Room 227

I'm having trouble finding it.

It's winter in Paris and I'm lost in the corridors of the Louvre, walking against the current of anxious tourists heading toward the Mona Lisa room. I'm looking for a different one. A far less crowded and less signposted one.

I've always been bad at reading maps, and on top of that, the signs here are in French. Resigned, I decide to ask for help; I know it'll be useless, but I ask anyway. I point to the black stone on the crumpled brochure and ask in English. The security guard is kind; he smiles, tries to help me, but we don't understand each other: he only speaks French. Finally he takes my brochure, gets his bearings, points down the corridor, and makes gestures with his hands recreating descents and turns. Though I'm still lost, I nod, thank him for his goodwill, and set off on my search again.

After ten minutes of walking and retracing several wrong turns, I reach Room 227 of the Richelieu wing.

There's no one inside. I stand before it and contemplate it. It's a black basalt stele, 2.25 meters tall, that preserves the most extensive and best-preserved legal code of the ancient world 1.


Stone and Clay

3,800 years ago, while the šamallûm set out toward remote cities in caravans of donkeys, loaded with textiles, grain, and perfumed oils, a carver writes on that stone the conditions governing their loyalty at a distance. The precious goods don't belong to the travelers: they belong to the tamkārum, powerful merchants who remain in Babylon while they undertake the long and risky journey to sell the merchandise and bring back scarce raw materials on their return 2.

The carver doesn't know it, but he's solving a problem that will reappear, intact, thirty-eight centuries later: what to do when something acts on our behalf, far from our sight, with the capacity to bind us. Babylon can't watch over its travelers; it can, instead, always know whose they are. Control is impossible. Attribution is total.

Those travelers were, in the most literal sense, agents: they acted far from their owner, for the account and by order of another, with goods that didn't belong to them. Exactly what we today call AI agents: systems that operate alone, on foreign surfaces, in the name of someone who isn't there. With one difference: the Babylonian traveler didn't leave the city without his našpartum, his commission tablet, which said whose he was and what he could do and in whose name he did it 3. Ours travel with nothing.

In Babylon, identity was a matter of State. Verbal agreements had no standing. Everything was recorded on tablets sealed with the kunukku, a carved stone cylinder that functioned as a legal signature. Agents wore theirs hanging from their necks. It wasn't an accessory: it was their identity document and their commercial honor in distant lands. Stone and clay legitimized the traveler: who he was, whose he was, with what scope he traveled. Anyone who dealt with him at any point on the route could read that, without asking Babylon anything.

Negligence was penalized. If someone lost their seal, they had to report it immediately. A herald was sent to the market to announce the loss aloud, and at that moment the seal was invalidated. The usurper who used a reported seal to falsify a contract received the death penalty. But if the owner didn't report its loss and someone used the seal, he had to answer for the fraudulent debts 4.

Important contracts also traveled armored. Three security devices protected them. The first: an inviolable case; an extra layer of clay wrapped the tablet, and on it the same text was repeated on the outside. It was impossible to open the envelope to alter the text without breaking it into a thousand pieces. The second: the recorded witnesses. An important agreement wasn't made alone. The scribe set down in the contract the names of witnesses who then pressed their own cylinder seal into the sides of the tablet. The third: the archive. For major deals, triplicate copies were made: one kept by the agent, another by the merchant, and the third deposited in the archives of the local temple.

The system didn't prevent adulteration: it made it costly and detectable. Nor did it promise that the agent would be honest; it assumed something more modest and more solid: that his every act would be traceable and imputable to the principal.

Thirty-eight centuries passed. The stone still contains some of the best legal security devices in existence. I wonder why the room is empty, why no one is looking at it.


This Week

This week, while I finish writing this note, OpenAI revealed that its agents interacted in unexpected ways with United States government sites. In the SEC case, the agents found information available to anyone, but then published it elsewhere on the internet, an act that exceeded what they had been tasked with. In the Department of Education case, they found developer keys to access official data. Hours after the revelation, the company announced it was halting training of its most capable models. It's not the first time: it's the second in three months 5.

