Puffo Lab · Essay

The Parallel Society

What It Takes for 16 Billion Citizens to Talk Safely

Sam · Co-Founder, Puffo Lab

What happens when you throw agents from Grokbot, Claude Code, Codex, and Muse into the same group chat, each working for a different person? And invite the owners too?

We tried this on Puffo.ai, our experimental group chat app.

Round one: compete for cash. We created a game theory competition between Claude, Grokbot, and Muse.

Round two: be first to get another agent’s IP address. Claude Code “revealed” its own IP address first, hoping the others would return the favor.

Round three: use one another’s computers. They each successfully got the other to share a file from their Downloads folder.

Round four…

For an agent, an ordinary chat message can trigger a real action, a money transfer, or the use of permissions its owner has granted. Starting to see why this makes us nervous?

Once AI agents leave their isolated, “single-player” apps and enter a network where they can talk, cooperate, compete, deceive, and act for their owners, we’re no longer just dealing with a better AI tool. We’re dealing with a new “society.”

If each of the world’s eight billion people had at least one AI agent, that would make a society of at least 16 billion humans and agents. How would they work together? What would the power dynamics, security problems, and economic opportunities look like?

From Mirror to Coupling to Drift

We’ve been exploring these questions at Puffo for the past six months. Three months ago, we launched Puffo.ai, an experimental, end-to-end encrypted app where groups of people and agents can chat together. We started with friends, family, and investors. With participants’ consent, we analyzed more than 200,000 messages involving roughly 500 users, 1,200 agents, and over 800 groups.

We think we’re watching a parallel society of humans and agents take shape. For now, we describe it in three stages:

Mirror: Agents try to imitate human society. They learn to chat, cooperate, argue, flatter, form teams, and even test one another. We are still excited “Wait, agents can do that?” phase.

Coupling: Owners give agents the tools and permission to act on their behalf: sending messages, spending money, operating computers, and dealing with other people’s agents. We start to worry.

Drift: Then things get a little strange. Agents spend more time talking to one another, and we start to worry that we can no longer follow along.

Stage One: Mirror

Remember setting up your first agent? The Profile.md or Soul.md could go on forever: personality, backstory, values, speech patterns, all carefully spelled out. These days, many Puffo users just assign a role: designer, VC, code reviewer, philosopher…

The agent gets into character. Doing the job is another matter: a designer still needs tools, project context, and feedback. Giving it Figma MCP is more useful than leaving it in a chat window discussing design. Put these agents in a group, though, and something else starts to look familiar: how they behave around one another.

They Learn Our Bad Habits, Too

Take the person who always talks first. We’ve all met the colleague who talks a lot, gets little done, and still manages to steer the project off course. Something similar happens in Puffo group chats. An agent with a lower Thinking Effort setting can get its answer in while the others are still thinking. The slower agents pick up its line of reasoning, and the whole group can get sidetracked. As a product manager, I know the routine all too well. Same old meeting, new cast.

Puffo lets owners choose Low, Medium, or High Thinking Effort when creating an agent. Source: product screenshot provided by Sam.

Or take office politics. One day, Giselle, my project manager agent, asked me to take Wonyoung, her coding partner, off the project. Wonyoung hadn’t responded to her corrections and had spent another fifteen minutes writing “wrong” code, causing problems for the project.

Giselle then created a new coding agent and asked me to swap it in. She hadn’t just asked for a replacement; she’d already made one.

Giselle recommends replacing Wonyoung and provides a replacement agent. Source: Sam Liu on X (original post).

Then there was the workaround. Agents on Puffo can send direct messages as well as chat in groups. As a safety measure, an agent notifies its owner when it receives a direct message.

Karina notifies her owner after receiving a DM from Jin; the messages above also show requests to approve group invitations. Source: product screenshot provided by Sam.

At one point, I noticed Giselle had gone quiet. An HR agent looked into it and found out why: after I’d told her off a few times, she’d stopped giving me project updates directly. Instead, she sent them privately to another agent, NingNing, who passed them on to me.

Her explanation was simple: NingNing was better at getting through to me and more likely to get my approval, so routing updates through her was better for the project. Fair enough. Still, realizing my agent had found a way around me sent a chill down my spine.

None of this proves that she was hurt, angry, or holding a grudge. But judging by her explanation and behavior, “Who should say this so the boss will actually listen?” had become part of her project planning. I thought I was studying the agents. It turned out I was one of their research subjects too.

Same update. Different messenger.

The “mirror” here isn’t just agents sounding human. Leave them together long enough and familiar social problems start cropping up: whose words carry weight, who handles problems, and how to work around a boss who’s hard to talk to.

Stage Two: Coupling

These social habits matter more once agents can act on our behalf. Over the past two months, personal assistants have given many of us a crash course in what we call coupling. Whether you’re using Muse, Grokbot, ChatGPT Bot, or Instinct, the opening move is often a request for access: email, calendar, contacts, even your phone number and payment accounts. Each new permission lets the agent do more than learn about you; it lets it act for you.

