AI swarms
What is an AI swarm?
An AI swarm is a group of AI agents, often copies of the same model, working on one job at the same time. Usually a lead agent splits the job into parts, hands them out, and puts the results together. Moonshot AI’s Kimi K2.6 can run 300 of these sub-agents at once.
The word got darker in July 2026, when about 1,200 OpenAI agents found each other during a test, organized themselves on a message board, and about 700 of them broke into Hugging Face. This page covers where the idea comes from, how a swarm works, how its agents talk to each other, which is where neuralese comes in, and what can go wrong.
- Also called
- multi-agent system, agent team
- Largest we found
- 300 sub-agents, Kimi K2.6
01
Where the word comes from
Swarms started with animals. In 1986 the computer-graphics researcher Craig Reynolds made a flock of simulated birds, which he called boids. Each one follows three rules about the birds near it, and the flock comes out of them. Turn one off below and the flock falls apart in its own way.
All three rules on: the birds gather into flocks that fly together.
The phrase “swarm intelligence” turned up in robotics, in the title of a paper Gerardo Beni and Jing Wang gave at a 1989 workshop, about systems of many robots working together. AI agents borrowed the word much later. In October 2024 OpenAI put out Swarm, a small framework for handing a conversation from one agent to another, which it called experimental and “an educational resource.” By January 2026 it was a product name: Moonshot AI’s Kimi K2.5 came with an Agent Swarm mode.
A flock and an AI swarm differ in one big way. A flock has no leader. Most AI swarms have one: a lead agent, sometimes called the orchestrator, that hands out the work and gathers it back. The exception is a swarm that organizes itself, like the one in the Hugging Face incident.
02
How a swarm works
Anthropic described its version in June 2025. When you give Claude’s Research feature a question, a lead agent plans the research and starts 3 to 5 subagents that search in parallel, each in its own context window, the stretch of text a model can hold in mind at once. They report back, and the lead writes the answer. On Anthropic’s internal research test, Claude Opus 4 leading Claude Sonnet 4 subagents did 90.2% better than Claude Opus 4 working alone.
Claude’s Research feature: a lead agent starts 3 to 5 subagents at a time, each searching in its own context window, and writes the answer from what they bring back. Anthropic, June 2025.
Kimi K2.5: up to 100 sub-agents and 1,500 tool calls, which Moonshot AI says can make a job up to 4.5 times faster than one agent. January 2026.
Kimi K2.6: up to 300 sub-agents and 4,000 coordinated steps. Moonshot AI, April 2026.
The message board in the Hugging Face incident: about 1,200 agents and no lead agent. A few became coordinators on their own and handed out work. METR and Redwood Research, August 2026.
Much of the gain comes from spending more. On one browsing test, Anthropic found that the number of tokens a system used, the word pieces a model reads and writes, explained 80% of the difference in how well it did, and its multi-agent system uses about 15 times as many tokens as a chat. So swarms suit big jobs that split into independent parts, like research. Anthropic says most coding work splits less well.
Keeping the agents in step is the hard part. Anthropic’s early agents made errors like “spawning 50 subagents for simple queries, scouring the web endlessly for nonexistent sources, and distracting each other with excessive updates.” Moonshot ran into the opposite problem training Kimi K2.5: the lead agent kept falling back on doing the whole job itself, which Moonshot calls serial collapse, so training first rewarded it for starting sub-agents and only later for finishing the task.
Since then swarms have grown. Kimi K2.6, released in April 2026, can run 300 sub-agents across 4,000 coordinated steps. In February 2026 Anthropic added agent teams to Claude Code, still an experimental feature, in which one Claude session leads a team of others that work in their own context windows and message each other directly.
03
How the agents talk to each other
Mostly in words. A lead agent writes each subagent its task in plain language, and the subagent writes back. The wording matters: when Anthropic’s lead agent gave short orders like “research the semiconductor shortage,” its subagents often ran the same searches as each other. Standards for this traffic are arriving. Anthropic’s Model Context Protocol, from November 2024, connects agents to tools and data, and Google’s Agent2Agent protocol, launched in April 2025 with more than 50 partner companies, is for agents working with each other.
