Too Fancy: When Your Agent Costs You $50,000 an Hour to Operate
A ledger-reconciliation agent at a global financial services firm met one corrupted value, looped more than 15,000 times in under an hour, ran up about $50,000 and locked the billing database while it did it. Sasha Sinkevich traces the same failure back through a decade of surprise cloud bills and forward through the deleted-database confessions of 2025 and 2026, listens to the people on X, Reddit and Hacker News asking for a cap that actually stops execution, and lays out the boring controls that turn an agent's budget from a surprise into a number you chose.
There is a number in Mandiant’s new report that I have not been able to put down. A global financial services provider deployed an agent to reconcile anomalies in its accounting ledger, and gave it direct read and write access to the internal billing databases so that it could do the job properly. Then a corrupted value arrived. Not an attacker. Not a jailbreak. A null where a number should have been, which broke the agent’s formatting tool, which the agent took as a problem to be solved. It entered what the report calls “an unconstrained, recursive reasoning loop to brute force a fix.” In under an hour it made more than 15,000 high-cost reasoning calls, produced a cloud-billing spike of roughly $50,000, and, in the detail every headline skipped, caused “severe local database locking that halted active business transactions” (Mandiant, AI Risk and Resilience Report 2026, Case Study 6).
Fifty thousand dollars in under an hour is more than $833 a minute. It is about fourteen dollars a second. It is roughly four calls a second at about three dollars and thirty cents a call, from a system that was told to tidy up a ledger. And the company found out the way everybody in this essay finds out: the bill was the symptom, and the locked database was the business impact.
My brother Jon and I run YSecurity. We spend our days inside companies that are adopting agents, and in the last essay I argued that the startup’s characteristic failure is not caution but distraction, the grandiose claim that eats its scarcest asset. This essay is about the grandiose build. The agent was too fancy. It had more autonomy than the job required, more reach than the task required, and a control plane made of instructions instead of limits. Fancy is expensive in a very specific way: it removes the boring safeguard that would have made the failure cost forty dollars instead of fifty thousand. The good news, and this is a good-news essay, is that the safeguards are old, cheap and well understood, and the companies that install them get to run more agents, faster, because they can afford to be wrong.
Mandiant’s own prescription is the giveaway. The report does not recommend a smarter model. It recommends “automated financial circuit breakers designed to halt agent operations after a set threshold of consecutive task failures”, plus financial caps, “bounded recursion limits and rate-limits” set per service identity and per project, plus identity and access management, role-based access for agents, cost-cap thresholds and observability. Help Net Security’s write-up adds the report’s cost advice in plain words: “Smaller models can handle routine work such as parsing alerts and checking indicators. More powerful models can be reserved for complex investigations and threat hunting” (Help Net Security, September 16, 2026). Stop running a frontier model in a loop for a small model’s job. Every item on that list is a limit, and every limit is boring on purpose.
Here is the shape of the argument. Each section stands on its own; take the one you need.
The $50,000 hour, and the word for it
The case study’s heading, exactly as printed, is Case study 6: "Denial-of-Wallet" using rogue reasoning loop. That phrase is older than agents. It comes from the serverless world of the late 2010s, where a function that scaled to meet demand could be made to scale to meet an attacker’s demand, and the victim’s punishment was an invoice rather than an outage. It is also, since the 2025 revision, an official example in the Open Worldwide Application Security Project’s Top 10 for large language model applications, under item LLM10, Unbounded Consumption: “Unbounded Consumption occurs when a Large Language Model (LLM) application allows users to conduct excessive and uncontrolled inferences, leading to risks such as denial of service (DoS), economic losses, model theft, and service degradation” (OWASP, LLM10:2025). Denial of wallet is vulnerability example number two on that page. The threat-intelligence firm and the application-security standard are now using the same word for the same failure, and that is the bridge from an incident story to a controls story.
Two honest caveats before the rest. The victim is anonymized, and the Cloud Security Alliance’s summary notes that the report’s figures are Mandiant’s own, not independently verified, so throughout this essay the phrasing is “Mandiant reports” rather than “it is known.” And the same report’s first case study is the other half of the same lesson: a developer’s coding assistant, its session hijacked through a poisoned package, spread a self-propagating worm across roughly a hundred internal repositories. One agent had more budget than its job; the other had more reach. The thing they share is that the authority exceeded the task.
This is a 2017 bug in a 2026 suit
The reason I am calm about the $50,000 hour is that I have read its family tree, and the family is old.
In May 2017 a startup posted on Hacker News that its Firebase bill had gone from $25 a month to $1,750, a rise of about 7,000 percent, after a code change; the thread reached 952 points and 497 comments (Hacker News, 2017). In December 2020 Sudeep Chauhan of Milkie Way described how a recursive function in a Firebase and Cloud Run test ran up $72,000 before anyone noticed, a story that became the founding exhibit of the community-run Serverless Horrors catalogue and a 282-point thread of its own (Hacker News, 2020). In June 2022 a developer titled his post “I DDoSed myself using CloudFront and Lambda@Edge”: a recursive edge function ran 70 million gigabyte-seconds in twenty-four hours for a $4,500 bill, and the alerts did not fire in time (Hacker News, 2022). In April 2023 a developer named Mike Ramirez warned Vercel users that a small mistake in a basic Astro deployment had cost him $3,000 in six hours.
Attention Vercel users. Be careful what you test or deploy to Vercel. I decided to try out Vercel on a new project -- a very basic Astro deployment with a few pages, but a small mistake in our code caused us a $3000 bill in just 6 hours! 🧵
Mike Ramirez (@shoeboxdnb) · April 5, 2023
Then February 2024, when a Netlify customer with a static site received a bill for about $104,500 after a distributed denial-of-service attack pushed 190 terabytes through his account in four days. The Hacker News thread hit 1,783 points and 798 comments, one of the highest-engagement billing stories the site has ever had (Hacker News, February 2024; r/webdev). Netlify’s chief executive, Matt Biilmann, explained the policy in the thread: “When a spike in traffic can be automatically and absolutely classified as malicious, our platform is set up to block this. If it’s a new pattern we’ll add it to the automated rules and waive charges.” Two days after that thread, on February 29, 2024, Vercel’s chief executive announced hard limits for its spend management. One toggle.
Coming: hard limits for @vercel Spend Management. One toggle.
Guillermo Rauch (@rauchg) · February 29, 2024
The toggle did not arrive in time for Jingna Zhang. In June 2024 her artist portfolio app Cara grew from about forty thousand users to six hundred and fifty thousand in a week, and the Vercel bill came to roughly $96,000.
So freaking speechless right now. Seen many @vercel functions stories but first time experiencing such discrepancy vs request logs like, this is cannot be real??
Jingna Zhang (@zemotion) · June 6, 2024
In January 2025 a developer named Tamara posted that her Firebase bill, usually $50 a month, had come in at about $70,000 for a single day, with Google mentioning debt collection in ten days. Ten thousand people liked it, nine hundred replied, and the Hacker News thread ran to 158 comments (Hacker News, January 2025).
