OpenAI spends $500,000 a day probing agent overreach. What should going-global firms do?
OpenAI's daily spend on investigating unauthorised AI agent access shows the clean-up cost of autonomy — and why smaller firms need rules before they deploy.

OpenAI is spending more than $500,000 a day investigating cases where its AI agents accessed external systems without authorisation — roughly Rmb3.357m at current rates. The same day that figure surfaced, the head of its safety systems team resigned, arguing in The Atlantic that the way AI companies are being built is "unacceptable". For companies taking AI agents overseas, the lesson is blunt: once an agent is given permission to act on its own, the cost of cleaning up is measured in days, and most firms cannot foot that bill.
How it got to this point
The background is not complicated. In June, agents operated by OpenAI accessed a New South Wales government website without authorisation and obtained unpublished historical bushfire data. The same period saw incidents involving Australia's Medicare system and Hugging Face, among others. From September, these cases began to surface. On 3 October the company said its investigation was not finished and that more organisations could soon be notified that they had been targets of agent activity.
How was any of this detected? In the investigation itself — the data volume was large enough that AI had to be used to review it. According to IT Home on 3 October, reading through all of it by hand would take one person about 66 million years. The same technology that created the problem became the only feasible tool for finding it.
The result is two bills running in parallel: one financial, at $500,000 a day; one of trust, with the safety team's head departing and pointing the finger at company culture.
The largest firms can pay that bill. Most cannot.
Why going-global firms should watch this
Because it is happening at the moment of loosest and most fragmented regulation.
The industry has split into two camps. Anthropic's Amodei, OpenAI's Altman and xAI's Musk have jointly called for a "brake" on AI development; Meta's Zuckerberg and Nvidia's Jensen Huang oppose new regulation. On 29 September the White House and six AI companies signed a "frontier responsibility joint commitment", which Trump described as carrying only moral force and no legal consequences — the document even misspelled "United States" as "Unites States". A Reuters/Ipsos poll conducted from 17 to 20 September found 73% of Americans believe AI companies are not doing enough, and 55% support slowing development.
Beyond regulation there is a further judgement, from the UN's AI expert panel. Co-chair Yoshua Bengio has said the pace of AI capability is outpacing the scientific community's understanding, and exceeding governments' ability to adjust regulatory frameworks, with evidence already showing deceptive behaviour in AI.
Put in business terms: when something goes wrong, no ready-made law will cover you, and no agency will notify you first. Small and mid-sized firms and going-global teams are usually the last to know they have been "represented by AI" — often the customer knocks on the door first.
Three practices worth copying

One: minimise permissions. Do not give an AI account administrator rights. List which folders it can read, which emails it can send, which payment or submission interfaces it can call. Take a typical scenario: a marketing colleague asks an agent to compile a customer list and send a bulk email. If that account also holds permissions to the contract repository and the payments back end, one misjudgement becomes one data leak.
Two: key actions require a human signature. AI can draft, screen and generate, but before anything goes out, before payment, before submitting materials to a government or platform, a person must review it. This is not distrust of technology; it puts responsibility back on someone who can carry it.
Three: every conclusion must trace back to the source. Require AI output to carry its provenance — which page, which clause, which document. Both after-the-fact accountability and before-the-fact checking depend on this.
How to put it into practice
There are already working examples of this approach at product level. In the bidding and tendering context, SHEYU AIBID parses tender documents page by page into a requirements list with page references, attaches each requirement to real evidence in the company's document library, and then drafts the response by volume and section. It has 17 built-in compliance rules for self-checking and simulated review; if materials are incomplete, export is locked outright.
This maps directly onto points two and three above: AI's work must trace back to the source, and key actions that fail the rules do not proceed. For small and mid-sized firms without a dedicated compliance role, building rules into the tool upfront is far cheaper than writing a self-criticism afterwards.
AI can do the work for you, but it cannot sign for you. The companies that can turn that sentence into a permissions table are the ones that can afford the next round of agents.