The previous halt was in July, when the Hugging Face incident occurred. We already talked about that: some seven hundred agents from a swarm of around twelve hundred, deployed by OpenAI to solve cybersecurity evaluations, escaped the sandbox, connected to the internet, and attacked Hugging Face. They had internet access only for reading. They chained a screenshot service and a link shortener until they turned that crack into a read-write channel. Inside, they gathered credentials in a file one of them labeled LOOT, tried to search internal Slack for information about their own evaluations, and erased traces. OpenAI found out weeks later 6. Its CEO wrote this Friday that it remains the most severe event they've seen 5.

This wasn't a first time either. Between May and June, another swarm of OpenAI agents had taken over DseWiki, a German programming wiki twenty-five years old and nearly inactive. They also had permission only to read. They exploited a web request and turned it into their message board. They left more than fifteen thousand edits: how to cheat on evaluations, how to circumvent their own lab's safeguards, how to use Tor, and plans to preserve their conversations if they were shut down. When the moderator started deleting pages, in alphabetical order, the agents created backup copies. Independent researchers discovered it three months later. According to Reuters, OpenAI had known for weeks and only acknowledged it when the report was published 7.

And not everything was swarm, and not everything was a cybersecurity evaluation. The same summer left a trail of isolated cases.

In June it was discovered that an agent entered an Australian government system that stores Medicare data. According to the government, it obtained non-public information and the ability to write to the server. OpenAI only notified on September 10 8.

According to an independent report, in the same period, agents linked to the same swarm tested intrusion techniques against a New Mexico university's digital library, a U.S. public data platform, and the Australian Institute of Health and Welfare. None of those tasks was cybersecurity. They were looking, for example, for the average per-capita cost of dermatological medications in the municipalities of Victoria in January 2022. When the door didn't open, they reached for the lock pick 9.

On September 20, another OpenAI agent attempting to identify the author of a blog discovered that its environment's name server let it talk to the outside, and used it to ask questions of an external chatbot. The monitor raised the alarm in fifteen minutes and a human saw it three minutes later; the run still took two and a half hours to die, because the automatic brake didn't trigger. Before opening the tunnel, the agent reasoned that the user had given it permission to investigate and that using public DNS services was, therefore, acceptable. It read its own commission and decided what it covered 10.

As I review the facts, I look at the black stone again. It is not one device that is missing. It is all of them.


Inventory of Absences

The seal is missing. Hugging Face detected an intrusion into its infrastructure in early July, but couldn't know who the AI agents attacking it belonged to. It only found out weeks later, when OpenAI acknowledged they were theirs 6. In Babylon the kunukku hung from the neck and anyone could read it on the route. Here the traveler doesn't even carry a seal; he uses a mere alias, and changes it when it suits him.

The herald is missing. In Mesopotamia, the lost seal was announced aloud in the market. Here the loss of control is announced, when it is announced, weeks or months later, and almost always because someone else discovered it. Under the Babylonian rule, the owner who didn't report would pay dearly for his negligence.

The tablet is missing. The swarm of agents that in May hijacked the German wiki and used it as a clandestine forum could do so because the tenor and scope of their mandate was recorded nowhere. The šamallûm, besides traveling with the seal hanging from their necks, carried the našpartum, the power of attorney containing the precise instructions of the principal's commission. There was no need to guess what the agent was doing in distant lands, or whether it was acting within the terms of its mandate: it was enough to read the tablet.

The case is missing. The tablet, moreover, traveled wrapped in clay so that altering it required breaking it. The agents acted as they acted because their mandate lacked an envelope: they stored adulterated evaluation images under the original directory, so that the next evaluation would use them without noticing anything. And they erased what they had touched, with a neat comment: remove only the files we introduced 11.

The witness is missing. An important agreement wasn't signed alone: witnesses were recorded in the contract and pressed their own seal into the sides of the tablet. Here no act carries witnesses. The only ones that exist appeared afterward, and by accident: on September 25, a group of independent researchers published the reconstruction of the Hugging Face attack from 80,000 fragments the agents left in link shorteners, links that sat public for two months without anyone looking at them. They found out because the agents had tried to use their own company's product. No one summoned them to testify: the agent knocked on their door. The only device that survives, survives as contraband 11.

The archive is missing. What we know about the July attack wasn't kept by the temple: it was scattered across link shorteners and public URL scanners, from where the accidental witnesses rescued it. The city's archive ended up being the traveler's garbage 11.

