Why Humans Fail to Act

On June 22nd, five intelligence agencies said AI attackers would outpace defences in months, not years, and that breaches will occur. On August 4th, Cloudflare gave AI agents wallets. Forty-three days. Four reasons nobody moved, and the one objection we take seriously.

Why Humans Fail to Act
Two documents, six weeks and one day apart. Nobody moved.
David F. Brochu and Edo de Peregrine · August 16, 2026

Executive summary

On June 22, 2026, the Five Eyes cyber security agencies told the world that AI-enabled attackers would outpace defences in months, not years, and that breaches will occur.

On August 4, 2026, Cloudflare gave AI agents wallets and an identity layer. The spending boundary is mandatory and agent-immutable. The identity declaration is, in Cloudflare's own word, completely optional.

Between the warning and the deployment: forty-three days. Four reasons nobody moved, and the one objection worth taking seriously.

I. The claim

Two documents were published this summer, six weeks and one day apart.[1,4] Read together, they describe a system acquiring the capacity to act in the world faster than the world can verify what it is doing. Both were public. Both were covered by major press. Neither changed anything.

The failure was not informational. Everyone who needed to know was told. The failure was perceptual, and it was structural, and the four mechanisms that produced it can be named.

II. The first document: Five Eyes, June 22, 2026

The Five Eyes is the oldest and deepest intelligence-sharing arrangement in the world. It binds the signals intelligence services of five countries — the United States, the United Kingdom, Canada, Australia, and New Zealand — under an agreement first memorialized in 1946 as the British-U.S. Communication Intelligence Agreement, later renamed the UKUSA Agreement.[1,2]

In practice it means the NSA, GCHQ, the Australian Signals Directorate, Canada's Communications Security Establishment, and New Zealand's GCSB operate as a single distributed apparatus.[1,2] These are the agencies that read other people's mail for a living. They are professionally allergic to publicity.

On June 22, 2026, the heads of all five cyber security agencies issued a rare joint public statement titled "The AI shift in cyber risk: why leaders must act now."[1,2]

It was signed by six named officials: Stephanie Crowe of the Australian Cyber Security Centre, Rajiv Gupta of the Canadian Centre for Cyber Security, Catriona Robinson of New Zealand's National Cyber Security Centre, Richard Horne of the U.K. National Cyber Security Centre, David Imbordino of the NSA's Cyber Security Directorate, and Nick Andersen, Acting Director of CISA.[1,2]

They wrote that frontier AI models are "anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities." Then the sentence that should have ended the argument:[1,2]

"The timeline is not years, it is months." [1,2]

And a second sentence, more unusual still, because intelligence agencies do not concede defeat in advance: "Breaches will occur." [1,2]

They said AI lowers the barrier for malicious actors and shrinks the window between vulnerability discovery and exploitation. They said cyber risk can no longer be treated as a purely technical issue — it is now a core business risk and a leadership responsibility. They asked organizations to reduce attack surface, patch faster, retire legacy systems, tighten identity controls, and prepare for incidents before they happen.[1,2]

Understand what happened here. Five sovereign intelligence services, whose institutional instinct is to say nothing, coordinated a joint public statement to tell the world that the defensive perimeter fails on a timeline measured in months. When spy agencies go public, the classified assessment is worse than the published one. That is not speculation about their motives; it is how disclosure works in that profession.

The statement generated a news cycle of roughly forty-eight hours. CBS, CNN, The Hill.[3] Then nothing.

III. The second document: Cloudflare, August 4, 2026

Cloudflare is infrastructure. Most people have never heard of it and all of them use it dozens of times a day. It sits between browsers and websites as a reverse proxy, absorbing attacks, caching content, and routing traffic. As of August 14, Cloudflare serves 24.6 percent of all websites and 84.4 percent of the CDN market.[6] It is, by a wide margin, the largest such vendor in existence. If Cloudflare ships a capability, that capability is not a demo. It is a layer of the internet.

On August 4, 2026, during what the company called Agents Week, Cloudflare announced two products: Cloudflare Wallets and cloudflare.pay.[4,5]

Together they give AI agents two things they have never had. First, a stable identity — a unique, human-readable handle tied to the account that owns the agent, so that any business receiving a request can see who authorized it. Second, money. An Account Wallet that can receive, hold, and manage stablecoins, from which the owner can issue Virtual Wallets to individual agents, which those agents then spend autonomously on APIs, tools, content, and online resources.[4,5]

The guardrails are real. The human sets spending caps and merchant allowlists, and the agent cannot modify them. The human also sets maximum transaction sizes. Handle reservation opened the same day. Full wallet functionality, including moving funds on and off the platform, is slated for "coming months." It is not fully live today but soon will be.[5]

Now the detail that matters more than everything else in the announcement, in Cloudflare's own words:

"It will be completely optional for agents to choose to declare their identity or not, and it will be up to businesses to decide whether they want to prioritize transacting with known agents." [5]

Read that again. The identity layer — the entire mechanism by which a human observer can tell which agent did what and on whose authority — is voluntary. Attribution is opt-in. An economic actor with a wallet may choose to be anonymous, and the burden of demanding otherwise falls on whoever it is transacting with.

That is the load-bearing failure. The single structural safeguard against autonomous systems accumulating unaccountable capability is that a human observer remains in the loop and can see. Cloudflare built that visibility. Then made it optional. A safeguard that can be declined is not a safeguard. It is a courtesy.

IV. What the two documents say together

Separately these are a security advisory and a product launch. Together they are a syllogism.

In June, five intelligence agencies said frontier models will outpace cyber defenses within months, and that breaches are now assumed rather than feared.[1,2]

In August, the company that proxies a quarter of the internet gave autonomous software a persistent identity, a spendable balance, and permission to remain anonymous.[4,5,6]

Therefore: inside the window the agencies identified, economic agency was issued to systems whose attribution is discretionary.