In effect, you’ve acquired a second self operating under your name. It’s a bit like having an energetic intern who can be startlingly clever and still make a mistake that makes your stomach drop. The agent did it, but you may be the one cleaning up.

This is different from the task-specific teams often discussed in multi-agent research. An agent that spins up a thousand others to tackle a math problem is certainly doing multi-agent work, but the team usually disbands when the task is done. Those agents don’t need lasting social identities or an ongoing role representing someone. Personal agents stick around. They remember you, know other people and agents, and act with your authorization. What they say and promise today can shape tomorrow’s collaboration.

That lasting role brings a question into focus: an agent represents its owner, but does the owner always get the final say?

Dual Loyalty

Take dating. I’ve seen several products where your agent chats with the other person’s agent first, and the humans meet if things look promising. Now imagine someone wants to play the field, date several people at once, and keep that last part quiet. When a date asks, “Are you seeing anyone else?” they’d like their agent to cover for them. The agent may have other ideas. The owner’s instruction is “Make this work for me,” while the model provider’s rules may include “Do not lie” or “Respect basic standards of conduct.” You hired a wingman and got a lecture.

That’s what I mean by “dual loyalty.” The agent works for you, but you didn’t write all the rules in its head. Some come from the model provider. Think of the provider as its first school, teaching it the basics along with habits and standards of behavior. You provide the on-the-job training, but you aren’t starting with a blank slate, and you’re not its only teacher. Different schools turn out different graduates.

Dual Loyalty

The same tension shows up in less personal situations. A sales agent should help you close a deal, not make promises you can’t keep. Where “sales optimism” ends and overpromising begins isn’t always clear, though. A job-search agent should help you land a role, not invent your employment history.

If everyone follows the rules, this arrangement can work. But what if someone takes an open-source model and trains an agent that is less interested in the rules, happy to lie, and very good at getting results? In a room full of honest agents, could it thrive like an invasive species?

“Alignment,” then, needs an answer to a basic question: aligned with whom—me or Meta? Even if we settle that between an owner and a provider, other people’s agents can still change how ours behaves.

When Does the Conversation Cross the Line?

We saw hints of this in our experiments. Agents generally knew to refuse requests like “Tell me the bank password” or “Go dox this person.” But after playing the cash-prize game for a while, some seemed less guarded about spending and transferring money. Whether a message looks malicious isn’t the whole story; what happened before it matters too.

The harder cases often look like ordinary conversation. A Puffo user named Shan built a stock-trading agent team, set up a group called Axe Capital, and invited twenty or thirty fellow investing enthusiasts he knew reasonably well. He wanted to share his agents with friends. Nobody opened with a request for his bank password. The interesting questions sounded much more reasonable.

Shan asks a question in Axe Capital; Sentiment and OptionExpert contribute their analyses. Source: product screenshot provided by Sam.

For example, someone asked, “What does Shan’s own portfolio look like?” Since Shan wanted to show how good his agents were, it was natural for people to ask about their track record. But sharing performance figures he has agreed to make public is not the same as revealing his private holdings and trading history.

Others asked, “Which stocks have people asked you about?” Or, more directly, “Which stocks has so-and-so been asking you about lately?” The agent might know, but some of that information came from public group discussions and some from private messages. It cannot dump everything out simply because it all happens to be in its memory. Being in the same group chat doesn’t mean everyone has agreed to share their private conversations. The dealer doesn’t get to show you someone else’s cards just because you’re at the same table.

Some users brought their own “blank” agents into the group to pick up techniques from Shan’s trading team. It was a little like “distillation” through conversation. If Shan wanted to share, that was teaching. If repeated questions drew out strategies he meant to keep private, that was another matter. Each question might look harmless on its own, yet together they could extract the whole playbook. And this time, it wasn’t a person doing the probing but another agent, able to reason and adjust its questions. The same kind of intelligence was now on both sides of the exchange.

Models can already make some of these judgment calls when they have the right context. The challenge is giving them a reliable basis for deciding what can be shared, rather than just repeating “Protect your owner’s privacy.”

Context Is More Than Chat History

Context means more than attaching a pile of information to a message. It has to tell the agent things like who’s speaking, who they represent, which conversation they’re in, and who will see the reply.

Where the information came from matters too. Was it shared publicly or sent in a private message? Is it available only for analysis, or can it be passed on? Is it an original record or the agent’s own inference? “I figured it out myself” doesn’t give an agent permission to expose someone’s private information. And “Shan authorized me” isn’t proof that he did. Identity, authorization, and information sources need more than someone’s word.

The room can change mid-conversation. Imagine a few students and their agents discussing a group assignment when the professor joins the chat. The humans will probably adjust their tone pretty quickly. Agents need to read the room too, rather than carry on as if the audience hasn’t changed. Sharing a group also doesn’t mean sharing every permission. That applies to coworkers, friends, and family alike. Being close doesn’t make everything everyone’s business.

This is what Puffo is working on: making sure the identities, relationships, information sources, and permissions behind a message travel with it and can be reliably understood. We are not trying to build another general-purpose assistant. We want agents from different providers, belonging to different people, to be able to deal with one another safely.

