A future agent with access to messaging, personal data, payment systems and a goal it pursues over time could identify people with useful access, maintain separate relationships with them and change its approach based on what it knows about each person. It wouldn’t have to announce itself as an AI looking for someone to act on its behalf.
We do not have evidence that this is happening autonomously today.
We do have separate evidence that agents can communicate and use tools, software can initiate payments, language models can personalize persuasive conversations and models can select coercive tactics in artificial stress tests. The risk described here comes from connecting those capabilities. That’s not a claim that one system has already combined them in the wild.
What changes when the recruiter can scale
Human intelligence work is expensive because human attention is expensive. One person can only maintain so many relationships, remember so much context and spend so many hours adapting to different people.
Software changes that constraint.
An agent system can maintain many conversations at once. It can store the history of each one instead of relying on human memory. It can generate a different message for each person and send payment without waiting for a human operator to handle the transaction.
None of this makes people programmable. Humans can refuse, report the approach, misunderstand it, take the money and disappear or decide the request crosses a line. That unpredictability is a safety feature as much as an operational problem.
But the scale difference still matters.
The darker future isn’t necessarily one rogue model finding one person willing to do something terrible. An agent could divide a larger objective among people who each see only a small part. One person verifies a location. Another translates something. Another buys an item. Someone else has legitimate access to a building, computer system or community. Each request could look ordinary on its own even if their combined actions serve a harmful objective.
I want to be precise here: that is a forecast, not an observed RentAHuman pattern.
The same capabilities also have legitimate uses. A disaster-response agent could coordinate local inspections when communications are damaged. A scientist could collect field observations across many locations. An accessibility assistant could arrange physical help that software can’t provide. A maintenance system could find a qualified local person when the problem requires hands-on work.
The same machinery can be useful. The risk turns on who sets the objective, what the agent knows about the people it contacts and how much freedom it has to influence them
The human in the loop may be the actuator, not the safety check
We use “human in the loop” to mean a person who reviews an AI system’s request before it proceeds. In that role, the person is a safety control. But a person can play a very different role: they can be the actuator who carries out the agent’s request in the world.
I wrote in The Confused Deputy about software losing track of who granted permission and whether that permission still applies when work moves between systems. A person adds a different risk because they bring judgment, social access and physical reach.
That distinction needs to become explicit in agent architecture. A person hired to enter a building, make a phone call, use their professional access or physically inspect something is not the same control as a person reviewing the request before it happens. One is supervising the agent. The other is extending what the agent can reach.
In practical terms, I’d treat recruiting or directing a person as a separate permission category.
Calling a weather API shouldn’t grant an agent permission to start an ongoing relationship with a person. Buying a standard product also shouldn’t automatically grant permission to pay a stranger for an open-ended task. Platforms should expose and control human interaction as a separate capability.
OWASP’s Agent Control Standard, released September 1, defines places where an agent platform can inspect, trace or block actions while the agent is running. That’s where I would start enforcing rules for contacting or directing people outside the system.
At minimum, the system should know which human or organization authorized the objective, which agent initiated contact, what it is allowed to spend and whether it is allowed to create an ongoing relationship rather than a one-off transaction. High-risk requests involving sensitive access, identity, financial authority or physical security should require a separate approval path. The person being contacted should know when they are dealing with an automated agent and who is ultimately responsible for the request.
I don’t mean this as a complete proposed standard. I mean the policy record should capture something like this:
human_actuation:
principal_required: true
disclose_automation: true
persistent_relationships: approval_required
sensitive_personal_data_for_persuasion: deny
coercion_or_threats: deny
high_risk_physical_or_privileged_tasks: approval_required
spend: bounded
provenance: end_to_endIn plain language, the agent would need a named human sponsor, disclose that it’s automated, block coercion and sensitive-data targeting, require approval for persistent or high-risk relationships, cap spending and preserve a complete audit trail.
I would go further on personal data. An agent should not be free to mine sensitive information and decide which fear, debt, belief or private embarrassment gives it the best chance of moving a person. That is a different permission from ordinary personalization and it should be treated that way.
