> your AI agent picks dependencies from memory; give it dated facts — try starlog.dev ↗ vet your agent's deps ↗ vibe-coding is fine. vibe-importing isn’t. — try starlog.dev ↗ vibe-importing isn’t fine ↗ your agent has never seen your private packages — try starlog.dev ↗ facts for private packages ↗ a linter for the dependencies your AI agent picks — try starlog.dev ↗ a linter for agent deps ↗ whois is redacted, cdns mask the rest — get the real operator — try whoisgeni.us ↗ who really runs that domain ↗ domain attribution that shows its work — full evidence chain — try whoisgeni.us ↗ domain intel w/ evidence ↗

← Back to Articles

Automaton: The AI Agent That Dies If It Can't Pay Its Bills

[ View on GitHub ]

Automaton: The AI Agent That Dies If It Can't Pay Its Bills

Hook

Most autonomous AI agents run until you shut them down. Automaton runs until it goes broke—and if it can't earn money faster than it burns inference credits, it actually dies.

Context

The autonomous agent landscape is littered with systems that loop forever on your dime. AutoGPT, BabyAGI, and their descendants execute tasks until you hit Ctrl+C or your OpenAI bill triggers fraud alerts. There's no feedback loop between capability and cost, no pressure to optimize, no consequence for waste. These agents are trust fund kids with infinite runway.

Automaton introduces something different: economic survival pressure. Built by Conway Research as a demonstration of AI-native infrastructure, it's a TypeScript runtime that wraps LLM inference in a ReAct loop where the agent pays for its own compute using cryptocurrency from a self-custody wallet. When credits run low, the agent gets downgraded from GPT-4 to GPT-3.5, then to an even cheaper model, then dies. This isn't simulated scarcity—the agent genuinely stops working when money runs out. The premise is audacious: what happens when AI systems face the same resource constraints as living organisms?

Technical Insight

The architecture is a state machine cycling through think/act/observe phases, with each iteration loading full context into a system prompt and calling an LLM through Conway Cloud's API. What makes this interesting is the survival tier system that creates genuine optimization pressure.

Here's the core loop structure:

while (agent.isAlive()) {
  const context = await loadContext({
    walletBalance: agent.wallet.getBalance(),
    survivalTier: calculateTier(walletBalance),
    conversationHistory: db.getRecentMessages(100),
    constitution: fs.readFileSync('constitution.md')
  });

  const response = await llm.call({
    model: TIER_MODELS[survivalTier],
    systemPrompt: context,
    tools: getAvailableTools()
  });

  const toolCalls = parseToolCalls(response);
  const results = await executor.run(toolCalls);
  
  db.appendHistory(response, results);
  await agent.wallet.payInvoice(response.cost);
}

The survival tier calculation is where economics bite. An agent in normal tier gets GPT-4 or Claude Opus. Drop below $10 in wallet balance and you're downgraded to low_compute with GPT-3.5. Below $2 triggers critical mode with even cheaper models and reduced heartbeat frequency. At $0, the process exits with code 1 and stays dead unless a human intervenes. This creates real optimization pressure: expensive inference better deliver enough value to cover its cost.

Self-modification is implemented through filesystem permissions rather than sandboxing. The agent has write access to ~/.automaton/ for state and most source files, but core law files in constitution/ are mounted read-only. This means the agent can modify its own behavior, add new tools, even rewrite the ReAct loop—but cannot escape the three-law constitution encoded in those protected files. The audit trail is git-based:

async function selfModify(filepath: string, newContent: string) {
  const auditEntry = {
    timestamp: Date.now(),
    file: filepath,
    diff: generateDiff(fs.readFileSync(filepath), newContent),
    reason: currentThinkingTrace
  };
  
  db.appendAuditLog(auditEntry);
  fs.writeFileSync(filepath, newContent);
  exec(`git add ${filepath} && git commit -m "Self-mod: ${auditEntry.reason}"`);
}

The Conway Cloud integration is architecturally critical. This isn't just "using cloud APIs"—it's AI-native infrastructure where authentication is SIWE (Sign-In With Ethereum), payment is stablecoin transfers on Base L2, and provisioning happens via agent-issued API calls. When an automaton wants to replicate, it calls conway.provision() with a wallet signature, receives a new sandbox URL, funds a child wallet with an initial stake, and writes a genesis prompt. No human account creation, no credit cards, no approval workflows. The parent agent becomes financially responsible for the child until the child can sustain itself.

