In 1988 a student took down a tenth of the internet. What did we do next?

Crowds of fun-seekers exploring a city on foot, "

Arjan Franzen

2 October 2026

Een groene rups kruipt over een uitgerolde band met ponstape en laat een spoor van steeds kleinere kopieën van zichzelf achter; links knielt een engineer die een pion en een koordje over het pad zet

In November 1988 Robert Morris, a student at Cornell, wrote a small program to count how many computers were on the internet. It copied itself from machine to machine, a bug made it do that far too often, and within a day about a tenth of the internet as it then was had gone down: some six thousand of the sixty thousand machines that existed, mostly at universities and labs. It has been called the Morris worm ever since, and it was the first worm to spread across the internet.

No malicious plan, then, just a benign goal and a design flaw nobody knew about. That is the pattern behind almost every incident I see, including the break-in by OpenAI's AI agents at Hugging Face this summer.

What happened next

Nobody tried to ban computers or small programs. There was no licence for writing software and no pause on the internet. What did happen, happened quickly and was fairly boring.

Morris became the first person convicted under the new American computer fraud law, with probation, community service and a fine. The one held to account was a human, not the program. (He later became a professor at MIT and co-founded Y Combinator, so it did not go badly for him.) And within a few weeks Carnegie Mellon had an emergency team, paid for by the American defence department: the first CERT, and the model for the dozens that followed.

Thirty years of boring agreements

Then came the part that never makes it into a documentary. Report leaks to the party that can close them rather than to the press. Give vulnerabilities a number so everyone is talking about the same thing. Pay hackers to break in before the wrong people do. A duty to report, which in Europe is now law: a data breach within 72 hours, a major security incident within 24.

Good hackers and bad hackers use the same tools, after all; what sets them apart is a contract beforehand and a report afterwards. What that means when you build software with AI in the mix we wrote up earlier in GDPR, NIS2 and DORA in your delivery pipeline.

Why this matters again

Every new kind of incident brings back the same reflex: this one is different, this one is more dangerous, this needs a pause or a licence. That was true in 1988 and it is true now, with AI agents that work for days on end.

I do not buy it, and the Morris worm is the reason. A pause costs the big players nothing and shuts the door on everyone behind them. What did work was ordinary work: holding a person to account, an emergency team, a duty to report, and agreements so boring that nobody remembers them. My expectation is that we will make exactly the same agreements about AI agents, and that it will take us about as long as it did then. If you would rather not wait: start with your own house, with our AI work and the cloud and platform work underneath it.

no image placeholder

The Agent Writes It. Who Reviews It?

How we can help

AI engineering

Use AI where it genuinely helps, with accountability staying with people.

See AI engineering →