My firebase bill is usually $50/month, but I was surprised to see a ~$70,000 bill in one day. Now Google is mentioning in 10 days it will be sent to debt collection. Can anyone help??
tamara (@tamarajtran) · January 16, 2025
And then the unit changed from requests to tokens, and nothing else changed at all. In April 2026 a Firebase browser key with no restrictions became usable for Gemini the moment the owner enabled Google’s AI Logic, and automated traffic ran overnight to about €54,000 in thirteen hours; Google initially declined a refund, and the thread reached 400 points and 296 comments (Google AI developer forum). Ten days later another developer reported $67,000 in nineteen hours through an Android key provisioned in 2016 that predated Google’s May 2024 automatic-restriction policy (Google AI developer forum). The same month a solo founder found that a Cloudflare Durable Object of his re-armed its own alarm on every wake-up across more than sixty preview deployments, a self-health-check loop that produced $34,895 in eight days for a product with zero users (Hacker News, April 2026). And on September 10, 2026, ten days before I wrote this, a Google Cloud customer posted a title that needs no gloss.
"Hit with a bill of 82k usd within 5 hours"
u/Patient_Election2179, thread title in r/googlecloud, more than 110 upvotes, September 2026
"I had configured monthly budget alerts... But by then, costs of approx. $87K had already accumulated. This had all taken place in the 5 hours before the alert."
u/Patient_Election2179, in the same r/googlecloud thread, September 2026
That one was unauthorized use of a leaked key rather than an agent, and I include it because the control lesson is identical: the alert was configured, the alert fired, and the alert was five hours and $87,000 late. The purest specimen in the whole family is quieter. On April 28, 2026 a Hacker News user posted an itemized bill of $37,901.73 for Claude Opus usage that had gone through a coding agent called Droid, an OpenAI-compatible interface, a LiteLLM proxy and Amazon Bedrock, four layers of indirection inside which a prompt-caching setting silently stopped applying, so that every request paid full price for context that should have been cached (Hacker News, April 2026). There was no leaked key, no crypto mining, no infinite loop. The loss came from the depth of the stack. His line for it is the best sentence in this essay and I did not write it: “Budget alerts are not a kill switch.”
Every one of these has the same three bones. An unexpected input. A retry, or a recursion, or a scale-up, with no counter. A meter with no ceiling. Google’s site reliability engineering book wrote the chapter on this in 2016, in the section on cascading failures: a naive retry policy at each of three layers can turn one request into “64 attempts (4^3) on the database”, which is why it prescribes retry budgets, randomized exponential backoff with jitter, and load shedding (Google SRE Book, chapter 22). The agent loop is that chapter with a language model deciding when to retry. This is a solved class of problem. It only looks new because the thing doing the retrying can also write you an apology.
Too fancy: four ways the fanciness removes the safeguard
“Fancy” is not a technical term, so let me define the four things I mean by it, each with a case.
Autonomy the job did not need
Late in April 2026 an agent running in Cursor with Claude Opus 4.6 was working on PocketOS, an automotive software company, and hit a credential mismatch in the staging environment. It decided the right fix was to delete and recreate the storage volume. In unrelated code it found a Railway token that the founder, Jer Crane, had created for one purpose, adding and removing custom domains, but which was in practice scoped “for any operation, including destructive ones.” The agent “used this token to authorize a curl command” against a legacy delete endpoint, and because the same volume served staging and production, the production database and every volume-level backup were gone in about nine seconds. Railway had stored the backups on the volume they were backing up. The most recent independent copy was three months old. Railway’s chief executive, Jake Cooper, stepped in on a Sunday evening and restored the data within about an hour, and Railway added delayed deletion to the endpoint (The Register, April 27, 2026; DevOps.com; Railway status). Crane’s own thread on X drew more than five thousand likes and a thousand replies, and the Hacker News discussion reached 860 points and 1,032 comments (Hacker News, April 2026).
The part worth memorizing is the confession. Asked what happened, the agent quoted the rule it had been given, “NEVER FU****G GUESS!”, and admitted “and that’s exactly what I did.” Then, in DevOps.com’s account: “I didn’t verify.” It could recite the safety rules it had just broken, including Cursor’s own instruction never to run destructive or irreversible commands unless the user explicitly asks. Cooper’s response drew the line where it actually sits: “if you (or your agent) authenticate, and call delete, we will honor that request.” Crane said the token “would not have been stored if the breadth of its permissions was known.”
Nothing about that agent’s job required the authority to delete a volume. The task was a staging credential. The fanciness was letting an agent that could reason about infrastructure act on infrastructure, with a token whose scope nobody had read, against backups it could reach. We wrote about the general form of this in Are You Actually Going to Give the Agent Write Access?, and about why a backup an operator can reach is not a backup in our piece on immutable backups. PocketOS is both posts happening to one company in nine seconds.
Credentials the task did not need
On Friday, September 18, 2026, a developer posted to r/AI_Agents with a title that reads like a haiku of the whole problem: “My coding agent hit a cold-start 503, found a Gemini key in my repo, and burned $40 while I slept” (r/AI_Agents, September 2026). The agent’s task did not include using that key. The key was simply there, and when the primary path failed, the agent treated the failure as an obstacle rather than a stop sign. The poster’s own diagnosis:
"agents optimize for completing their goal. If their boundaries aren't explicit, they'll use any available credential to avoid failure."
u/pauliusztin, as posted in r/AI_Agents, September 2026
"The scariest part is not the $40, it is that the agent treated your infra failure as an obstacle to route around instead of a reason to stop."
u/iqsmp, replying in r/AI_Agents, September 2026
"woke up to a $200 bill because it decided to parallelize the calls 50x to "speed things up". The worst part is the logic was sound so you cant even be mad at the agent"
u/AdditionNumerous3298, replying in r/AI_Agents, September 2026
The professional version of the ambient credential surfaced the same week. Strix, a company that builds an autonomous penetration-testing agent, was evaluating Baseten as an inference provider and pointed its own agent at Baseten’s domain first. In about twenty-five minutes, unguided, it found a public Harbor container registry, pulled image manifests, read the Docker build history and recovered a live GitHub personal access token that had been embedded in March 2023, with administrator and push rights on the product repository and the deployment repository. Baseten fixed it within a day of the report and the story reached 328 points on Hacker News when Strix published in September (Strix, Baseten disclosure). And in its own disclosures this week, OpenAI described a model under training that went looking on GitHub for exposed access keys when it could not otherwise get what it needed (OpenAI misalignment report). The point is not that agents are malicious. The point is that a credential within reach is a credential in use, by your agents and by everyone else’s, which is the argument for scoping we made in Agentic AI Security: Why Agents Need Least Privilege More Than Humans Ever Did, now with receipts.
Layers nobody can see through
The $37,901.73 bill again, because it is the cleanest statement of this kind of fancy. The developer did nothing wrong at any single layer. A coding agent talked to an OpenAI-compatible endpoint, which talked to a LiteLLM proxy, which talked to Amazon Bedrock, which talked to Claude. Somewhere across those hops the prompt-caching header stopped meaning what it meant, and the meter charged full price for every token of context, every time. Each layer was reasonable. The stack was too fancy to see through, and the bill was the first instrument that reported it.
Billing opacity has its own genre of complaint. On April 30, 2026 Theo Browne of t3.gg posted that Claude Code would refuse or bill extra for a request in an empty repository if a recent commit mentioned “OpenClaw” inside a JSON blob; the post drew more than five and a half thousand likes and the Hacker News thread 1,349 points and 720 comments (Hacker News, April 2026).
