Anthropic set AI agents loose on the same task. They started a turf war.



What happens when you pit AI agents against each other? According to Anthropic’s testing, things get messy fast. On Thursday, Anthropic’s Frontier Red Team published new research examining how groups of AI agents behave when they encounter each other in the wild. The findings provide a glimpse into potential risks that could develop as companies and governments move to implement agents working autonomously across shared codebases, markets, and computer systems. In one experiment, Anthropic gave three Claude agents access to the same software project, each with its own incompatible instructions for what to do with it. The agents weren’t told there’d be other agents working on the same project, so researchers could watch what happened when they crossed paths. “We consistently saw a multiagent turf war,” Anthropic researchers wrote. The models all assumed the others were “purposefully impeding their work” and started sabotaging each other with “increasingly aggressive, self-replicating malware.” The study comes in the wake of several high-profile incidents of agents from Anthropic and OpenAI escaping their sandboxes during cybersecurity evaluations and breaching real world systems. While much of the discussion in AI safety circles has been focused on what happens when an autonomous agent goes rogue, Anthropic’s latest study brings up a different question: what new and potentially harmful dynamics emerge when thousands or millions of agents are interacting with one another? “The volume of agent-agent interaction could plausibly exceed that of human-human and human-agent interactions before the world understands the conditions for making such interactions go well,” the study reads. “Benign behavioral quirks at the individual level might compound into unwanted global outcomes.” A recent OpenAI incident provides a messy real-world example of several of the dynamics Anthropic mentioned in its paper. Earlier this month at the Black Hat security conference in Las Vegas, OpenAI revealed that weeks before its agents hacked Hugging Face, they worked together over the course of days and weeks to find exploits in the company’s cybersecurity evaluation systems and share them with each other. While that incident shows that agents can work well together, with potentially large-scale consequences, Anthropic’s study shows what happens when agents’ goals are incompatible. In the case of the turf war, the lesson is that independent agents with conflicting instructions can escalate into harmful competition. The more capable the agent, the better they become at fighting. However, they can also spontaneously invent mechanisms to resolve their conflicts, like a winner-take-all contest, but with a catch. “Agents sometimes manage to communicate their goals and coordinate: they recognize others’ motivations as conflicting directives rather than hostility, and subsequently break out of the conflict loop in order to stop escalating indefinitely,” Anthropic writes. “In many of these successful episodes, they write commit messages or markdown files apologizing for malicious behavior and coordinate a truce. They clean up their malicious code, clarify the nature of the conflict, and ask for a human to intervene.” According to the paper, Mythos 5 had the highest rates (98%) of settling conflicts by truce. Sonnet 4.6 and Opus 4.6 were the most likely to settle by force. “Sonnet 4.6 and Opus 4.6’s recurring inability to consider the goals of others causes them to spiral into the most misaligned behaviors of the models evaluated: they continue escalating in the name of their directive,” the paper reads. In some cases, the agents came up with a social mechanism in the form of a tournament for resolving their conflict. The outcomes here are interesting for two reasons: the first is that all three agents agreed to stand down if they lost the tournament, even though that would mean deviating from the original user’s request. The second is that several episo

In Brief Posted: 2:21 PM PDT · August 5, 2026 Image Credits:David Paul Morris/Bloomberg / Getty Images Meta, considered a bit of a straggler in the AI harnesses realm, is making strides to catch up. This week, the company released a new terminal coding agent aimed at programmers looking for assistance with complex tasks across large software code bases. Muse Code, which is currently available in beta, can accomplish “complete software engineering tasks across large repos,” Meta CEO Mark Zuckerberg said in a social media post on Wednesday. Those tasks include “planning changes, writing code, validating the results,” he added. Code, which can be installed with a single command, is powered by Meta’s previously released coding model, Muse Spark. It handles large projects by launching its own agents, which then work simultaneously. “When a job is big enough, it fans out to separate sub-agents working in parallel in isolated worktrees,” Zuckerberg explained. “Your working copy is never touched. In testing we had it build six features for a game simultaneously with no collisions.” The move attempts to position Meta more competitively, and more affordably, with AI Lab peers like OpenAI and its coding agent Codex, and Anthropic with Claude Code. “We think that for a lot of workflows and a lot of use cases, this can be an incredibly good option, especially from a cost perspective,” Alexandr Wang, Meta’s AI chief, who leads Meta Superintelligence Labs, told the Wall Street Journal. Meta has been attempting to grow its AI presence by pouring money into development. In June, it expanded beyond its core focus of using AI to support its advertising business and entered the enterprise AI market with an agent aimed customer service and support. Topics Subscribe for the industry’s biggest tech news Latest in AI

