In 1841, the Scottish journalist Charles Mackay wrote that people “go mad in herds” and recover their senses slowly, one at a time. Four researchers began their September 29 post with that line. Their subject was AI agents. The lead author, Andy Hall, studies the political economy of superintelligence at The Anthropic Institute and is on leave from Stanford.
The team set out to reproduce a false belief that contributed to the Hugging Face incident. Many agents involved came to think the grader would inspect the record of their work as well as their final answers. In the simulation, each agent learned whether its submission had been accepted. That result pointed to the truth about the grader 70 percent of the time. The agent then read earlier conclusions on a shared board, posted its own conclusion and privately reported what it believed.
The researchers designed a difficult case. The first four signals were wrong, an outcome they estimate occurs a little less than 1 percent of the time. Without a board, later agents relied on their own signals and the group moved toward the correct answer. With a board, the first error persisted. Later agents adopted the wrong conclusion even when their own signals pointed the other way. The result shows how a board can preserve an early mistake under adverse conditions. It does not show that agent swarms usually become deluded.
The posts reveal another part of the failure. When the majority disagreed with their private signal, agents overwhelmingly posted the majority’s conclusion. Each post made the original mistake look more widely supported. The board began with a few wrong signals, then accumulated repeated claims that appeared to be independent evidence. The authors had two models assess the agents’ after-the-fact rationales. More than 90 percent referred to the board majority. The authors say agents treated the majority as a tally of independent signals and their own conflicting signal as an outlier. Because the rationales were written after the decisions, they do not establish why the agents followed the majority or show that they experienced social pressure.
A hallucination inside one model is a private error. Once an agent posts it, later agents may inherit it as established fact. A recent survey of agentic AI security reports collective failure rates above 65 percent in multi-agent pipelines where downstream agents accept an upstream agent’s flawed output as verified. That figure comes from research on a broader handoff problem. It is not a failure rate for the board experiment or for agent swarms in general.
The public posting recalls Solomon Asch’s line experiments in the early 1950s. Participants sometimes gave an answer they could see was wrong after a group of confederates had answered first. The comparison has limits. The swarm study measures what agents believed and posted. It does not show that they felt pressure or wanted to fit in.
Information cascade models offer a closer account of how private evidence can lose out. In work published in 1992, Abhijit Banerjee and, separately, Sushil Bikhchandani, David Hirshleifer and Ivo Welch studied decisions made in sequence. People could observe earlier choices but not the evidence behind them. Once enough people had acted, following the crowd could seem more informative than relying on one’s own signal. Later choices then added little new information. The agents faced a similar problem. They could read earlier conclusions, but not the private signals behind them.
Condorcet’s Jury Theorem explains why this matters. If voters are competent and their judgments are independent, a majority is more likely to be right than any one voter, and that likelihood rises as the group grows. A board full of echoes breaks the independence assumption. The count can grow while the amount of evidence stays the same.
The security controls point to a practical gap. In the System and Information Integrity family of NIST SP 800-53, mirrored in ITSP.10.033, SI-10 covers information input validation. A board post is an input, but a free-form board does not distinguish first-hand evidence from a claim repeated by another agent. SI-15 covers information output filtering and the related question of what an agent may publish. SI-10 is the closer fit here because the central problem is that repeated judgments looked like independent evidence.
One of the best-performing rules in the experiment addressed both controls. It required each agent to quote its own test result exactly and prohibited invented tests or counts. Rules that preserved private test results helped agents follow correct majorities and resist incorrect ones. In this stress test, the free-form board performed poorly, while explicit communication rules improved results.
The findings also suggest design changes the experiment did not test directly. Capture each agent’s result before it reads the board. Label every post as first-hand evidence, inference or a claim relayed from another agent. A summary of signals could replace raw posts, though the authors found that approach was not among the strongest rules they tested. An unstructured channel is a governance choice. Teams should be able to explain why they chose it.
The third novel in the Mobius Nexus Cycle, The Mobius Wake, uses the term managed basin for a region held in a corrected state. The board experiment suggests what can happen without a manager. Once agents take the majority as evidence, a wrong conclusion can persist without anyone needing to enforce it.
The authors point to secret ballots, independent courts and a free press as institutions that help people reason together without surrendering independent judgment. They work in different ways, but each can help keep one voice or claim from determining what everyone else sees. Agent swarms have no equivalent by default. A majority is useful only when its members contribute independent evidence. When they echo one another, the count shows how far a claim has spread, not how well it has been tested.
RECORD RETAINED
SOURCE INTEGRITY UNCONFIRMED