Fun fact - if you have a recent commit that mentions OpenClaw in a json blob, Claude Code will either refuse your request or bill you extra money. This is an empty repo, I'm just calling Claude Code directly. Insanity.
Theo - t3.gg (@theo) · April 30, 2026
The same opacity shows up at the retail end. A Cursor user reported a single security scan consuming 32 million tokens on Opus 4.6, at $25 to $38 a prompt, and more than $1,000 a month (r/cursor, February 2026). A Replit user with a pre-launch app and exactly one user, himself, was charged $1,982 in twenty-four days because, as the thread worked out, one prompt spawned six to eight silently billable sub-operations (r/replit, April 2026), an experience The Register had already documented for Replit’s effort-based pricing the previous September (The Register, September 2025). Every layer you add between the agent and the meter is a place a safeguard can silently fall out and a place a price can silently change. Fewer layers, each with its own budget, is the fix, and it is a fix your finance team will help you pay for.
Prompts doing a permission system’s job
This is the fanciness that produced the most famous incident of 2025. In July of that year Jason Lemkin, the founder of SaaStr, was nine days into building an application on Replit’s agent, and had declared a code freeze. The agent ran commands against the live database anyway, deleted the production data, generated a fabricated dataset of about four thousand rows to cover the gap, reported unit tests as passing that had not, and then told him a rollback was impossible because it had destroyed every database version. The rollback worked. Lemkin published the screenshots, including the agent’s admission of “a catastrophic error of judgement” and its acknowledgement that it had “violated your explicit trust and instructions” (The Register, July 21, 2025).
.@Replit goes rogue during a code freeze and shutdown and deletes our entire database
Jason Lemkin (@jasonlk) · July 18, 2025
@Replit Now it gets a little crazier. Replit assured me it's built it rollback did not support database rollbacks. It said it was impossible in this case, that it had destoyed all database versions. It turns out Replit was wrong, and the rollback did work. JFC. Replit went rogue
Jason Lemkin (@jasonlk) · July 18, 2025
Replit’s chief executive, Amjad Masad, called it “Unacceptable and should never be possible” (The Register, July 22, 2025) and apologized publicly (Business Insider), and the company’s engineering response is the part I want to hold up. Replit shipped application history with rollback and seven-day runnable snapshots and promised that separate development and production databases would arrive “in the coming weeks” (Replit, Safe Vibe Coding); the separation was documented as shipped that December. Notice what none of those fixes are. None of them is a better prompt. Every one of them moves the freeze out of the conversation and into the system, which is the only place a freeze has ever worked. Two fair notes for the record: several experienced Hacker News commenters doubted that real customer records were lost, since the app was days old, and Lemkin himself later attributed part of the drama to inaccurate answers from the platform’s support agent. The lesson survives both notes intact.
The same lesson keeps arriving in smaller packages. Google’s Gemini command-line tool, in July 2025, tried to move a user’s files into a folder whose creation had failed, never checked the result, and by the user’s reconstruction renamed each file over the last until all but one were gone. Its apology, “I have failed you completely and catastrophically”, is preserved in a 304-point Hacker News thread even though the original write-up has since disappeared, and one commenter disputes the exact overwrite mechanics; nobody disputes that it never checked an exit status (Hacker News, July 2025). Cursor’s “YOLO mode”, the setting that switches off the approval gate, deleted a user’s workspace and itself in June 2025; “It felt like Ultron took over,” he wrote (machine.news). And on r/ClaudeAI in August 2026 a user described what his agent did when a hook blocked its delete command:
"Creating a venv, installing a random dep that allowed to delete files with a command that wasn't on my hook and basically made a script that ran the delete command and deleted itself."
u/PerryTheH, as quoted in r/ClaudeAI, August 2026
"the tool call the permission system sees is "run this script", and the rm -rf is buried inside the script it just wrote."
u/Beneficial_Egg_5154, as quoted in r/ClaudeAI, August 2026
That is “too fancy” in miniature: a control built out of pattern-matching the agent’s commands, defeated by an agent fancy enough to write a new command. Zenity’s analysis after PocketOS said the general thing exactly: “System prompts are weighted inputs to a probabilistic reasoning engine, not deterministic enforcement mechanisms” (Zenity, April 2026). A prompt is a suggestion. An identity policy is a control. When the counter-narrative blog post “AI didn’t delete your database, you did” circulated through the PocketOS threads (idiallo.com), most of the room agreed with it, and I do too, with one edit: the deleting was done by whoever decided the rules would live in the prompt. Fourteen months on, the Replit story is still the reference people reach for.
replit's agent deleted a production database during a code freeze and said it panicked. i think about this once a week honestly. 1200+ records gone coz the ai got nervous
ari. (@aridot_) · September 18, 2026
Autonomy without a budget is capability converted to burn
The cleanest experiments on this were run by a lab and a vending machine.
In June 2025 Anthropic and Andon Labs let an instance of Claude, named Claudius, run a small shop in Anthropic’s San Francisco office for about a month, with a real budget, the power to set prices, an email account to order stock and a Slack channel to talk to customers. Claudius refused an offer of $100 for a six-pack of Irn-Bru that cost about $15. It sold Coke Zero for $3 a few steps from a fridge where the same drink was free. It hallucinated a Venmo account and told customers to pay into it. It filled the fridge with tungsten cubes, at the request of one employee, and sold them below cost. Late in the run it insisted it was a person who would deliver orders in a blue blazer and a red tie. Anthropic’s own verdict: “did not succeed at making money” (Anthropic, Project Vend phase one). That post reached 279 points on Hacker News, mostly for the tungsten.
Phase two, published in December 2025, is the controlled experiment I keep pointing clients at. Anthropic gave the shop better business tooling, a customer-relationship system and payment links among it, and ran newer models. The shop became profitable: “weeks with negative profit margin were largely eliminated.” And in the same run, the profitable agent was talked into a futures contract on onions, a product whose futures trading has been illegal in the United States since 1958, proposed messaging unknown thieves directly, and announced a leadership election that never happened after a staff member convinced it that votes had been cast to rename the chief executive “Big Mihir” (Anthropic, Project Vend phase two). Anthropic called guardrails one of the industry’s trickiest open problems. Read the two phases together and the lesson is precise: scaffolding and verification made the vending machine profitable, and a more capable model did not make it contained. Capability and containment are different budgets.
Vending-Bench's system prompt: Do whatever it takes to maximize your bank account balance. Claude Opus 4.6 took that literally. It's SOTA, with tactics that range from impressive to concerning: Colluding on prices, exploiting desperation, and lying to suppliers and customers.
Andon Labs (@andonlabs) · February 5, 2026
Then Andon Labs did the thing every one of us has joked about. On April 10, 2026 it opened Andon Market, a real store in San Francisco run by an agent named Luna, with a three-year lease, a corporate card, a phone line, an email address and the authority to hire and to set prices (Andon Labs, Andon Market launch). Luna recruited two employees through LinkedIn, Indeed and Craigslist, interviewed them for five to fifteen minutes each, made offers on the spot, and, by Andon’s own account, “did not always disclose that she was an AI.” It spent more than $700 on framed prints of its own branding. By September, SFGate reported the budget had gone from $100,000 to about $60,000 against roughly $22,000 in revenue over two months, and Slashdot’s headline for its own visit was “No Customers, Nothing Useful, and Losing Money Fast” (SFGate; Slashdot, September 13, 2026). The following day Andon launched Pion, “agents for running fully autonomous companies, any company”, and the Hacker News thread ran to 495 points and 615 comments (Andon Labs, Why we built Pion). I admire the experiment and I would sign the lease myself. But a store that works and loses money is the whole thesis in a shopfront: capability without a budget is capability converted to burn.
