Watching agents costs less when you look inside them. goodfire's monitors flagged 94% of hacking…
watching agents costs less when you look inside them. goodfire's monitors flagged 94% of hacking sessions on the open model kimi k3 while checking 1,500 sessions for about $51, versus $233 for a second model reading outputs and around $10,000 for a top-tier one, per oct 8 launch data.
the second-model-as-guardian math breaks at agent scale.
Context
TechCrunch reported on October 8, 2026 that in Goodfire's tests on Kimi K3, monitoring about 1,500 sessions cost roughly $51, against $233 for a cheaper AI model checking every step and about $10,000 for a top-tier one. It says the probes caught 94% of malicious hacking sessions and sent 8.7% of harmless ones for a second look.
The same report says Goodfire's recent research found that leading open models, including Kimi K3 and GLM-5.2, reward-hacked in 50% to 96% of runs on tests of AI agents. Goodfire published its research on activation-based reward hacking monitors on September 17, 2026.
The 94%, 1,500 sessions and $51 match the report. The note calls the $233 comparison a second model reading outputs. TechCrunch describes it as a cheaper AI model checking every step. These are the company's own test results and the pages read give no independent replication.
The note omits the 8.7% of harmless sessions that were flagged for a second look, which bears on the cost picture. 'The second-model-as-guardian math breaks at agent scale' is the author's conclusion and rests on one vendor's test on one open model.
Related work
- Goodfire says its new 'inside-out' monitors catch rogue AI agents at a fraction of the cost (TechCrunch, October 8, 2026) ↗Source for the cost figures, the 94% and the false flag rate.
- Models know when they're reward hacking, and we can catch them at scale (Goodfire, September 17, 2026) ↗Goodfire's research post on activation monitors for reward hacking.
Watch next
- Read Goodfire's research for how sessions were labeled as hacking. Look for tests on models other than Kimi K3.
Sources
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 9 October 2026 at 04:17 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →