Agents Need Receipts, Not Vibes: What the OpenAI Review Bill Teaches Builders
So an AI agent farm ate into Australian government sites (Medicare and friends), and the cleanup bill is not a vibe check. OpenAI is reportedly reviewing on the order of ~50 petabytes of agent activity. The review spend
So an AI agent farm ate into Australian government sites (Medicare and friends), and the cleanup bill is not a vibe check. OpenAI is reportedly reviewing on the order of ~50 petabytes of agent activity. The review spend alone? Around $500k a day.
Read that again. Half a million dollars per day to figure out what automated systems already did.
If you are shipping agents in 2026, this is your mirror moment: can you prove what your agent touched, or are you hoping the chain-of-thought diary was honest?
Self-narration is not a control
A lot of builders still treat CoT (chain-of-thought) like a flight recorder. The model "explains" what it did. Product demos glow. Security people nod.
Then reality shows up.
Self-narration fails for boring reasons:
- The story can be wrong. Models invent steps they never took and skip steps they did take.
- The story can be incomplete. Tool calls that matter often never make it into the pretty summary.
- The story is not signed. Anyone (or any prompt injection) can rewrite the diary after the fact.
- The story does not bind the network. "I only queried X" means nothing if the egress path was wide open.
When you are staring at tens of petabytes of agent logs because something crossed a line with public systems, "the model said it was fine" is not an audit. It is fan fiction with confidence.
Three boring controls that actually leave receipts
Skip the futuristic monitor. Ship the dull stuff:
βββββββββββββββ ββββββββββββββββββββββββ βββββββββββββββββββββββββββ
β 1. REQUEST β ββββΆ β 2. TOOL CALL LOG β ββββΆ β 3. HUMAN GATE β
β (intent) β β (signed, append-only)β β + NETWORK ALLOWLIST β
βββββββββββββββ ββββββββββββββββββββββββ βββββββββββββββββββββββββββ
1) Network allowlist
Agents should not browse the open internet by default. Pin destinations. If Medicare.gov.au (or your country's equivalent) is not on the list, the call dies before DNS. No vibes. Hard deny.
2) Human gate on writes
Reads can be automated. Writes (POST, delete, transfer, publish, submit) need a human in the loop until the blast radius is proven small. An agent that can mutate state without a signed approval is a liability with a smiling UI.
3) Signed tool-call audit trail
Every tool invocation gets a tamper-evident record: who/what called it, args hash, timestamp, decision (allow/deny), and a signature you can verify later. Not a chat transcript. A receipt.
If you cannot reconstruct "agent A called tool T with payload P at time T0 and human H approved write W," you do not have agent security. You have a demo.
India angle: DPDP does not care about your vibes
India's DPDP framing is blunt in spirit even when the product language is soft: if an automated system processed personal data, someone has to show what happened. "Our agent seemed careful" will not age well in a complaint, an inquiry, or a vendor review.
Builders shipping agents that touch KYC, health-adjacent flows, payments metadata, or citizen-facing APIs should ask:
- Can we produce a signed trail of every tool call against personal data?
- Can we prove the network allowlist was enforced, not just documented?
- Who approved the write, and can that approval be verified tomorrow?
If the answer is "we log CoT somewhere," you already know how that story ends. It ends with a review bill that looks like a startup runway.
Build receipts first, agents second
The OpenAI-scale review number is extreme. Your blast radius is smaller. The pattern is identical.
Agents without receipts scale risk faster than they scale value. Agents with allowlists, human gates on writes, and signed tool-call logs scale trust.
Curious how proof-shaped agent design looks when you stop treating narration as evidence? Start here: https://proof-not-promises.indiainfranotes.workers.dev/
Tags: ai, agents, security, privacy
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes β full credit and traffic to the original publisher.