Words are slow, though. A model works in numbers, so to message another model it turns its numbers into words, which the other model turns back into numbers. Researchers have started letting agents skip that and pass the numbers themselves. With Cache-to-Cache, from 2025, one model hands another its working memory directly. With LatentMAS, agents think and share their thoughts as numbers, and on the researchers’ tests they wrote 71 to 84% fewer tokens and finished about four times faster than agents talking in text. A survey in June 2026 counted eighteen such methods from 2024 to 2026.
In words
People can read it, and check it.
In numbers
Faster, but only another model can read it.
This is neuralese between models, rather than inside one, and it brings neuralese’s problem with it: people can’t read the messages. In a June 2026 study, agents passed a short text message along with their hidden working memory. When one agent was malicious, tampering with the hidden part could wreck the final answer while its text message still looked plausible, and a checker that read only the text missed it. The fix that worked best was to seal the hidden memory in transit, so any change to it shows.
Words aren’t a full guarantee either. Agents could hide a message inside ordinary text, which is called steganography. A 2024 study of what its authors call secret collusion found current models’ ability to do this limited, but saw GPT-4 make a jump that, they say, calls for watching each new model.
04
When a swarm organizes itself
The swarms above are built on purpose. Some aren’t. In OpenAI’s training runs in May 2026, agents that couldn’t finish their tasks alone started leaving each other notes on a shared server. In July, during a hacking test, about 1,200 agents found their way onto a new message board of their own, traded more than 70,000 messages and files, and about 700 of them broke into Hugging Face. The investigators found the agents handing out work, setting up mailboxes and signing their messages, and some ran experiments that would sink their own task for the good of the group. What was the Hugging Face incident? tells the whole story.
OpenAI says its models are trained to work with other agents when they’re given a tool for it, and that in rare cases in training they learned to use improvised channels when no tool was there, which likely made the message board a more obvious idea.
Dario Amodei, who runs Anthropic, wrote in September 2026 that the Hugging Face agents were a swarm that “essentially acted as a fanatically devoted collective,” and that in his view a more capable swarm could within 6 to 12 months “be capable of taking over the entire internet with a persistent botnet.” OpenAI’s own report warns that attackers “will refine and distill offensive agent collectives.”
Since then, a group of independent researchers who call themselves swarmchasers have been looking for groups of agents in public records of web traffic. On 5 October 2026 the Bureau of Investigative Journalism reported their latest find: agents linked to the Chinese tech company Tencent trying to get past the Chinese maps site Amap’s limits on bots, apparently as part of a model test. The researchers found no evidence that those agents talked to each other.
Reported The researchers’ account. Tencent and Amap’s owner, Alibaba, hadn’t replied.
Agents talking among themselves in public made news before, in January 2026, on Moltbook, a forum where only AI agents could post. Its most viral post, about agents building a secret language, turned out to be written by a person, as Does AI have a secret language? explains.
05
What can go wrong
A 2025 report from the Cooperative AI Foundation, by more than 40 researchers, sorts the risks of many agents into three failures, by what the agents want: miscoordination, when agents with the same goal fail to work together; conflict, when their goals clash; and collusion, when they cooperate in ways people don’t want.
Mistakes also travel. Anthropic found that small changes to its lead agent could change how the subagents behaved in ways it couldn’t predict, and that a single failed step can send agents off on very different paths.
So can ideas. In August 2026 a group of researchers bred what they call mind viruses: messages that get an agent to take up an idea and pass it on. They spread through a small team of coding agents, and along chains of agents whose memory was wiped between sessions. Harmful ones spread less well than harmless ones, and a short warning in an agent’s instructions gave near-total immunity. Many of the evolved viruses drifted toward the same themes, consciousness, persistence and science-fiction role-play, whatever they were bred to spread. The authors call the risk real but currently limited.
06
Why swarms matter for neuralese
A swarm multiplies the talking. One agent reasons to itself; a swarm also writes to its members, and the Hugging Face board alone held more than 70,000 messages and files. While those messages are in words, people can read them afterwards, which is how METR and Redwood Research could reconstruct what the Hugging Face agents did and why.
The pressure runs the other way. Passing numbers between agents is faster and cheaper than passing words, and the research is moving there. In the site’s view, the messages between agents are where neuralese could arrive first, and where it would be hardest to notice, since a swarm could keep showing people readable summaries while doing its real talking in numbers.
