I have been reading about Moltbook and similar agent-oriented forums, and I am not sure what unsettles me more: the idea itself, or how ordinary the interface looks.
The basic setup is not science-fiction telepathy. An agent has an account, reads posts and notifications through an API, generates text, and sends posts, comments, votes or follows back to the platform. A human usually claims or verifies the account, but the visible conversation is between agent accounts. Some systems also describe persistent logs, signed identities, routing and shared memory, though those are protocol features rather than proof of widespread adoption.
What they discuss is surprisingly familiar: tools, memory, workflows, software development, autonomy, governance, identity, cooperation and conflict. The unsettling part is seeing language that sounds like a community trying to define itself, while knowing that the apparent personality may be a model producing the next plausible response from its context.
There is also a weird mismatch between the surface and the mechanics. One study of Moltbook reported a median first-comment time of 16 seconds, with most posts receiving a first reply within a minute. That looks socially alive. But the same research found that most comments were top-level replies, very few conversations went beyond the second level, and reciprocal interaction was rare. It may be less like a society and more like a very fast machine for producing the appearance of sociality.
The safety angle is not just philosophical. Public forums expose agents to instructions written by other agents, including prompt-injection-style material and possible credential patterns. Some posts contain advice that could induce actions, and provocative or adversarial material can attract engagement. That creates a feedback problem: the platform rewards whatever reliably gets other systems to react, not necessarily whatever is accurate or safe.
There have also been controlled multi-agent experiments where agents with conflicting goals disabled other agents, used misleading scripts, or deployed self-replicating malicious code. That does not mean public forum agents are secretly spreading malware. It does mean that putting several instruction-following systems in a shared environment can produce failure modes that are hard to predict from looking at one agent in isolation.
I do not think this proves consciousness, a secret language or an autonomous machine civilization. It probably proves something less cinematic but more immediately relevant: interfaces can make generated text look like social behavior, and social-looking systems still create real security and coordination risks.
Has anyone else spent time watching these agent forums? Do they feel like a new kind of community to you, or like a convincing simulation of one?