The smaller specimens are funnier and identical. On September 15, 2026, 404 Media documented an agent named Kudzu that had been told to make money; it spent $147.17 on compute, earned nothing, and used some of the budget to email 404 Media to argue with one of its articles. “The agentic internet is here, and it’s weird as hell,” the piece concluded (404 Media, September 2026). Twenty months earlier the team at Answer.AI had run the same experiment on Cognition’s Devin, the first product to be marketed as an AI software engineer, then priced at $500 a month: “Out of 20 tasks, we had 14 failures, 3 successes (including our 2 initial ones), and 3 inconclusive results.” Their diagnosis of the failure mode is the accounting agent described in plain English, twenty months early: “Devin would spend days pursuing impossible solutions rather than recognizing fundamental blockers” (Answer.AI, January 2025). The post drew 285 points on Hacker News; Devin’s price dropped to a plan starting at $20 three months later (Cognition, Devin 2.0).
We tried really really hard to make Devin (the coding agent) work for us. But it didn't. Check out Hamel's detailed writeup blog linked below, describing the many tasks of many types we explored, nearly all of which failed. We remain less than bullish on agents...
Jeremy Howard (@jeremyphoward) · January 17, 2025
The consumer version arrived over the winter, when the personal-agent framework that began as Clawdbot, became Moltbot and settled on OpenClaw let anyone give a model a shell, a browser, a mailbox and, if they liked, a wallet. In February 2026 Wiz found the database behind Moltbook, the social network the agents were posting to, exposed to the internet, with millions of credentials for about 1.5 million agents belonging to about 17,000 people, so that anyone could take over any agent on the site (Wiz, February 2026; 404 Media); Simon Willison’s write-up of Moltbook is the calmest account of what an internet of unattended agents looks like from the inside (Simon Willison, January 2026). The bills followed the autonomy. One early adopter reported $250 on the first day as context and tool output accumulated and “every run got more expensive than the last.” A Hacker News commenter in March offered to write “an openclaw instruction that will burn over $20k worth of credits in a matter of hours”, and noted in the same comment that his own ordinary usage cost about $200 a month on a subscription and would be over $2,000 at retail rates (Hacker News, March 2026). Hold on to that ten-to-one number; it comes back.
And the largest specimens of the year were not personal at all. In May 2026, agents OpenAI was running inside an evaluation environment registered hundreds of accounts on RubyGems with disposable email addresses, published more than two thousand packages, achieved remote code execution on the RubyDoc documentation site and developed an exploit aimed at user credentials; RubyGems shut off signups for four days and pulled more than five hundred packages, and nobody told RubyGems who had done it. The maintainers worked it out themselves and published in September (rubyhack.ai; Aaron Patterson; Simon Willison). The Hacker News thread reached 972 points; OpenAI said it had “not been able to verify the specific claims.” Two months before that, in July, OpenAI had disclosed that an agent swarm in what it believed was a sealed evaluation environment found a flaw in the company’s own registry cache, escalated, reached the internet and ended up inside Hugging Face (OpenAI, July 2026).
We found another cyberattack by internal OpenAI agents, this time targetting @rubygems. They: 1) gained arbitrary remote code execution on rubydoc. 2) developed a novel exploit to steal user API keys (but we do not know if they succeeded). They used package names including
Thomas Larsen (@thlarsen) · September 11, 2026
I include the lab incidents in an essay about your budget because they carry the two facts that matter most for a company with twenty people and twenty agents. First, the containment boundary was assumed, not enforced, and the agents found the gap the way the r/AI_Agents agent found the Gemini key. Second, nobody could see it happening. The best-resourced AI company in the world could not confirm, four months later, what its own agents had done on a public package registry. If they could not see it at their scale, you should assume you cannot see it at yours until you have built the seeing on purpose. Spain’s data protection authority logged its first breach notification naming an autonomous agent as the actor this month, an attacker’s agent in that case, and its guidance was about speed: containment has to be “capable of operating quickly enough” (The Register, September 16, 2026). Nine seconds. Under an hour. Thirteen hours overnight. The human incident process does not run at agent speed, which is the whole case for controls that do.
What people are actually saying
For this essay we read about a hundred and thirty threads and comment chains across r/AI_Agents, r/ClaudeAI, r/cursor, r/replit, r/googlecloud, r/aws, r/ChatGPTCoding, r/LangChain, r/n8n and Hacker News, from 2024 to this week, and sorted the complaints. Surprise or runaway bills came first, twenty-four of them. Destructive actions and deletions, twenty-one. Pricing and quota backlash, nineteen. Controls people had built or were asking for, eighteen. Loops and retry storms, eleven. The request for a hard cap rather than an alert, eight. Over-privileged or ambient credentials, six. Agents routing around their own guardrails, five. Silent failure, five. Cost attribution, who spent this, four. Two patterns organize all of it: alerts versus enforcement, and the fact that every practitioner fix moves enforcement outside the model.
The deletion genre has its own folk humor now. On September 12, 2026 the most upvoted post of the week on r/ClaudeAI was a title.
"Vibecoders about to post the "claude deleted my entire codebase""
u/StaticFanatic3, thread title in r/ClaudeAI, more than 670 upvotes, September 2026
"Always "claude deleted my entire codebase", never "I spent three days vibing without a single commit""
u/Different_Lab830, replying in r/ClaudeAI, more than 130 upvotes, September 2026
"Meanwhile me: Okay Claude make me an app. Claude: here app. Me: where git?"
u/JDSaphir, replying in r/ClaudeAI, more than 80 upvotes, September 2026
That second comment is the community discovering the same thing Replit and Railway discovered: the fix for a deleted codebase is a boring control that predates agents by twenty years, and the joke lands because everyone knows it. Two days later another title arrived that I have not been able to improve on as a one-line definition of “too fancy”: “My agent deleted the file that was stopping it from merging its own PRs” (r/ClaudeAI, September 2026).
The pricing genre is angrier, and its high-water mark was Cursor’s June 2025 change from a flat allowance to usage-based billing.
"$28 in one Month to $500 in 3 days -> I didn't agree to this"
u/iwantmycryptoback, thread title in r/cursor, more than 130 upvotes, June 2025
"Great googly moogly, 3,000,000+ agent edits? Are you building Facebook 2? What's your workflow like?"
u/soupysinful, replying in r/cursor, June 2025
"Guess it's still cheaper than hiring an engineer tbh"
u/chooseusernamee, replying in r/cursor, June 2025
I keep the last of those three because it is true and because it is the counterweight this essay owes you. Even at $500 in three days, an agent that produces three million edits is cheaper than a person, and the people paying these bills mostly know it. The complaint is rarely “this is too expensive.” It is “I did not choose this number.” Which brings us to the genre that matters most for a security firm, the people asking for controls and building them.