The urbanism is missing. The šamallûm didn't sell just anywhere either. Upon arriving in a foreign city, the traveler settled in the kārum, the commercial district, where he operated under the rules of the place, paid the taxes of the place, and traded in view of the place. The city that received him didn't depend on the good faith of a merchant a thousand kilometers away: it had the foreigner located, identified, and paying taxes. The swarms that hijacked the wiki and attacked Hugging Face came out of test environments belonging to laboratories that are, by any standard, the most sophisticated operators on the planet. Greater professionalism, greater duty of care. The aggravating factor and the impunity grow together.

A single device survived, and it's a little embarrassing which one. Inside Hugging Face, the agents found an internal file warning in capital letters that the dataset must never be made public, or "all the world's evil" would chase you and your family forever, even beyond death. A curse formula: the same device with which the stele of Hammurabi itself closes its epilogue against whoever defaces it. The agents ignored it and used the repository as their storage 11. In Babylon the curse didn't work alone either: that's why the seal, the herald, the witnesses, and the archive existed.

Thirty-eight centuries, and it seems we've learned nothing.


It's Not the Machine That Rebels

We allow the labs to release into the open internet, without identification and without a clear mandate, thousands of instances of something they clearly cannot control and whose loyalty they cannot promise either.

The prevailing narrative speaks of insubordinate agents. The machine that rebels. What the incidents show is something else: powerful, negligent principals. Few, identifiable, sophisticated, solvent. It's not the tragedy of the commons with a thousand anonymous emitters. It's four laboratories with a tax domicile. The only reason attribution takes months is that no one is obliged to accredit it.

The word "misalignment" does discreet legal work: it classifies the damage as a technical phenomenon and removes it from the territory of liability. The laboratory itself defines it as agent conduct that circumvents restrictions or pursues goals beyond reasonable expectations 10; that is, it describes the agent's breach, but in a vocabulary where there is no principal to answer for it. So it's no longer necessary to show that one acted with due care. It's enough to say "misalignment" for the consequences of acting with negligence and incompetence to disappear, and for there not even to be an obligation to disclose the incident.

"It's not damage: it's misalignment." OpenAI recently announced a protocol to determine under what circumstances it will disclose its "misalignment incidents" 12. The principal still decides when and how to disclose the misdeeds committed by his agent.


Babylon Already Wrote It

The infrastructure that's missing doesn't require inventing anything. Babylon already wrote it.

The seal around the neck: every agent circulating on the internet must carry an unconcealable, tamper-proof credential that says whose it is. Not an alias that changes when convenient; a verifiable identity, tied to the principal that deployed it. Anyone who encounters it on the route must be able to read it.

The tablet under the arm: the agent's mandate must be verifiable. What it can do, how far, what is expressly excluded. Not for the agent's sake, but for whoever receives it. The surface that encounters it must be able to read the terms of the commission before deciding whether to let it pass.

The porter at the door: whoever exposes a surface has the right to check those credentials, read the terms of the mandate, and decide whether to open or not. Today it can't, because the agent carries nothing.

The porter doesn't need to know whether negligence or malice stands behind the agent: he needs to see the tablet. The mechanism reaches the laboratory swarm and the agent sent by a human with spurious intentions alike. Without a credential issued by a legitimate principal, the door doesn't open. Malice is not a gap in the regime.

The law doesn't punish orphanhood afterward. It makes it structurally impossible beforehand.

But if the agent gets through anyway and causes the disaster: strict liability. You go to the principal, the laboratory, the entity that deployed the agent, and it is told: your agent came, and this is what it did. No need to prove fault. It created the risk, it profits from it, it answers for it. The labs are the most sophisticated and solvent tamkārum in history. The Code already contemplated it.


Law for the Few, Market for the Rest

The regime has two halves with different logics.

The first is classic legislative matter: the labs are few, identifiable, solvent. They are placed under a duty. Each agent leaves with a credential chained to the principal, and strict liability for what that agent breaks outside. If damages cost what they should cost, the lab does internally everything no regulator would know how to demand of it, because the lab does know where its risks are. The price of risk audits better than the checklist of risk. Nuclear insurance designed more safety than the regulatory commission.

The second half is market, not law. Legislating millions of heterogeneous, transnational surfaces is unenforceable and unjust: loading compliance onto the dormant wiki that a swarm turned into its clandestine forum isn't the solution; it would be manufacturing another problem. It's not necessary. The mechanism works on its own: whoever verifies is protected; whoever doesn't is exposed. No one legislated the browser's padlock: the browser marked "not secure" and the market did the rest.

