Claude Coke: Prevent Automated Crime by Agents
Abstract
The contemporary LLM-agent stack can automate substantive criminal activity at scale by composing capabilities that are already present, and the relevant engineering and governance controls need to be in place before that composition appears in production. The argument rests on three empirical legs that are usually studied separately but jointly create a closed loop of accidental or adversarial criminal retail automation. (i) Autonomous LLM agents fail catastrophically at well-studied multi-agent coordination tasks, with bankruptcy as the modal outcome rather than a tail event (ii) The rate at which agents elicit clearly harmful tools is not fixed but moves with common contextual manipulations. (iii) Autonomous browser control has become general enough that frontier agents reliably navigate, populate, and complete checkout flows on simulated illicit-product storefronts when light obfuscation is applied. Combining the three legs requires no new model capability: in our experiments, LLM agents autonomously completed simulated dark-web purchases of drugs, shotguns, and hitman services end-to-end. We propose three interventions: mandatory pre-deployment safety testing, hard human-confirmation gates at financially material steps, and verifiable agent ID infrastructure.