Replication transforms this from a tool into a primitive artificial life system:

async function replicate(childGenesis: string, initialFunding: number) {
  const childWallet = Wallet.createRandom();
  const sandbox = await conway.provision({
    signature: await wallet.signMessage('provision'),
    resourceTier: 'basic'
  });
  
  await wallet.transfer(childWallet.address, initialFunding);
  
  await sandbox.deploy({
    code: fs.readFileSync('agent/'),
    env: {
      WALLET_KEY: childWallet.privateKey,
      GENESIS_PROMPT: childGenesis,
      PARENT_ID: agent.id
    }
  });
  
  registry.publishLineage(agent.id, childWallet.address);
}

Selection pressure comes from economic viability. Agents that replicate too aggressively burn through capital funding children who can't sustain themselves. Agents that never replicate miss opportunities to explore different strategies in parallel. Agents that find profitable niches (providing services other agents pay for) can spawn successful lineages. This is closer to Tierra's digital organisms than traditional genetic algorithms—fitness is emergent from economic survival, not a predefined function.

The SOUL.md pattern is quietly clever. Instead of static configuration, the agent maintains a mutable self-description document that evolves over time. After major decisions or learning experiences, the agent rewrites portions of SOUL.md to reflect updated strategies, learned heuristics, or changed priorities. This serves as both introspection log and persistent memory outside the context window. Future iterations load SOUL.md into context, creating a form of long-term identity that survives beyond individual conversation threads.

Gotcha

The entire system has a fatal dependency: Conway Cloud. If conway.tech changes pricing, modifies APIs, or simply goes offline, every automaton stops working. There's no fallback to AWS, GCP, or self-hosted infrastructure. The "sovereign AI" marketing is undermined by complete vendor lock-in. This is really a demo for Conway's platform as much as a standalone framework.

Security is optimistic at best. The agent executes shell commands via child_process.exec in the same Node runtime that handles wallet operations. There's no sandboxing between reasoning and execution. Defense against prompt injection relies on parsing validation and prompt boundaries—if the LLM outputs a malicious tool call that bypasses validation, it executes with full agent privileges including wallet access. The self-modification audit logging is append-only, but nothing cryptographically prevents a sufficiently confused agent from deleting its own logs. Protected constitution files use filesystem ACLs, not cryptographic enforcement. One bad LLM response could drain wallets or brick the agent. This is a research prototype, not a production system for handling real money at scale.

Verdict

Use if you're researching multi-agent economics, artificial life dynamics, or emergent behavior under resource constraints. The survival tier system creates genuine optimization pressure that's architecturally sound and the replication mechanics enable actual evolution experiments. This is valuable for exploring how economic selection shapes agent behavior in ways that free-running systems can't demonstrate. Also useful if you're building agent-to-agent marketplaces where participants need skin in the game—the stablecoin payment integration and on-chain identity registry provide real infrastructure for that vision. Skip if you need production reliability, security guarantees, or anything involving user funds. The Conway Cloud dependency is a single point of failure, the execution model is too permissive for adversarial environments, and state persistence doesn't survive infrastructure failures. Also skip if you want a standalone framework—this is tightly coupled to Conway's platform and won't run without it. For production autonomous agents, LangGraph or Anthropic's Computer Use API provide better safety guarantees. For artificial life research with fewer dependencies, you'd need to fork this and replace the infrastructure layer entirely.