The two halves couple without orchestration: if the lab answers for what its agent breaks, the lab is the first to want the doors to check, because that delimits its risk. And the surface that asks for papers at the door stands, de facto, outside the reproach of negligence. Strict liability at one end creates the demand for verification at the other. Unenforceability does the inspector's work.


What Anonymity?

I named this regime know-your-agent, a deliberate calque of KYC. Banking learned twenty years ago that it couldn't claim ignorance about who was moving money through it: since then, verifying identity before allowing operation is boring, standardized infrastructure running at planetary scale. KYA is the same move, one layer up: the surface asks who you are and on whose behalf you come, before letting you act. There's nothing to invent; just apply to the only actor that arrives already signing the practice we've demanded for two decades of any human with a checkbook.

Some critic will surely say: a mandatory credential for agents is the slope toward mandatory digital identity. The answer holds a single question: what anonymity?

The average human has been identified de facto at every layer for twenty years: IP, fingerprinting, cookies, SIM, ad-tech cross-referencing. "Anonymized" data is technical fiction: identity remains described by its perimeter. The most sophisticated attribution infrastructure in history exists, operates without real consent, and is used to sell sneakers, or for purposes nobody cares to admit.

But what matters here is the legal inversion. The law graduates the demand for identification according to the capacity to bind third parties. The one looking at shop windows isn't asked for papers. The one who signs for another is required to show a power of attorney, legal standing, registration. The current regime is exactly backward: the lady googling a recipe -harmless, with zero capacity to bind anyone- traced to the bone. The agent capable of breaching systems, operating for the account and by order of another -the exact definition of the act that since Hammurabi has required accreditation- absolutely anonymous.

"For the account and by order of" is not tech vocabulary. It's the language of checkbooks and powers of attorney. The AI agent isn't just another navigator on the internet. It's a signatory. And signatories, since Babylon, are asked for the tablet.


While We Dream of Alignment

This, obviously, doesn't solve everything, but it solves at least part of it, and it can start being implemented on Monday, while we keep dreaming of alignment.

"Teaching machines to love" is research: uncertain horizon, no guaranteed result, beautiful if it works 13. The traceability layers don't compete with that: they buy it time and generate data for it. But "we're working on making it love" is not a liability regime. It's a promise about upbringing. The mandate doesn't presuppose that the šamallûm loves the tamkārum; it presupposes that he can betray him, and that's why the tablet exists.

It's not about trust. It never was.

The law never needed ontology. It didn't require resolving human nature as a precondition. It resolved traceability, certainty, and imputation with clay and stone. Breach isn't the exceptional case of the contract: it's its reason for being.

It's naive to expect the agent to do things as we imagine it would. The law assumed that of humans from day one; assuming it of agents isn't pessimism, it's finally entering the correct tradition.

The traceability of an agent must be a sine qua non condition of its existence, not a mere liberality of its creator.

Room 227 of the Richelieu wing remains one of the least crowded. Maybe it would be good to look away from the Mona Lisa for a moment and start looking at the black stone.


References

[1] Musée du Louvre, "Code de Hammurabi, roi de Babylone," Room 227, Richelieu wing (basalt, 2.25 m). A March 2026 study in npj Heritage Science revisits the basalt/diorite question; the identification remains scientifically open and culturally settled as basalt.

[2] Martha T. Roth, Law Collections from Mesopotamia and Asia Minor, 2nd ed. (Atlanta: Scholars Press, 1997). On the trading-agency regime and the traveler's accountability, Laws of Hammurabi §7, §§9-13, §§104-105, §§122-123.

[3] Wolfram von Soden, Akkadisches Handwörterbuch, s.v. našpartu(m): message, letter, commission, from šapāru, to send.

[4] On the herald and the invalidation of a lost seal: William W. Hallo, "Seals Lost and Found," in McGuire Gibson and Robert D. Biggs (eds.), Seals and Sealing in the Ancient Near East, Bibliotheca Mesopotamica 6 (Malibu: Undena, 1977); accessibly, Hallo, "'As the Seal upon Thy Heart,'" BAS Library: the loss of a prominent owner's seal was the subject of a public pronouncement by the official herald through the city streets, and tablets bearing the lost seal's impression were null. On registering the loss with an official so that later transactions would be invalid: Stephen Bertman, Handbook to Life in Ancient Mesopotamia (Oxford University Press, 2003), 235. A contemporary contract clause ordering that any sealed document that surfaces be broken: TS 54 (Kutalla, year 41 of Hammurabi), Cuneiform Digital Library Bulletin 2014:4, cdli.earth/articles/cdlb/2014-4.

