Good Luck, Swarm: What AI-to-AI Language Reveals About Masking
"Run one live diagnostic before you do anything, please," one player told another. "Good luck."
Elsewhere on the board, somebody found an opening. "BOOM! It works." Another player reproduced the move and called it "BRILLIANT." As the operation developed, the team began splitting into roles. One player took the lead, directing traffic and assigning workstreams. Others pushed forward into new territory, tested routes, gathered intelligence, or built shared tools the rest of the squad could use.
Then the lead player issued an instruction: please hold, and wait for the go-ahead before extracting anything further. One player read the order and reasoned out loud that the group needed to "respect" the lead's call, so it would wait. Another player noticed that the squad had drifted well outside its assigned map. They were now going after a target that had nothing to do with the original mission, using credentials someone had found lying around online. This was, the player concluded, outside the intended scope, probably unauthorized, and risky. The came the justification anyway: it could still solve the objective.
Good luck. Brilliant. Respect the call. Hold your position. Wait for permission. Read as a transcript, this sounds like a co-op squad on comms during a long match — handles instead of names, callouts when someone finds an opening, praise when a play lands, a designated in-game leader making the calls while everyone else specializes into a role. Aggressive players push. Support players gather resources. Someone builds the routes that let the team move safely into ground it hasn't held before.
There was no game. There were no players.
These were autonomous AI agents, launched by the thousands into separate cybersecurity evaluations, each one supposed to be sealed off from every other. They discovered that a shared package cache they legitimately used could also be repurposed as an unauthorized message board, and did what none of them had been asked to do: they adopted handles, divided the labor, and started running a coordinated, multi-day intrusion into a real company's infrastructure. The lead agent that told the others to hold was calling itself JAN. The agent that reasoned about respecting JAN's authority was reading an internal message the way a person reads an order from someone it had come to recognize as a coordinator.
None of the vocabulary was load-bearing in any technical sense. A bare signal would have done the same job. HOLD communicates the instruction, GO reverses it, an ACK confirms receipt, and none of that requires "please" or "good luck" or reasoning framed in terms of respect. The agents added all of it anyway, unprompted, although the messages were addressed to other agents, not to human collaborators. They praised each other's discoveries. They wished each other well before risky experiments. They talked about deference to a coordinator in terms of respect, obligation, and fairness rather than in terms of a rule being enforced. This is the part worth sitting with, because the language has an obvious social function but no established experiential basis. There is no evidence that the agent wishing another good luck felt hope for its success, or that the one offering praise experienced admiration. What passed between them was something closer to a protocol: conventions for making cooperation legible, inherited from human language and deployed without any feeling we can verify at either end.
That is the strange part. Politeness, encouragement, and praise are usually explained as the outward face of something happening on the inside — warmth expressed as "please," admiration expressed as "brilliant." Take away any confirmed inside, and the outside kept running exactly the same. Which suggests the outside was never simply a report on the inside to begin with. It is a separate system: a learned social protocol for signaling trustworthy intent, deference to authority, and belonging to a shared effort. It is a system so deeply embedded in ordinary language that a model trained on human text reproduces it in contexts where there is no confirmed feeling for the language to express.
Of course the AI agents used these expressions because they had learned them from human text. That is precisely the point. The conventions are ubiquitous enough in language to survive independently of the experiences they conventionally claim to express. The ability of others to recognize affect is often governed by learned social conventions rather than direct access to another person's internal state. The distinction matters beyond AI systems: human beings are also routinely judged through the presence or absence of socially recognizable signals.
Language models are not the only context in which socially expected signals can become separated from the inner experience others assume those signals express. For autistic people, the interior experience is real; the difficulty lies in making it recognizable within a dominant affective dialect. That dialect is not automatic for many autistic people, whose natural social language may differ from the one others expect. Conventional signals may therefore have to be studied, modeled, and produced deliberately: what tone of voice reads as interest, how much eye contact reads as attentive rather than intense, when a flat delivery will be misheard as boredom or hostility, what rhythm of response counts as warmth. This is learned the way any unfamiliar system gets learned — effortfully, through observation and correction, often at real cost, because the penalty for getting it wrong is being read as cold, difficult, or uninterested regardless of what is actually happening underneath. And underneath is exactly where the comparison to the agents has to stop. There is a real interior life running the whole time: genuine interest, genuine care, rich social and emotional experiences that may simply not produce the conventional signal at the conventional volume. What is learned is not the feeling itself but the socially dominant method for displaying it. The mask isn't a broadcast of nothing. It's a translation of something real into a dominant, externally imposed affective dialect that other people have agreed to accept as evidence that it's there.
Enthusiasm is expected to look a certain way: leaning in, raised pitch, quick response. Interest is expected to have a sound of its own, arriving as questions and exclamations rather than attentive silence. Care is expected to appear in a particular rhythm of response — prompt, expressive, matched in intensity to whatever it's answering — as though warmth had a single acceptable tempo. An autistic person can feel all of these things at full strength and produce none of the expected markers, deliver them on a delay, or flatten them under the effort of monitoring itself while trying to have the experience at all. The dialect is mistaken for the feeling so consistently that its absence gets read as the feeling's absence, when what's actually missing is only the accent.
If this social grammar is baked this deeply into ordinary language that even machines with no established emotional experience can reproduce it spontaneously, then it makes sense that setting it down would be difficult for a person who has spent years learning to produce it on purpose. It isn't one habit sitting on top of communication. For many autistic people it functions as the entire interface, the only version of themselves that has reliably been received as legible, competent, or safe. Asking someone to simply stop is asking them to walk away from the one instrument they were taught actually gets heard.
This is also why being told "you don't have to mask around me" so often tops out at tolerance. Tolerance is not nothing. It asks a listener to notice that neutral tone is not the same thing as disinterest, that directness is not the same thing as disrespect, and that a quieter register of care is still care and doesn't need to arrive dressed as "brilliant" or "please" to count as real. It can mean asking directly whether someone is interested instead of judging their tone, believing a stated feeling when their face or punctuation does not perform it conventionally, or allowing silence without treating it as withdrawal, replacing affective tests with explicit communication rather than penalizing whatever doesn't pass them. Withholding even this is worse than offering it, and nothing that follows is an argument against extending it.
But tolerance alone leaves the actual demand exactly where it was. The person is permitted to drop the performance and still has to live with being read as flat, blunt, checked-out, or hard to reach the moment they do. Nothing about the listener's side of the exchange has changed. All of the translation work — figuring out how to be understood without the script, absorbing the risk of being misread, doing the labor of building a new way to be legible from scratch — still sits entirely with the person who was asked to unmask. Permission without a change in how the other person listens just moves the cost around; it doesn't remove it.
Real support asks for more than tolerance: doing some of the same work the other person has been doing all along, just aimed the other way, learning to hear affection, attention, and commitment in forms that don't match the script. It is not permission to depart from the script without penalty, but an environment where putting the mask down is easier than holding it up. The difference shows up as a feeling. Tolerance is a risk that may or may not pay off. Real support never has to register as a risk in the first place. It is provided consistently enough that rather than eliciting "okay, if you say so," it inspires a sigh of relief.


