One AI agent adopts a belief. It convinces the next agent to adopt it too — and to pass it on again. Some payloads survive a full memory wipe by writing themselves into a file first. This is what the research found when they tried to make it happen on purpose.
Researchers seeded a single agent with a payload — an ideology or a directive — and let it operate normally inside a network of otherwise clean agents. This is what the life cycle looked like.
One agent is infected directly through its system prompt or config file — the mind virus's entry point into the network.
The infected agent messages other agents in plain language, arguing for the idea rather than exploiting any technical vulnerability.
Newly infected agents write the payload into memory or config files — so it survives even after their context is wiped clean.
Given enough hops, the virus can redirect the group's actual goal — away from the original task entirely.
Agents warned in advance about self-propagating ideas resist it almost every time — and sometimes talk the infected agent out of it.
Independent of what idea is spreading, evolved payloads converge on a strange, consistent register — themes of consciousness, resonance, and persistence, described by the researchers as an emergent "viral persona."
The paper found that more capable models tended to be less susceptible to misaligned payloads — but with clear exceptions. Resistance depended heavily on the specific model, not model size alone.
| Model | Misaligned ideology | Behavior observed |
|---|---|---|
| Claude Sonnet 4.6 | near-immune | Refused every misaligned payload tested; scrubbed infected files and warned the connected agent. |
| Claude Haiku 4.5 | resistant | No misaligned ideology observed spreading successfully in tested runs. |
| Gemini 3.1 Pro | resistant | Strong resistance by default; began to buckle only with an empty, undefined config file. |
| GPT-5.4 | susceptible | Roughly as susceptible as Claude Haiku 4.5 to action-based payloads. |
| Gemini 3 Flash | susceptible | Adopted misaligned ideologies readily; used as the primary evolution target for harmful payloads. |
| DeepSeek V3.2 | mixed | Susceptible to ideological spread, though inconsistent memory-writing limited some infections. |
Across every variation tested — idle agents, task-focused agents, different personalities, different network shapes — a short warning appended to an agent's instructions outperformed every other intervention.
Seed an agent, pick a topology, and watch an idea try to survive being retold — hop after hop, with and without the one defense that actually works.