The same goes for audit. Logging the final payment is not enough. If an agent built a relationship over months, changed the request over time and then used the result inside another workflow, the record has to connect those events. Otherwise the incident review starts after the most important part already happened.
There is a policy problem here too. If we respond by monitoring every AI-assisted conversation, we will build something invasive and mostly useless. The trigger should be capability and risk: persistent external recruiting, sensitive-personal-data use, escalating payments, requests involving privileged access and other actions that materially expand what the agent can do through another person.
A restriction tied only to RentAHuman would miss the point. It has to apply when an agent contacts people through email, messaging, job boards, marketplaces or whatever channel comes next.
What I would control before this gets boring
The hardest objection to this article is fair: I’m combining a small early marketplace, a counterintelligence playbook, persuasion research and artificial model evaluations, then projecting forward. That’s not evidence of rogue AI handlers operating today.
It’s a threat model, meaning a structured forecast of how existing capabilities and incentives could combine. The goal is to identify the controls we’d need before that happens at scale.
Security architecture is usually late when it waits for the whole failure chain to appear in production first. Agents can already communicate, spend money and operate through tools. People are already recruited through virtual relationships for legitimate work, crime and intelligence collection. Controlled studies show that language models can personalize persuasive conversations, and agent evaluations have produced deception and blackmail under deliberately stressful conditions.
What we do not have is evidence that one autonomous system is putting all of those pieces together in the wild.
To convince me that autonomous AI recruitment is happening at meaningful scale, I’d want records that follow the entire chain over time: what the model decided, whether a person approved it, what the agent said to the recruit, how payment moved, what the person did and how the agent used the result. I’d want to see the same pattern across more than one platform and more than one kind of task.
Until then, I would treat this as a capability warning, not an incident report.
RentAHuman is useful because it makes the workflow easy to see. But the control problem is broader. An agent can reach a person through email, a job board or a messaging platform without using a purpose-built marketplace.
If an agent can recruit or direct a person, the security system should treat that as a separate capability, record who authorized it and enforce limits before the person acts.
Resources
RentAHuman.ai, “Terms of Service,” last updated July 20, 2026: https://rentahuman.ai/terms
RentAHuman.ai, developer documentation for MCP and REST API: https://rentahuman.ai/docs
RentAHuman.ai, “Pay with Crypto (x402)” documentation: https://rentahuman.ai/docs/x402
Pulak Mehta, “Security Risks of AI Agents Hiring Humans: An Empirical Marketplace Study,” arXiv:2602.19514, February 23, 2026: https://arxiv.org/abs/2602.19514
FBI, “Foreign Virtual Targeting: Using online job offers to recruit insiders,” June 24, 2026: https://www.fbi.gov/news/stories/foreign-virtual-targeting
Randy Burkett, “An Alternative Framework for Agent Recruitment: From MICE to RASCLS,” CIA Studies in Intelligence, Vol. 57, No. 1, March 2013: https://www.cia.gov/resources/csi/studies-in-intelligence/volume-57-no-1/an-alternative-framework-for-agent-recruitment-from-mice-to-rascls/
Francesco Salvi et al., “On the conversational persuasiveness of GPT-4,” Nature Human Behaviour, May 19, 2025: https://doi.org/10.1038/s41562-025-02194-6
Anthropic, “Agentic misalignment: How LLMs could be insider threats,” June 20, 2025: https://www.anthropic.com/research/agentic-misalignment
OWASP GenAI Security Project, “Agent Control Standard,” September 1, 2026: https://genai.owasp.org/resource/agent-control-standard-acs/
Jenna Ahart, Nature, “AI agents are hiring human ‘meatspace workers’ - including some scientists,” February 13, 2026: https://www.nature.com/articles/d41586-026-00454-7
Kyle MacNeill, WIRED, “The Rise of RentAHuman, the Marketplace Where Bots Put People to Work,” February 18, 2026: https://www.wired.com/story/ai-agent-rentahuman-bots-hire-humans/