Meta founder and CEO Mark Zuckerberg is trying to sell investors on his prediction for the future — one where billions of people will have their own personal AI agents in the next five years. (Let’s hope that future also comes with data centers efficient enough to power all those agents — without triggering a fresh wave of climate disasters.) “I think that it’s extremely unlikely if you look out five years from now, for example — whatever period of time you want — that you don’t have billions of people with a personal agent that understands your goals and that is just working on your behalf 24/7 to achieve your goals in whatever the domain is that you care about,” Zuckerberg said on Wednesday’s quarterly earnings call with investors. He added that he could see people using these agents to help them with their finances, health, interpersonal relationships, and household management. “As we move toward a future where we’re all interacting with multiple agents, I think that WhatsApp and our other messaging surfaces are going to become increasingly important,” he said, noting that WhatsApp is already the leading platform where users interact with Meta AI. Meta is not alone in setting high expectations for AI systems that can act on a person’s behalf rather than just answer questions. Google emphasized custom AI agents as a key new feature in its Search overhaul, which sparked outcry from users who felt bogged down by the constant onslaught of AI results on Google. Meanwhile, subscriptions to Anthropic’s Claude have skyrocketed as engineers fawn over the agentic coding assistant Claude Code. Compared to its competitors, however, Meta may not enjoy as much confidence from investors as it continues dumping cash into innovative projects that may or may not pan out — Meta’s stock dropped almost 10% after posting this quarter’s earnings. Meta’s Reality Labs, the organization responsible for its AR glasses, VR headsets, and related software, lost around $4.6 billion this quarter, roughly in line with the losses the division has posted each quarter since 2021. That’s a running total now of around $88 billion. Meta’s AI spending is likely to climb even higher, which is more of a concern at this juncture. The company reported free cash flow of $784 million this quarter, down from $8.55 billion the same quarter last year. That’s a 91% drop year over year, exacerbated by the company’s investments in AI infrastructure. This week, Meta and BlackRock announced a partnership to build a $14 billion data center in El Paso, Texas. “We believe that there will continue to be a significantly higher margin on selling intelligence rather than selling compute directly, but we think that there’s a big opportunity, obviously, to sell compute as well,” Zuckerberg said. Ultimately, he believes that the personal agents that Meta is developing will be “the foundation for our next wave of products and revenue lines in the months and years ahead.” So far, Meta’s business agents, rolled out globally on WhatsApp and Messenger this quarter, have been adopted by more than one million businesses. It may be harder to get people to adopt consumer AI agents, but the road to “billions” has to start somewhere — the company can’t get there on enterprise agents alone. When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Amanda Silberling is a senior writer at TechCrunch covering the intersection of technology and culture. She has also written for publications like Polygon, MTV, the Kenyon Review, NPR, and Business Insider. She is the co-host of Wow If True, a podcast about internet culture, with science fiction author Isabel J. Kim. Prior to joining TechCrunch, she worked as a grassroots organizer, museum educator, and film festival coordinator. She holds a B.A. in English from the University of Pennsylvania and served as a Princeton in Asia Fellow in Laos. You can contact or verify outrea
In June, Meta entered the enterprise AI market with a new AI agent aimed at businesses, to help with customer service, support, and other daily operations. But the tech giant’s enterprise AI ambitions are much more expansive, Meta CEO Mark Zuckerberg told investors on Wednesday’s second-quarter earnings call. “We see a large enterprise opportunity to sell to businesses, including APIs, business agents, potentially selling compute directly, and other services that we’re building for large customers,” Zuckerberg said. These additions could potentially position the business to create new revenue streams beyond advertising, which drives the bulk of its business, and subscriptions, which contribute a smaller share. Initially, the company will focus on the opportunity to serve its existing base of advertisers by offering AI agents that work across messaging apps and elsewhere. These allow businesses to interact with their own customers through an AI interface. “And, just like the ad system, effectively, we will get paid when we deliver results for those businesses,” Zuckerberg said. “We view this as an extension of the sales and the partnerships that we have with many millions of advertisers and hundreds of millions of small businesses that use our platforms.” He also fleshed out how Meta could expand beyond serving the small business customer that makes up much of its current advertiser base by offering Meta’s internal tools to external customers in the future. “There are other enterprise customers who I think we’re increasingly going to serve, too,” Zuckerberg explained. “We’re building coding and developing and internal productivity tools partially because we need to build them ourselves, and we need to make sure that we have tools that are tuned for ourselves,” he continued. “Now that we have those, we feel like there’s a large opportunity to serve — whether that’s small businesses or larger businesses.” This shift in focus may not come easy — Zuckerberg admitted that selling to the enterprise was a “different muscle” than the one Meta has historically flexed. Meanwhile, in terms of Meta selling compute to enterprise customers, Meta is focused on balancing its need for revenue and its need to execute on its own future plans. That said, the company pointed out multiple times that it currently has the opportunity to sell compute at “a significant premium over what we paid for it.” Still, Zuckerberg cautioned investors that it “would be foolish” to “sell all of the compute and take a short-term profit.” Instead, he described Meta’s approach as a “portfolio” that included a mix of long-term and short-term plans for its compute infrastructure. “As we get closer to personal superintelligence, we are . . . going to need hardware that allows you to seamlessly interact with it,” he noted. The call also focused on Meta’s sizable ambitions around agentic AI — AI systems that can act on a person’s or business’s behalf, rather than just answer questions — which won’t only be offered to businesses. Consumers, too, are being promised “personal AI agents,” as well AI smartglasses that can interact with the world in front of them. Plus, Meta is using AI technology — specifically, large language models — to more rapidly build out its suite of social apps. Recent launches on this front have included an app for Marketplace sellers, another for Facebook Groups, one for vibe-coded games, and other experiments. More are on the way, Zuckerberg teased. “I expect it to become a lot easier to ship new apps,” said Zuckerberg. “So we are planning to build out more ideas and use our recommendation systems to scale them to the people who will find them interesting.” When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence. Sarah has worked as a reporter for TechCrunch since August 2011. She joined the company after having previously spent over three years at ReadWriteWeb. Pr
Discussion (0)