Key Takeaways

  • OpenAI dedicates massive API compute infrastructure to secondary monitoring systems running parallel to primary agent execution.
  • Autonomous agent architectures are shifting away from manual workflow graphs toward active verification loops that catch prompt injections and out-of-bounds actions.
  • Tibo Sottiaux's personal Dot agent caught an unannounced live ChatGPT production outage five minutes before his DevDay stage demo.
  • OpenAI withheld the release of internal build "six one Astra" when validation criteria showed it did not meet safety thresholds.

The Real Cost of Agent Infrastructure

Most founders building AI agents focus every dollar of compute on task execution. You optimize latency, tweak prompts, and route tasks to the cheapest capable model. OpenAI takes the opposite approach when scaling to 1.2 billion users.

As Sottiaux explains, raw execution is only half the workload: “We are spending more and more compute on secondary monitoring. You have all the compute going to the primary system, the agent doing work. And then you have all the compute going into monitoring the primary agent to make sure that it's not taking too high risk of actions, or interrupting it if anything looks like it's getting prompt injected.”

When agents transition from text output to live actions, deterministic safety checks fail. Malicious data inside a web page or database can hijack the agent mid-task. Running a secondary, sandboxed model alongside the primary agent creates an active supervision layer. One model acts; the other model critiques every API call and state change before execution.

“The majority of our investment on the API stack is actually going into the safety stack,” Sottiaux notes. “To me, that is pacing. You want to make sure that you are extremely hardened.”

Why Holding Back Models Is a Competitive Edge

Frontier pacing requires holding back capabilities until the guardrails catch up. The pressure to ship raw model intelligence often leads teams to skip strict release gates. Sottiaux points to internal discipline around withheld releases as a key metric of success.

“It was in the news that we had six one Astra and then we didn't release it,” Sottiaux shares. “That is something I am very proud of.”

When safety guardrails work, agents gain real-world situational awareness without catastrophic failure modes. Right before taking the stage at DevDay, Sottiaux experienced this firsthand. "My Dot realized that ChatGPT production went down, so it pinged me five minutes before the live demo."

The goal of pacing is not slowing down progress. It is ensuring that when an agent acts autonomously on production systems, it operates inside verified boundaries. If your agent infrastructure lacks a dedicated monitoring stack, you are trusting raw model completions with your production database.

What to Do With This

Audit your production agent pipeline tomorrow morning. Split your agent telemetry into two distinct budgets: primary execution and secondary verification. If 100% of your token spend goes to the worker model executing the task, introduce a lightweight classification call that inspects tool inputs and scraped data for prompt injections before the worker acts.