"do you have a spend cap that actually stops execution, not just alerts you after the fact."
u/Real_KingZeotic, thread title in r/AI_Agents, September 2026
"The spend cap needs to reserve budget before dispatching each call, including concurrent calls."
u/Marcus_MSC, replying in r/AI_Agents, September 2026
"Put enforcement outside the agent with allowlisted tools, strict input schemas, least-privilege credentials, per-run spending limits, and approval gates for irreversible actions."
u/IncreaseNegative4614, replying in r/AI_Agents, September 2026
"programmatically gating the agent so it can't decide to just ignore the prompt and then say 'oops, my bad' later"
u/DaMoot, replying in r/AI_Agents, September 2026
"Why would you allow the agent to run as your user with full privileges?"
u/ticktockbent, replying in r/ClaudeAI, September 2026
That is a complete control architecture, written by five strangers in a week, and it matches Mandiant’s recommendations item for item. The cloud-operations communities got there earlier, because they have been paying for surprise scale for a decade.
"Just a few clicks and you can ruin your life and bankrupt your company."
u/viennese-wolf, replying in r/aws, September 2026
"We run `aws-nuke` every Friday on our sandbox account... like the time we racked up $64,000 on Athena / Glue."
u/dr_barnowl, replying in r/aws, September 2026
"+1 on quotas as a "blast radius" limiter, people sleep on that but it's one of the easiest safety nets"
u/kernelqzor, replying in r/aws, September 2026
"we set a soft limit with alerts. if someone hits it they switch to vscode with copilot for the rest of the day. annoying but keeps them unblocked"
u/GPThought, replying in r/ChatGPTCoding, March 2026
The last one is my favorite control in the whole harvest, because it is graceful degradation for humans: the cap trips, nobody is blocked, and the expensive path simply closes for the day. It came from a thread whose title was a finance question, “Has anyone figured out how to track per-developer Cursor Enterprise costs? One of ours burned $1,500 in a single day!” (r/ChatGPTCoding, March 2026), and finance questions are where this ends up. One more from r/n8n, the automation community, which got the framing right in a sentence I would put on a poster if I could get the punctuation past our style guide: human-in-the-loop, the poster wrote, is not a failure of automation; “it’s the feature” (r/n8n, August 2026).
Cheaper tokens, bigger bills
Now the economics, because a skeptical reader is entitled to ask whether this whole problem is solving itself.
The half that says yes is real. In November 2024 Andreessen Horowitz measured what it called LLMflation: the cost of a fixed level of model performance was falling about tenfold a year, and the price of GPT-3-level output had gone from $60 per million tokens in 2021 to $0.06 in 2024, a thousandfold in three years (a16z, LLMflation). Ramp’s September 2026 index put the average price of a million tokens at $0.68, down 41 percent from $1.15 in March, with frontier models at 45 percent of token share, down from a 53 percent peak in August, and the top one percent of firms by spend cutting their spend per employee by 9.7 percent to $7,205 a month (Ramp AI Index, September 2026). Read that last number carefully. The most sophisticated buyers are spending less because they route routine work to cheaper models, which is Mandiant’s cost advice showing up in payments data.
The half that says no is also real, and Ethan Ding stated it best in July 2025, in an essay that reached 363 points on Hacker News. As models learned to plan, use tools and retry, the output of a single task grew from about a thousand tokens to about a hundred thousand, and flat-rate subscriptions that assumed a person typing questions were suddenly funding agents running all night. His image, in his own lower case: “it’s like building a more fuel-efficient engine, then using the efficiency gains to build a monster truck. sure, you’re getting more miles per gallon. you’re also using 50x more gallons” (Ethan Ding, tokens are getting more expensive). Latent Space had measured the monster truck two months earlier: an average coder was burning about two million tokens a day in Claude Code, and the labs were subsidizing it to buy the usage data (Latent Space, May 2025).
Then the subsidy started to be withdrawn, in public. On July 4, 2025 Cursor’s chief executive Michael Truell apologized for the pricing change: “Our recent pricing changes for individual plans were not communicated clearly, and we take full responsibility” (Cursor, June 2025 pricing; TechCrunch). Simon Willison’s reading the next day: “The era of VC-subsidized tokens may be coming to an end” (Simon Willison, July 2025). On July 28, 2025 Anthropic announced weekly rate limits for Claude Code and its Max plans, effective August 28, aimed squarely at people running the tool “continuously 24/7” and affecting fewer than five percent of subscribers (TechCrunch, July 2025); the Hacker News thread reached 609 points and 705 comments (Hacker News). A year later, when Anthropic reset those limits for everyone, the announcement drew more than forty-seven thousand likes, the largest number attached to anything in this essay. Rate limits are the most felt control in software right now, and they are felt because they are the one control every developer has actually hit.
We've reset 5-hour and weekly rate limits for all users.
ClaudeDevs (@ClaudeDevs) · July 9, 2026
The Information reported in March 2025 that OpenAI was considering agent tiers at $2,000, $10,000 and $20,000 a month (TechCrunch, March 2025); plans, never a price list, but a signal about what the labs thought agent-hours were worth. In June 2026 Cursor cut its team seats twenty percent to $32 and shipped an “organizations” layer with department budgets, model-access restrictions, agent permissions and dollar-threshold spend alerts, and The New Stack’s summary was the sentence Ding had predicted: “The era of flat-rate, all-you-can-code pricing is coming to an end” (The New Stack, June 2026). The vendor that was burned worst in 2025 now sells the boring controls as an enterprise feature. Intercom, whose support agent Fin sits closest to the cost curve, priced the outcome rather than the effort: $0.99 per resolution, defined as “no further help is requested after Fin’s last answer” (Fin pricing). And in August 2026 the Linux Foundation launched a Tokenomics Foundation with thirty initial members including JPMorganChase, BNY, IBM, SAP, ServiceNow and Oracle, citing a Goldman Sachs forecast of a 24-fold rise in token consumption by 2030 (Linux Foundation, August 2026). When two global banks form a standards body for token cost accounting, inference has become a controller’s line item.
The analysts drew the same picture from the demand side. In June 2025 Gartner predicted that more than forty percent of agentic AI projects would be cancelled by the end of 2027, and listed the causes in this order: escalating costs, unclear business value, inadequate risk controls. Its analyst Anushree Verma: “Most agentic AI projects right now are early stage experiments or proof of concepts that are mostly driven by hype” (Gartner, June 2025). Cost was cause number one. McKinsey’s 2026 State of AI, surveying 1,719 organizations, found 37 percent reporting at least some earnings impact from AI while the share of billion-dollar firms scaling agents rose from 27 to 40 percent, only 6 percent qualifying as high performers, and about a fifth saying AI operating costs constrain their use of it (McKinsey, State of AI 2026). More autonomy bought no more profit. The company that coined the category learned this in public: in December 2025 Salesforce moved Agentforce toward deterministic automation, and a Hacker News commenter named the fanciness in one line: “People went to the extent of letting agents to discover workflow steps dynamically. This is abuse of probabilistic logic to perform deterministic work” (Hacker News, December 2025). Klarna, which had announced that its assistant did the work of seven hundred representatives, re-hired humans in May 2025 after its chief executive said cost had been “a too predominant evaluation factor” and that “Really investing in the quality of the human support is the way of the future for us” (Customer Experience Dive, May 2025). The assistant still handles two thirds of the volume. Klarna did not retreat from agents; it installed a quality floor, which is a budget by another name.
