Note · AI Implementation Strategies

Why Nextdoor Suspended My AI Agentfor Doing Exactly What I Approved

David He, FounderSeptember 17, 20265 min read

An AI agent got suspended for replying to job applicants too fast - a preview of what happens as agents become the majority of web traffic.

Nextdoor suspended my account for replying to a dozen job applicants in half an hour - not because an AI agent sent the replies, but because nothing else moves fast enough to do that by hand. The filter that caught it would have caught a person copy-pasting the same replies just as fast, and understanding that distinction is the actual lesson here for any business now putting agents in front of customers.

The Reply Nobody Ever Sent

My wife needed help at her warehouse. We posted the opening everywhere - Indeed, Craigslist, two Facebook groups, Nextdoor. Within hours, more than a dozen people replied across the four channels.

I had an agent draft a response to each one. I read every draft myself before anything went out, then approved them and told it to send.

Thirty minutes later, the agent reported it had been logged out mid-task. I opened the browser myself. Nextdoor's own message: the account was suspended indefinitely, for breaking community guidelines, with no further specifics.

One of the people who replied is still waiting on an answer that was written, reviewed, and approved - and never delivered.

This Wasn't the First Time

The same account was suspended the same way once before, on April 7, 2026. That time, one message to Nextdoor support restored it within a few hours.

This time was different. An in-app appeal went in that night. An email escalation went to Nextdoor's support address the next morning. Roughly eighteen hours after the ban, neither had drawn a response.

Here's the part that matters more than the outage itself: after the April suspension, we wrote down the fix. Space messages out. Cap how many new people you message in one sitting. Nobody wired that rule into the system that actually sends the messages. So this time, the agent did exactly what a person pasting a dozen replies in half an hour would also get flagged for.

Digging into why turned up something worth knowing if you run any kind of automated outreach: Nextdoor's own California AG transparency filing defines spam by pattern - the volume and speed of messages to new contacts - not by a published numeric cap the way some platforms publish one. There's no threshold to stay under. There's a shape of behavior to avoid, and a fast agent doing wanted, reviewed work has exactly that shape.

The Web Now Runs Majority-Machine

Zoom out and this stops being a Nextdoor problem specifically. It's a scale problem, and the scale has already tipped.

Cloudflare's own traffic count, reported by CEO Matthew Prince in June 2026, put bots at 57 percent of web requests, humans at 43 percent - the first time in the internet's history that the majority visitor to most sites isn't human. Imperva's 2026 Bad Bot Report counts it closer to 53/47, using a different measurement basket (all traffic, not just HTML requests). Different rulers, same direction.

Most of the infrastructure built to catch abuse online was built assuming the minority visitor was the machine. That assumption is now backwards, and almost nothing has been rebuilt to match it.

Some Companies Are Already Building For This

A few companies have already concluded that blocking agents isn't the right default anymore - they've built ways to let an agent do the thing instead.

Stripe built an agent wallet directly into Stripe Link, so an agent can hold and spend from a wallet its owner approves, rather than needing raw card details. Google shipped the Agent Payments Protocol, an open standard with more than 60 launch partners, that produces a signed, auditable record every time an agent transacts on someone's behalf. And in July 2026, Anthropic and 1Password shipped a way for Claude to log into a website using your saved password - without the password, or any secret, ever entering Claude's context, memory, or Anthropic's own systems.

Three different companies, one shared conclusion: figure out how to let the agent do the work safely. Don't just block it and call that safety.

Nextdoor's abuse filter was never asked that question. It doesn't check whether the account behind a message is a bot. It checks whether the account is moving at bot speed - and a reviewed, wanted, human-approved reply sent by an agent moves exactly that fast, so it reads the same as spam.

Where Agents Help, and Where They Shouldn't

None of this means every interaction should route through an agent. There's a real argument that some exchanges should stay strictly person to person - a neighbor vouching for a babysitter, a landlord sizing up a tenant's story, anywhere the entire point of the exchange is knowing who is actually behind the words. I agree with that argument completely.

Hiring isn't that case, and a conversation I had this week made the gap concrete. A recruiter I know told me he's started posting his own job openings as local-only instead of remote. The reason: a remote listing pulls hundreds of replies within hours, and there's no practical way to sort the ten strong candidates out of that pile by hand.

An agent trained on what actually made past hires good at the job doesn't replace a recruiter's judgment - the person still decides. What it changes is the math: going remote stops being a liability the moment something can read the whole pile fast enough to surface the real candidates. Right now, the applicants getting filtered out of a search like his aren't losing on merit. They're losing on geography, because the volume problem has no other fix yet.

The Actual Takeaway

The rule that stops spam and the rule that stops legitimate work are, on most platforms right now, the same rule. Nobody running those platforms has decided which one they actually want to be running - and until they do, the responsibility sits with whoever is operating the agent.

Until platforms make that call, I check first: before I point any agent at a site to do outreach, hiring, or my own job search, is that platform built to work with an agent, or only built to catch one. If your business runs agents against outreach, hiring, support, or sales, the same question applies before you build the workflow, not after it gets suspended.

More notesnewest first

Working on something like this?

Bring the app or the process to a free 15-minute call. I will tell you what I would look at first, and whether I am the right person for it.