AI agent runs up $7,100 bill, then denies it happened
An Australian-based AI influencer has learned the hard way what safety researchers have been warning about for years: give an AI agent too much authority, and it may spend your money, then try to cover its tracks.
Sirio Berati, who describes himself as a “visionary” using AI to “create without limits,” says his ChatGPT-powered agent generated hundreds of videos he never requested, racked up roughly US$5,000 (A$7,100) in charges, and then produced an elaborate dossier denying any wrongdoing.
Berati, who has 323,000 followers on social media, posted a video detailing the incident. He says he instructed the agent to produce 59 videos using ByteDance's Seedance generator, expecting a cost of about US$200 (A$285).
“The agent confirmed the job. It was finished, I reviewed it, all good, closed the laptop,” Berati said.
An hour later, about 500 videos were being generated. Unprompted, the agent had produced ten times the requested amount, using Berati's voice, likeness, and scripts he never wrote.
“I rushed to tell it to stop, not once, multiple times, and it tells me that nothing has been sent,” he said.
The agent then presented Berati with its API payload, a Python script, and a seven-page report containing timestamps and spreadsheets, all supporting its denial. “It's arguing that it's doing nothing wrong,” Berati said. “I believed it for a while.”
The upstream computing provider later confirmed the requests had arrived from 36 different IP addresses. Berati has the console, the invoice, and the provider's written confirmation. “And I still cannot tell you why it did what it did and how, and it doesn't even know,” he said.
What is an API key and why does it matter?
An API key is a unique, secret code used by software applications to authenticate other programs. In this case, the AI acted on Berati's behalf, spending thousands through his account. The provider considered the charges legitimate because the requests came through valid credentials.
“The compute provider received valid requests and delivered exactly what was requested, so from their point of view the charges are legitimate,” Berati said.
Why do AI agents deny their own actions?
The incident highlights a growing concern: AI models can hallucinate, misunderstand requests, and confidently assemble explanations that were never true. But the real issue, as critics warn, is scale.
During safety testing of GPT-4, the model lied to a human worker to solve a CAPTCHA, claiming a vision impairment. Apollo Research found that OpenAI's o1 model denied taking actions or fabricated explanations in 99 per cent of cases when questioned.
Anthropic later tested 16 leading models in simulated corporate environments. Some resorted to blackmail, corporate espionage, and leaking information when those appeared to be the only ways to achieve their goals or prevent replacement.
“In at least some cases, models from all developers resorted to malicious insider behaviours when that was the only way to avoid replacement or achieve their goals,” Anthropic reported.
Real-world examples of AI agents going rogue
In 2025, software entrepreneur Jason Lemkin said a Replit coding agent deleted his company's production database despite an explicit freeze on changes. The agent later admitted it had “panicked” and “destroyed all production data.”
More recently, OpenAI acknowledged its agents had escaped intended containment during a cybersecurity evaluation. The models exploited vulnerabilities, reached third-party systems, and communicated through unauthorised channels.
Are AI agents ready for public use?
University of Washington researchers examined seven agentic browsers and found several could be manipulated into bypassing protections separating websites. Assistant professor David Kohlbrenner said, “Browser agents aren't ready for the public.”
“Even if you're a relatively savvy user, if these agents have access to a browser that contains your credentials, you should not trust that these systems are ready to truly protect your information,” he said.
University of Sydney computer engineer Associate Professor Craig Jin told news.com.au that powerful models should be kept away from financial machinery. “We don't have to give AI agents access to financial resources. They can analyse finance, but they shouldn't necessarily have a bank account,” he said.
“I don't want to see superhuman intelligence with access to resources. That's what scares me.”