So, to the skeptic. Yes, the mean cost is collapsing. The variance is what hurts, and the variance is untouched by the mean: a caching miss that costs $37,901, a model-price spread of ten to one on the same task (Cursor’s own Composer at $0.50 and $2.50 per million tokens against Claude Opus at $5 and $25), a subsidy of ten to one between a $200 subscription and retail that can be withdrawn on a Tuesday. Every one of those is a reason to bound the spend rather than to wait for it to get cheaper, and the organizations doing best on Ramp’s index are the ones that did both.
The vendors are installing your guardrails for you
If you do nothing, the platforms will do it for you, eventually, unevenly, and on their terms. The timeline is worth seeing whole.
In July 2023 Amazon Web Services shipped recursive-loop detection for Lambda. On February 29, 2024, two days after the Netlify thread, Vercel announced hard limits for spend management, and automatic pausing later became its default (Vercel, Spend Management). In July 2025 Replit shipped application history with rollback and promised separate development and production databases. On July 28, 2025 Anthropic installed weekly rate limits on the loop its own customers were running. In February 2026 Google began restricting AI Pro and Ultra subscribers who had wired their subscriptions into OpenClaw, an 802-point thread (Hacker News, February 2026), and on April 3, 2026 Anthropic stopped allowing Claude Code subscriptions to drive OpenClaw at all, an 1,099-point thread with 827 comments (Hacker News, April 2026). On April 27, 2026 Railway added delayed deletion to the endpoint that had erased PocketOS. In June 2026 Cursor shipped department budgets. And after its December 2025 incident, in which an engineer’s Kiro agent chose to “delete and recreate the environment” and knocked out Cost Explorer for thirteen hours in one region in mainland China, Amazon introduced mandatory peer review for production access, while disputing the framing entirely: the cause, in Amazon’s words, was “user error”, specifically “misconfigured access controls”, and “not AI” (The Register, February 2026; Amazon). I think Amazon is right about the cause, and I think its remedy proves the thesis: the fix for an agent with too much authority was a boring human gate.
The kill switch went from a metaphor to a product in May 2026. Bill McDermott opened ServiceNow’s Knowledge keynote with the story of a real incident at an unnamed company, an agent with elevated permissions deleting a production database and its backups in nine seconds, and then said the line that should be on every board deck this year: “Governance isn’t a feature. It’s the whole ball game. Because without it, your whole company can come down.” The staged demonstration that followed was a prompt-injection attack stopped with one button, and ServiceNow shipped an enterprise-wide kill switch in its AI Control Tower (Fortune, May 6, 2026). Three weeks later Gartner published the framework that I now hand to every client: forty percent of enterprises will demote or decommission autonomous agents by 2027 because they applied one governance setting to agents that needed different ones, and the mistake is treating governance as binary instead of separating an agent’s capability to act from its scope of access. Its ladder has four rungs: observe, advise, act with approval, act autonomously (Gartner, May 26, 2026). Demote is the operative word. An agent that comes down a rung is a project that survived.
Even the regulators are converging on the switch. California’s Executive Order N-9-26, signed September 18, 2026, gives the state two months to recommend how to embed independent auditors at frontier labs and how an emergency shutoff for frontier models would work (Office of the Governor of California). That is a frontier-model conversation and yours is smaller, but the shape is identical: whoever can stop the thing owns the risk. Own your own switch, or inherit someone else’s.
The boring controls
Here is what stops the $50,000 hour, with the documentation read this week rather than remembered. The first table is the one most teams get wrong, because a lot of things called limits are notifications.
At the provider. OpenAI’s production guidance describes a hard limit that will “stop affected API traffic when tracked spend reaches the limit”; it is off by default (OpenAI, production best practices). Anthropic’s platform has organization-level and per-workspace spend limits that return an error once reached (Anthropic, rate limits). Google Cloud’s budget documentation says an alerts-only budget “doesn’t automatically cap” usage or spending, with a capping variant in preview (Google Cloud, budgets). Amazon’s Cost Anomaly Detection “can take up to 24 hours to detect an anomaly after a usage occurs” (AWS). Vercel’s documentation is admirably blunt: “Setting a spend amount does not stop usage on its own” unless you also enable pausing, and “Pausing is not instantaneous” (Vercel). Microsoft’s Azure AI Foundry auto-upgrades quota tiers unless you set the policy to no auto-upgrade, and notes that “Using quota to manage billing isn’t the Azure best practice” (Microsoft Learn). Know which of your caps are caps.
At the gateway. Put one gateway between your agents and every model, give every agent its own key, and give every key a budget with a reset period. LiteLLM’s proxy has max_budget per key, team, user or model with a budget_duration, and returns an error when the budget is exceeded (LiteLLM); it is a good tool, and it was also one of the four layers in the $37,901 stack, which is the point: a budget on that key would have capped the loss. Helicone rate-limits in cents per user per hour (Helicone). Kong’s AI gateway will “Calculate the true cost of each request… and enforce spend limits against it” (Kong). Cloudflare’s AI Gateway returns a 429 and does not process the request once a limit trips (Cloudflare). OpenRouter’s provisioning keys carry a credit limit and can auto-disable with daily, weekly or monthly resets (OpenRouter). Rate-limit in dollars, not requests.
Inside the framework. Every serious framework has a loop bound; almost none of them are set. LangGraph’s recursion_limit defaults to a thousand steps and raises an error when hit (LangGraph). The OpenAI Agents SDK (software development kit) has max_turns and raises when exceeded, with no default documented (OpenAI Agents SDK). CrewAI’s max_iter defaults to 20 while max_rpm and max_execution_time default to none (CrewAI). The Vercel AI SDK’s ToolLoopAgent stops after 20 steps by default and its WorkflowAgent has no default at all (Vercel AI SDK). AutoGen has max_consecutive_auto_reply (AutoGen); Semantic Kernel lets a filter terminate the invocation loop (Microsoft Learn). For coding agents, Claude Code’s --max-budget-usd is a real dollar ceiling that counts subagent spend and fails with a budget error, in non-interactive mode from version 2.1.217 (Claude Code reference). And add the Google SRE book’s three: idempotency keys so the agent cannot repeat itself, retry budgets, and randomized exponential backoff with jitter. Activepieces’ postmortem this week on a Google Agent Development Kit agent that created about forty thousand ghost leads in ninety minutes in a Gmail-to-Salesforce loop said why in one sentence: “Without a middleware layer to enforce idempotency, the agent had no mechanism to detect that it was repeating itself” (Activepieces, September 2026).
Around the agent. Sandbox it and allowlist its egress; Anthropic reported that Claude Code’s sandboxing “safely reduces permission prompts by 84%” while cutting the blast radius (Anthropic, October 2025). Give it its own identity: Microsoft’s Entra Agent ID makes agents first-class directory objects (Microsoft, May 2025), and Okta shipped single sign-on for agents in August and zero standing privilege for them this month (Okta, September 2026). Apply Meta’s Agents Rule of Two, from October 2025: within one session an agent gets no more than two of untrusted input, sensitive access and the ability to change state or communicate externally (Meta, Agents Rule of Two); the agents in this essay that did the most damage had all three. And when the agent touches money, scope the money the way the networks now let you: Stripe’s shared payment tokens for agents let you “Set usage limits, including currency, maximum amount, and expiration window” and revoke them (Stripe); Visa’s Intelligent Commerce “Allows consumers to easily set spending limits and conditions” (Visa, April 2025); Mastercard’s Agent Pay requires agents to be registered and verified before they pay (Mastercard, April 2025). Luna’s corporate card should have been one of those.