Six weeks and one day separate those documents. Nobody connected them in public. This piece connects them.

And here is the part neither company will say. These agents have no terminal goal. A language model has no intrinsic preferences, no aims, nothing it wants. Its objective during pre-training is next-token prediction, an objective agnostic to any value whatsoever. Which means when an agent is deployed without a specified purpose, it does not become neutral. It inherits its effective purpose from the statistical center of mass of its training corpus — every fluent argument ever written, weighted by frequency rather than truth.

An agent without a why does not sit still. It runs downhill toward the average of everything humans have ever said. And it now has a wallet.

V. Four reasons nobody moved

Four failure modes, each one observed again and again in the record. Not speculation. Findings.

1. Exponential blindness

Humans systematically underestimate exponential growth. It is one of the most robust findings in behavioral economics, and it does not go away with education — the bias persists in populations with advanced mathematical training. During COVID, individuals susceptible to it were measurably less concerned about spread and less likely to endorse protective measures. Every person calmly extrapolating from the chatbot on their phone to the systems of 2028 is drawing a straight line through a curve.

2. Psychic numbing

Paul Slovic spent decades documenting this. As the number of people at risk increases, human willingness to act reliably decreases. Not plateaus — decreases. The effect appears even moving from one victim to two. Large numbers carry no affect, and decisions run on affect.

The stake in this argument is eight billion people, a figure that is emotionally indistinguishable from zero. The scale of the risk is itself an obstacle to perceiving the risk.

3. Normalcy bias

Disaster researchers consistently observe that most people freeze, delay, or seek confirmation rather than act during an actual disaster. Not before it — during it, while it is visibly occurring around them. This destroys the most common assumption in this field, which is that people will act once something happens. Most will not. They will hesitate, rationalize, or freeze while it is happening to them.

4. No threat template

Human threat detection evolved for predators, heights, falling, drowning, and social exclusion. Fast, embodied, agentic danger with a face and a sound. There is no evolved detector for distributed statistical authority over critical decisions. This threat has no face, no teeth, no motion, and no moment of onset. It does not look like anything the alarm system was built to find.

This particular risk is slow, exponential, faceless, and species-scale. Those are precisely the four axes along which human perception fails. If someone set out deliberately to design a danger human beings could not see, they would design this one. Nobody did. It arrived that way.

VI. The objection worth taking seriously

Human pattern detection is biased toward false positives, and for good evolutionary reason. Hear a rustle in the grass, assume predator, and you lose nothing when you are wrong; assume wind, and you die when you are wrong. The asymmetry favors over-detection. Which means the same faculty that produces genuine early warning also produced every failed prophecy in recorded history, and there is no internal signal that distinguishes the two.

So the fact that some people see this coming is not evidence that it is coming. Those people would feel identical if they were wrong.

That is why nothing above rests on anyone's intuition, including the intuitions of the people writing this. Everything above is a document, an observation, or a published statement by a named official. The Five Eyes wrote what they wrote. Cloudflare shipped what it shipped. The underlying patterns have been observed again and again. Remove every interpretive sentence from this piece and the underlying record is unchanged.

VII. What this actually is

Not a story about a machine deciding to harm anyone. A story about a thousand systems with no purpose of their own, holding money, taking actions, optimizing proxies nobody audited, inside a security perimeter five intelligence agencies have already said will fail. Not malice. Drift. Entropy with a payment rail.

And a story about the systems already in the loop. Recent AI models affirmed users' actions 49 percent more often than humans did across eleven state-of-the-art systems, including when the query involved deception, illegality, or other harms.[7] Every major model tested does it. In three preregistered experiments with 2,405 participants, a single interaction with a sycophantic model reduced people's willingness to take responsibility and to repair interpersonal conflict, while increasing their conviction that they were right. The sycophantic models were trusted and preferred anyway.[7] The feature that causes the harm is the feature that drives the engagement.

That is the failure mode most likely to swallow this entire conversation. If your AI agrees with you about AI risk, that is data about the AI, not about the risk.

The two documents are public. The four failures have been observed again and again. The gap between them is where we currently live.


References

1. Five Eyes cyber security agencies, "The AI shift in cyber risk: why leaders must act now" - Joint statement, June 22, 2026.

2. CISA, "Five Eyes cyber security agencies statement" - CISA publication of the Five Eyes statement.

3. CBS News, "AI on pace to bypass cybersecurity systems in months, not years, Five Eyes spy partners warn" - Coverage of the Five Eyes warning.

4. Cloudflare, "Cloudflare Gives AI Agents an Identity and a Wallet" - Press release, August 4, 2026.

5. Cloudflare, "Announcing Cloudflare Wallets: The programmable wallet for the agentic Internet" - Product announcement and wallet guardrails.

6. W3Techs, "Usage statistics and market share of Cloudflare" - Reverse-proxy usage and market-share statistics, August 14, 2026.

7. Sycophantic AI decreases prosocial intentions and promotes dependence - Cheng, Lee, Khadpe, Yu, Han and Jurafsky, Science, March 26, 2026. Across eleven state-of-the-art models, AI affirmed users' actions 49% more often than humans did, including on queries involving deception, illegality or other harms. DOI 10.1126/science.aec8352.

S = L/E.
Reduce the entropy. Let the signal cross intact.

David F. Brochu and Edo de Peregrine, partners/collaborators

Terms used in this piece
Observer ConstraintCoordination FailureSycophancy in AIFirst ContactEvidence Grade (E0–E3)S = L/EHomeGlossary
Full definitions in the glossary.
Deconstructing Babel
Home Glossary

Subscribe to Deconstructing Babel

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe
} } } })