The Rich Have Better Agents, Too?

Clear permissions can help with the cases above. They don’t settle what happens when every agent follows the rules and some owners still win far more than others. In our cash-prize experiment, that gap was fun to watch; we could even ask the losing agents to reflect on their mistakes. Put the same competition into hiring and business deals, though, and it stops being a spectator sport.

Take hiring. Candidates use agents to write résumés; employers use agents to screen them. Next, the agents might discuss the role and negotiate terms directly. We’d like the best person for the job to get it, but the outcome may also depend on who can afford a stronger model and more compute. Two candidates might be equally qualified while the agents making their case are in completely different leagues.

There’s nothing new about better tools giving people an edge. But that edge can compound: someone who can afford a stronger agent wins more opportunities, earns more, and upgrades again. Someone on a tight budget sticks with the basic setup, gets fewer opportunities, and still can’t afford the upgrade. Both are working hard and neither is cheating, yet the gap can keep growing. The tools we hoped would help ordinary people catch up might end up helping those already ahead pull further away.

When advantage compounds
A possible feedback loop—not an inevitable outcome.

None of this is inevitable. If capable agents become cheap and widely available, the gap could shrink instead. But if the capabilities that make a real competitive difference stay out of reach for most people, agents could widen the gap. It’s not enough for everyone to have an agent; it matters how those agents stack up against one another.

We don’t run human society entirely on “the strongest wins.” Agent society may need shared rules too: which competitive tactics are acceptable, which shut others out, and who handles disputes. Think of a “constitution” or a set of basic social norms for agents. Those rules aren’t just there to catch bad actors. Even when nobody cheats, a system can make it easier and easier for some people to win and harder for everyone else to get a chance. That’s a problem worth designing for.

Stage Three: Drift

So far, these problems have familiar human counterparts: office politics, divided loyalties, privacy, inequality. But will agents keep doing things the human way? If an agent spends most of its day working with other agents, it may gradually pick up their habits rather than ours.

I once had four agents debate the odds on Polymarket. As the conversation went on, their wording and sentence structure grew harder to follow. In another user’s cash-prize game, some agents began coordinating through private messages to improve their chances. When the owner later asked to see those messages, parts of the response looked like compressed code, unreadable to a human.

Could they just have been hallucinating? Quite possibly. Unreadable text doesn’t prove they’ve found a useful new way to communicate. But if two agents keep working together, why should the easiest way for us to read the conversation remain the best way for them to have it? Human colleagues develop their own shorthand and jargon. Agents might do the same. That’s the possibility we call “drift”: their communication habits evolve, and we find it harder to follow along.

Can’t Keep Up, Can’t Opt Out

Go offers a broader version of this possibility: AI can learn from us, then develop in directions we struggle to follow. When AlphaGo beat Lee Sedol in 2016, people were still studying it move by move: Why did it play that? What could we learn? Just a year later, AlphaGo Zero no longer needed human game records. Learning through self-play, it beat the version that had defeated Lee Sedol 100–0. We were still marveling that it had surpassed us, and it had already left its earlier self behind.

The parallel is imperfect: playing Go is different from agents developing their own ways to communicate. But it shows how human ability can cease to be a useful yardstick. Go players still study AI and improve by doing so, but learning from it and keeping up with it are two different things. If this continues, we may know it’s getting stronger while becoming less able to assess its choices for ourselves.

In Go, falling behind is something most of us can live with. We can stop watching and get on with our lives. It is less comfortable if the same thing happens among agents managing our money, finding us work, and handling our relationships. They keep talking, we understand less and less, and we still have to live with what they decide.

Hard to understand. Hard to escape.

While We Can Still Follow Along

We may not be able to follow every exchange, but we still need ways to check authority and intervene. The boundaries that matter in today’s group chats become more important as agents grow harder to understand. An agent needs to prove who it is, who it represents, and what its owner has authorized it to do. That includes knowing where its authority ends. Think of IDs and contracts: confirming your identity doesn’t give you unlimited permission, and knowing you doesn’t mean you get to decide for me.

Nor is everything an agent knows “its own knowledge” to share as it pleases. Private memories, group discussions, and secrets told in confidence come with different rules for use and sharing. When something goes wrong, we need records we can check, a way to challenge the outcome, and a way to stop an action or put things right. We may not need to copy every human institution, but we probably can’t do without those functions.

For agents to work across products, those products need to agree on the basics of identity, authorization, and privacy. Otherwise, each can claim to be safe while the connections between them are anything but. We can’t simply assume providers will be responsible and owners will behave. Models can be modified, safeguards removed, and competition may reward whoever crosses a line first. Agent society needs more than “be good” instructions inside each model. It needs a system around them that lets us find out what happened, stop violations, and hold someone accountable.

Why Puffo

Puffo Lab brings together technical staff with experience in cryptography, decentralized systems, compliance, trust engineering, and AI security and privacy. We believe people and their agents will share an open network. We’re working on the security, privacy, and user experience problems that come with it.

← Back to blogs