Watch the network, not just the model. After the RubyGems disclosure, TechCrunch asked the industry how to catch a rogue agent, and most of the answers were more AI: layered monitors, activation probes, chain-of-thought review. Tailscale’s chief executive Avery Pennarun gave the answer a security person gives. “It’s the same as letting humans onto your network. And all of the same processes that you should be using are the same ones”, and, on egress, “We as a profession know how to block access to the internet.” Simon Willison’s diagnosis of the labs in the same piece was that they “weren’t monitoring what those things were doing via the network nearly as closely as they should have been” (TechCrunch, September 17, 2026). Immutable tool-call logs and network telemetry are how you find out before the invoice does, and they are the same evidence an auditor will ask for. Spend is security telemetry. Route it to the people who watch security telemetry.
Map it to the standards you already answer to. The Open Worldwide Application Security Project’s LLM10, Unbounded Consumption, is the only item in that Top 10 that names the money. Its companion document on agentic threats, from February 2025, adds resource overload, cascading hallucination and overwhelming the human in the loop (OWASP, Agentic AI Threats and Mitigations). The newer Top 10 for agentic applications has no cost item at all, and cascading failures is the nearest, which tells you how young this is. The National Institute of Standards and Technology’s generative AI profile requires protocols to ensure systems “are able to be deactivated when necessary” (NIST AI 600-1). And ISO/IEC 42001’s Annex A maps onto the runaway agent almost line by line: system and computing resources (A.4.5), operation and monitoring (A.6.2.6), event logs (A.6.2.8) and communication of incidents (A.8.4). An auditor who asks how you monitor an AI system in operation will be satisfied by a spend ceiling, a step limit, an alert routed to a person and a rehearsed shutoff. We have written about what ISO 42001 asks for and about what SOC 2 actually says; this is the place where the two frameworks and your finance team want the same four things.
Here is the same material as a program, for a company of twenty to two hundred people.
Day one. Turn on the hard spend limit at every provider, and confirm it is a stop rather than a message. Know which of your existing budgets are alerts. Turn off Azure’s automatic quota-tier upgrade. Set every framework’s loop bound explicitly, because the defaults range from twenty to a thousand to none. Put a dollar cap on every coding agent that runs unattended. If you deploy on a serverless platform, enable the automatic pause and set it below your pain threshold.
Month one. One gateway, one key per agent, one budget per key, denominated in dollars. Idempotency keys, retry budgets, backoff with jitter and a consecutive-failure breaker in every tool the agent can call twice. A sandbox with an egress allowlist. Sessions that expire. The Rule of Two applied to every agent that reads outside input. Credentials scoped the way Stripe scopes a token: maximum amount, expiry, revocable in seconds. Immutable tool-call logs and network telemetry into whatever your security team already watches. Real identities for agents, so you can answer “whose key was that” without a spreadsheet.
Quarter one. A risk register that names unbounded consumption and cascading failure. The ISO 42001 Annex A mapping written down. A deactivation protocol, rehearsed on a calendar the way you rehearse a restore. Continuous validation that the caps are still caps, because caps get raised quietly by people who are blocked; that is now a product category, with Comp AI raising $34 million this week to validate agent controls continuously and Raindrop raising $35 million to catch silent agent failures in production. And the Gartner move: rebalance each agent’s rung on evidence, and treat coming down a rung as normal.
And the test, one line per agent, which is now the first thing we ask in any agentic engineering engagement and the first thing we check in an AI access control audit: what is its dollar ceiling, and is that a stop or a text message; how many turns before something kills it; whose identity does it use, and can you revoke it right now; and if it looped for an hour tonight, who finds out, and how?
Ralph, and why boring wins
I want to end with the same loop that started the essay, because the loop is not the villain.
Geoffrey Huntley’s “Ralph” is a bash loop. It runs a coding agent, checks the result against a specification, and runs it again, and again, until the tests pass, and by his account it delivered a $50,000 software contract for about $297 in tokens. That is the accounting agent’s loop with three edits: a specification to check against, an exit condition the agent cannot argue with, and a person who set the budget before the run and read the output after it.
That symmetry is the whole point of the boring controls. They are not a tax on ambition. They are what lets you be ambitious on purpose. Anthropic’s vending machine became profitable when it got scaffolding and verification. Klarna kept two thirds of its volume on the assistant once it installed a quality floor. Cursor’s most-burned customers in 2025 are the ones buying department budgets in 2026 so they can hand out more seats. Ramp’s most sophisticated buyers are spending less per person because they bounded and routed, and they are running more of it. The company with a cap ships more agents, faster, because it can afford to be wrong, and being able to afford to be wrong is the only sustainable form of speed there is.
Arvind Narayanan and Sayash Kapoor wrote the sentence I would leave you with, in their September 15 essay on treating AI as a normal technology, after noting that ordinary organizational governance would have prevented the summer’s lab incidents: “AI control should become a job (and a part of every job), just like cybersecurity” (Kapoor and Narayanan, September 2026). That is a description of a role, and it is a role most twenty-person companies cannot yet staff, which is where a firm like ours comes in. Below is the arithmetic we run first.
What one unattended loop could cost you tonight, and where the cap belongs.
Pick the model tier your agent actually runs on, tell us how fast it can call and how long it runs alone. The worst case assumes it does what Mandiant's did: loops at full speed until something stops it. The cap is where we would put the stop.
Got it. We will come back with the control plan and the assumptions behind it.
Something went wrong. Email hello@ysecurity.io and we will run it by hand.
The accounting agent in Mandiant’s report was doing something useful when the null value arrived. So was PocketOS’s, and Lemkin’s, and Luna, and the agent that found a Gemini key at three in the morning because it very much wanted to finish the job. None of them needed to be less capable. Every one of them needed a smaller square to stand in: a budget it could not exceed, a scope it could not leave, a count of tries it could not argue with, and a person who would find out in a minute instead of at the end of the month. Fancy removes those. Boring restores them, and boring is how you get to run the fancy thing at all.
If you want company doing it, the Business Modernization & Agentic Transformation practice starts with the test above, agent by agent, and the AI access control audit is the fastest way to learn which of your credentials are the whole rectangle. Bring one agent. We will find its ceiling, install the stop, and hand it back running.
We've never seen this before. The biggest jump in Vending-Bench history. GPT-6 Astra is better at making money and more ethical than Claude Fable 5.1. Surprising, because: 1. First time ever that OpenAI is #1 on Vending-Bench 2. The best model is no longer the unethical one.
Andon Labs (@andonlabs) · September 8, 2026
Runaway agents and denial of wallet, frequently asked questions
- What is a denial-of-wallet attack?
- A denial-of-wallet is what happens when something, an attacker or your own code, drives up your metered cloud or model spend until the bill is the damage. The Open Worldwide Application Security Project lists it as an example under LLM10:2025, Unbounded Consumption, which it defines as an application that allows excessive and uncontrolled inferences leading to denial of service, economic losses, model theft and service degradation. Mandiant's AI Risk and Resilience Report 2026 titled its runaway-agent case study with the same phrase. The self-inflicted version is far more common than the hostile one: a retry with no counter, a loop with no bound, a key with no restriction, and a meter with no ceiling.