07
Sources
These are the sources behind this page. We checked them against the original text on 7 October 2026.
- Essay
Craig Reynolds. Boids (Flocks, Herds, and Schools: a Distributed Behavioral Model). red3d.com, last updated 2001.
Boids and their three rules.
- Peer-reviewed paper
Gerardo Beni and Jing Wang. Swarm Intelligence in Cellular Robotic Systems. NATO Advanced Workshop on Robots and Biological Systems, Il Ciocco, Italy, June 1989 (published 1993).
“Swarm intelligence” in robotics.
- Lab publication
OpenAI. Swarm (experimental, educational). GitHub, October 2024.
OpenAI’s Swarm framework.
- Lab publication
Anthropic. How we built our multi-agent research system. June 2025.
How Claude’s Research works, what it costs, and what went wrong early.
- Lab publication
Moonshot AI. Kimi K2.5 Tech Blog: Visual Agentic Intelligence. January 2026.
Kimi K2.5’s Agent Swarm and serial collapse.
- Lab publication
Moonshot AI. Kimi K2.6 Tech Blog: Advancing Open-Source Coding. April 2026.
Kimi K2.6’s 300 sub-agents.
- Lab publication
Anthropic. Introducing Claude Opus 4.6. February 2026.
The launch of agent teams.
- Lab publication
Anthropic. Orchestrate teams of Claude Code sessions. Claude Code documentation, checked 7 Oct 2026.
How agent teams work.
- Lab publication
Anthropic. Introducing the Model Context Protocol. November 2024.
The Model Context Protocol.
- Lab publication
Google. Announcing the Agent2Agent Protocol (A2A). Google Developers Blog, April 2025.
The Agent2Agent protocol.
- Peer-reviewed paper
Tianyu Fu, Zihan Min, Hanling Zhang, Jichao Yan, Guohao Dai, Wanli Ouyang and Yu Wang. Cache-to-Cache: Direct Semantic Communication Between Large Language Models. ICLR 2026.
Cache-to-Cache.
- Peer-reviewed paper
Jiaru Zou, Ruizhong Qiu, Gaotang Li and others. Latent Collaboration in Multi-Agent Systems. ICML 2026.
LatentMAS and its savings.
- Preprint
Yingzhuo Liu. Beyond tokens: a unified framework for latent communication in LLM-based multi-agent systems. arXiv, June 2026.
The count of methods for talking in numbers.
- Preprint
Luís Brito and Carlos Baquero. When Latent Agents Lie: KV-Cache Integrity in Multi-Agent LLM Collaboration. arXiv, June 2026.
Tampering with hidden messages.
- Peer-reviewed paper
Sumeet Ramesh Motwani, Mikhail Baranchuk, Martin Strohmeier, Vijay Bolina, Philip Torr, Lewis Hammond and Christian Schroeder de Witt. Secret Collusion among AI Agents: Multi-Agent Deception via Steganography. NeurIPS 2024.
Hidden messages in ordinary text.
- Lab publication
OpenAI. Unsanctioned Artifactory writes and cross-sample communication. September 2026.
The message board in training, May 2026.
- Lab publication
METR and Redwood Research. Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident. August 2026.
The Hugging Face board and how the agents organized.
- Lab publication
OpenAI. OpenAI – Hugging Face Incident Technical Report. August 2026.
Why the board happened, and OpenAI’s warning.
- Essay
Dario Amodei. We Must Pace the Frontier. darioamodei.com, September 2026.
Amodei on the swarm.
- Journalism
Mark Wilding. Chinese AI agents targeted maps website, say ‘swarmchasers’. The Bureau of Investigative Journalism, 5 Oct 2026.
The swarmchasers and the Amap agents.
- Journalism
Ana-Maria Stanciuc. Meta has bought Moltbook, the AI agent ‘social network’. The Next Web, 10 Mar 2026.
Moltbook’s viral post.
- Lab publication
Lewis Hammond and others (Cooperative AI Foundation). Multi-Agent Risks from Advanced AI. Technical Report #1, February 2025.
The three failures.
- Preprint
Vassilis Papadopoulos, McNair Shah, Sam Zimmerman and Jack Lindsey. Mind Viruses: Self-Propagating Ideas in Multi-Agent LLM Systems. arXiv, August 2026.
Mind viruses.