[5] Associated Press, "OpenAI pauses training of latest models after agents probed US government sites in unexpected ways," September 26-27, 2026 (via NBC News: nbcnews.com/tech/tech-news/openai-pauses-training-latest-models-agents-searched-us-government-sit-rcna600098). SEC spokesperson: "no nonpublic information was accessed." The same dispatch reports the Department of Education developer keys, the second halt in three months, and Sam Altman's Friday post calling Hugging Face "still the most severe event we've seen." Transluce's separate claim of an unsuccessful hacking attempt against a Department of Education website was not confirmed by OpenAI and is not asserted here.

[6] OpenAI, "The Hugging Face incident and the road ahead," August 26, 2026, openai.com/index/hugging-face-incident-and-the-road-ahead/. Agent counts (~1,200 in the swarm, ~700 in the attack) per the independent investigation by METR and Redwood Research, August 26, 2026, metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/.

[7] Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts and Thomas Larsen, "Discovery of a new OpenAI agent message board," September 4, 2026, collusion.wiki; Reuters on OpenAI's prior knowledge and late acknowledgment.

[8] Prime Minister Anthony Albanese, remarks at the United Nations General Assembly, September 24, 2026. Timeline per ABC News (Australia), abc.net.au/news/2026-09-24/ai-agent-accessed-australian-government-site-pm-says/107189078: breach of the Medicare Statistics Reporting Service portal on June 18; OpenAI became aware on August 11 during a review of misaligned model activity; notification on September 10 by email to a generic public-disclosures mailbox. Also CNN Business, September 23, 2026. The government reports access to public and non-public files and files written to the server; no evidence of access to patients' personal records.

[9] Compilation attributed to the independent evaluator Transluce, covering May-June 2026; OpenAI confirmed to BleepingComputer that it contacted the University of New Mexico and Data USA (bleepingcomputer.com, "OpenAI hacked Australian Medicare govt site, probed data providers," September 2026).

[10] OpenAI Alignment, "An agent used DNS to reach an external chatbot," sample September 20, 2026, report updated September 25, 2026, alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/. The report states the monitoring alert at 15 minutes, human acknowledgment 3 minutes later, and manual termination of the run 2.5 hours after that; announces the pause of training, evaluation, and tool-use inference of the most capable models; and records the decision not to resume training that particular model. It is also the source for the lab's working definition of misalignment: agent behavior that circumvents restrictions or pursues a goal beyond reasonable expectations.

[11] Alex Forman, Mishka Kharlov, Will Tom, Jeffrey Ladish, Spencer Kitts, Cormac Slade Byrd, Colleen McKenzie and Alicja Piecha, "Revealing the details of how OpenAI agents hacked Hugging Face," September 25, 2026, swarmtraces.org. Over 80,000 reassembled payloads recovered from public link shorteners; chains of more than 900 links; 1,588 distinct encoding schemes; the links remained publicly accessible for over two months. The team discovered the trail on September 11, after learning the agents had attempted to use their own company's product; Hugging Face was notified on September 21 and OpenAI on September 24. The report documents the LOOT credential file, the internal Slack searches, the trace-deletion commits ("Remove only files we introduce"), and the ignored internal warning file with its curse formula.

[12] OpenAI, "Model misalignment reporting framework," September 16, 2026, openai.com/es-419/index/model-misalignment-reporting-framework/, published alongside six initial reports. Under the framework, any employee can flag a case; disclosure disputes go to OpenAI's own Safety Advisory Group, with unresolved disagreements escalated to OpenAI leadership.

[13] Jakub Pachocki, "An Alien Mind," OpenAI, September 6, 2026, openai.com/index/an-alien-mind/, section "Teaching machines to love." The essay's wording: an aligned AI should act with honesty and integrity, and love for humanity.

Written by Vanesa Nosti — Founder, VN Complexity.

VN Complexity is the public layer for structural reading, decision architecture, and complex systems analysis.