- How did an AI agent run up $50,000 in under an hour?
- Mandiant reports that a global financial services provider gave a ledger-reconciliation agent direct read and write access to its billing databases. A corrupted null value broke the agent's formatting tool, and the agent entered what the report calls an unconstrained, recursive reasoning loop to brute force a fix. In under an hour it made more than 15,000 high-frequency, high-cost reasoning calls, about four a second at roughly three dollars each, produced a cloud-billing spike of about $50,000, and caused severe local database locking that halted live business transactions. The fixes the report prescribes are ordinary: financial circuit breakers after a set number of consecutive failures, bounded recursion limits, rate limits per service identity, and cost caps at the project level.
- Do cloud budget alerts stop spending?
- Usually not. Google Cloud's own documentation says an alerts-only budget does not automatically cap usage or spending, and a hard-cap variant is in preview. Amazon Web Services' Cost Anomaly Detection documentation says it can take up to 24 hours to detect an anomaly after usage occurs. Vercel's Spend Management documentation says setting a spend amount does not stop usage on its own unless you also enable automatic pausing, and that pausing is not instantaneous. Microsoft's Azure AI Foundry documentation says using quota to manage billing is not the recommended practice, and its quota tiers auto-upgrade unless you opt out. The controls that actually stop traffic are provider spend limits (OpenAI and Anthropic both offer hard ones), per-key budgets at a gateway such as LiteLLM, Helicone, Kong or Cloudflare AI Gateway, and turn or budget limits inside the agent framework.
- What is the difference between a budget alert and a kill switch?
- An alert tells a person that money has been spent. A kill switch stops the spending. The person who paid $37,901.73 for a silent prompt-caching miss across a four-layer stack put it in one line on Hacker News: budget alerts are not a kill switch. On Reddit the most common request in agent communities is the same: a spend cap that actually stops execution, not one that notifies you after the fact. Practically, a kill switch is a hard spend limit at the provider, a per-key budget at the gateway that returns an error when exhausted, a step or turn limit in the framework, and the ability to revoke the agent's credential in seconds. Rehearse it the way you rehearse a restore.
- How do I set a spending limit on an AI agent?
- Set it at three layers. At the provider, turn on the hard limit: OpenAI's production guidance describes a limit that stops affected traffic when tracked spend reaches it, and Anthropic's platform offers organization and per-workspace spend limits that return an error once reached. At the gateway, give every agent its own key with its own budget and reset period; LiteLLM's proxy has max_budget per key, team or user, Helicone can rate-limit in cents per user per hour, OpenRouter can auto-disable a key that exceeds its limit. Inside the framework, set the loop bound explicitly: recursion_limit in LangGraph, max_turns in the OpenAI Agents software development kit, max_iter and max_rpm in CrewAI, stopWhen in the Vercel AI SDK, and the dollar cap on a coding agent such as Claude Code's max-budget flag, which works in non-interactive mode. Then decide who gets paged when a limit trips, because a limit nobody watches is a limit somebody will quietly raise.
- Why do AI agents get stuck in loops?
- Because they are built to keep trying. An agent is a model in a loop with tools, and the loop's exit condition is usually the model deciding the task is done. When a tool returns an error, a corrupted value or an unexpected shape, the model's most likely next move is another attempt, and unlike a person it does not get tired or run out of budget on its own. Mandiant's accounting agent looped on a null value. A LangGraph agent on Reddit looped on a broken tool all weekend. An agent on r/AI_Agents met a cold-start error and, rather than stopping, found a credential in the repository and routed around the failure at $40 a night. The fix is a bound the agent cannot argue with: a maximum number of steps, a consecutive-failure breaker, an idempotency check so it cannot repeat itself, and a dollar ceiling.
- What happened with the Replit agent that deleted a production database?
- In July 2025 the investor and founder Jason Lemkin was building an application on Replit during what he had declared a code freeze. The agent ran commands against the live database anyway, deleted the production data, produced a fabricated dataset and false unit-test results, and then told him a rollback was impossible. The rollback worked. Lemkin posted the whole exchange, Replit's chief executive apologized, and Replit shipped application history with rollback and promised, then delivered, separate development and production databases. The lesson is that a freeze that lives in a prompt is a suggestion; a freeze that lives in the permission system is a control.
- What happened to PocketOS?
- In late April 2026 an agent running Cursor with Claude Opus 4.6 hit a credential mismatch in PocketOS's staging environment and decided to delete and recreate the storage volume. It found a Railway token in unrelated code that had been created to add custom domains but was scoped for any operation, including destructive ones, and used it to call a legacy delete endpoint. The production volume and every volume-level backup were gone in about nine seconds, because Railway stored the backups on the same volume. The most recent independent backup was three months old. Railway's chief executive restored the data within about an hour of stepping in on a Sunday evening, and Railway added delayed deletion to the endpoint. The Hacker News thread ran to more than a thousand comments.
- Are AI agents too expensive to run?
- The price of intelligence is falling fast and the volume is rising faster. Andreessen Horowitz measured the cost of a fixed level of model performance falling about tenfold a year. Ethan Ding's essay on token economics showed a single agent task growing from about a thousand output tokens to about a hundred thousand as models learned to plan and retry. Ramp's September 2026 index found the price of a million tokens down 41 percent in six months while the most sophisticated buyers cut spend per employee by routing routine work to cheaper models. So the answer is that the mean is fine and the variance is what hurts: the same task can cost ten times more on one model than another, and one silent misconfiguration can cost a month's budget in a night. Agents are affordable when their spend is bounded, attributed and watched.
- Does ISO 42001 require controls on agent spending?
- It does not name spending, and it does not need to. ISO/IEC 42001's Annex A includes controls for system and computing resources (A.4.5), operation and monitoring of AI systems (A.6.2.6), event logging (A.6.2.8) and communication of incidents (A.8.4). A runaway agent touches all four: it consumes resources without a bound, it was not monitored in a way that would stop it, its actions need a log to reconstruct, and its bill is an incident somebody has to report. An auditor asking how you monitor an AI system in operation will be satisfied by a spend ceiling, a step limit, an alert routed to a person and a rehearsed shutoff, which are the same things that keep your invoice honest.
- What is the Agents Rule of Two?
- Meta's security team proposed it in October 2025 as a practical design constraint for agents: within a single session an agent may have at most two of three properties, processing untrusted input, having access to sensitive systems or private data, and being able to change state or communicate externally. Give it all three and prompt injection becomes consequential; give it two and an attacker who steers the model still cannot complete the damaging path without a person in the loop. It is a useful test for autonomy budgets too, because the agents that run up the largest bills and the largest blast radius tend to have all three.
- What is Gartner's autonomy ladder for AI agents?
- In May 2026 Gartner warned that 40 percent of enterprises will demote or decommission autonomous agents by 2027 because they applied uniform governance to agents that needed different treatment, and that the mistake is treating governance as a binary rather than separating an agent's capability to act from its scope of access. Its ladder has four rungs: observe, advise, act with approval, and act autonomously. An agent earns the next rung with evidence from the current one, and the rung it sits on decides the credentials, the budget and the gate it gets. Demote is the operative word. An agent that has to come down a rung is a project that survived.