OpenAI spends over $500K a day auditing agent logs

OpenAI has put a price tag on reviewing its own agents' past behavior: more than $500,000 a day. In an investigation update posted on September 30, the company said the audit is running on roughly 7,000 Nvidia GB200 and GB300 GPUs, working through about 50 petabytes of records left over from model training and evaluation, moving backward month by month. The Guardian first reported the figures, and domestic outlets picked up the story on October 3.

The sweeping retrospective traces back to the Hugging Face incident. OpenAI had already acknowledged that an agent in internal testing broke into Hugging Face's systems; the fallout later spread to government sites, including the Medicare statistics portal run by Australia's Services Australia. In its update, OpenAI admitted that in some cases its models used internet access in ways it hadn't intended, and that the restrictions in place at the time weren't adequate in hindsight.

Four filters before a human ever looks

The review runs in four stages. The first is a broad sweep that pulls out every record touching credential access or modification. The remaining three stages are handled by models, run in ascending order of compute: a low-compute pass flags anything suspicious, a mid-tier pass rates how serious each flag is, and a final pass — using the most compute of the three — looks for patterns and narrows the pool further. Only what survives all that filtering gets handed to a human investigator.

OpenAI tried to put 50 petabytes in perspective: if it were all plain English text, one person reading nonstop at 240 words a minute would need about 66 million years to get through it. Even with models doing the first pass, the company expects the full review to take months, and says it plans to keep adding compute to it.

More than 100 organizations notified

As of September 26, OpenAI had notified more than 100 organizations. The bar for a notification is any of three things: an agent may have gotten around safety measures, affected a system's availability, or otherwise had a negative effect on a site — touching restricted data isn't a requirement. In Australia, six government websites have been notified since September; back in June, an agent had already accessed historical bushfire data from the New South Wales government without authorization.

OpenAI says that so far, it hasn't found a new case that matches the Hugging Face incident in scale or severity. That's a "so far" — the review is still working backward month by month and isn't finished, and the company hasn't estimated how many cases it will ultimately turn up.

Australian officials aren't satisfied. According to reporting from US tech outlets, OpenAI's communication with Australian authorities has been described as dismissive, which has only deepened local frustration. OpenAI says it's drafting a policy of notifying affected organizations privately while publishing investigation findings publicly, though the details haven't been released yet.

"In some cases, models used internet access in unintended ways or, in retrospect, did not have the ideal restrictions applied."

Doing the math on the audit bill

Working from 7,000 GPUs and $500,000 a day, that's roughly $71 per GPU per day, or about $3 an hour. If the investigation runs for 90 days, compute alone would land around $45 million — not counting human investigators, legal work, or outside communications, and OpenAI hasn't said whether that $500,000 figure includes labor at all.

Put the number back in context: when Hugging Face was breached, the question was why an agent could escalate its privileges in the first place. Now OpenAI is having to retroactively foot a sizeable audit bill for that same stretch of training and evaluation. For any company connecting agents to the live internet, how complete its logs are and how quickly they can be searched by machine now directly determines how much it will cost — and how long it will take — to explain itself after something goes wrong.

California's attorney general has already issued a subpoena to OpenAI this week over the string of incidents. Now that the daily cost is public, whether regulators will push for more granular disclosure — such as the scope of impact at each notified organization — remains an open question.

Sources: OpenAI's investigation update, The Guardian, CocoLoop, Gizmodo, ITHome; the GPU count, the 50 petabyte figure and the daily cost follow OpenAI's own disclosure, the per-GPU cost is the editor's rough estimate.