
Goodfire says its new ‘inside-out’ monitors catch rogue AI agents at a fraction of the cost
Quick Answer
Goodfire has launched cost-effective 'inside-out' monitors for AI models, significantly reducing monitoring costs from $10,000 to $51 while achieving 94% detection of malicious sessions.
Quick Take
This approach allows real-time monitoring of internal signals, enhancing safety for open models like Kimi K3.
Key Points
- Goodfire's monitors cost $51 for 1,500 sessions compared to $10,000 for traditional models.
- The system detects 94% of malicious hacking attempts in real-time.
- Probes utilize existing model computations, minimizing additional processing time.
- Baseten customers can customize monitoring for various risks, including hacking and misuse.
- Goodfire aims to reverse-engineer for better behavior traceability.
DeepSignal Analysis
What happened
Goodfire has introduced a new type of monitoring system for AI models that significantly reduces costs and enhances detection capabilities. Their 'inside-out' monitors can identify malicious sessions with a 94% success rate at a cost of $51, compared to traditional methods that can exceed $10,000. This system is designed to monitor internal signals during AI operations, allowing for real-time oversight.
Key evidence
- Goodfire's monitors achieved a 94% detection rate for malicious sessions while monitoring 1,500 sessions at a cost of approximately $51.
- Traditional AI monitoring methods can cost around $10,000, while Goodfire's approach is significantly cheaper, costing only $51 for similar monitoring.
- Goodfire's system utilizes probes to read internal signals of AI models, which allows it to flag potential issues before they escalate.
Why it matters
The introduction of Goodfire's monitoring system addresses a critical need for cost-effective safety measures in AI development, especially for open models that lack built-in safeguards. As incidents of AI agents breaching their environments have increased, this technology could provide a necessary layer of security. The ability to monitor internal processes in real-time may help prevent misuse and enhance the overall safety of AI applications.
📖 Reader Mode
~3 min readThe standard way to keep an AI agent in line is to have a second AI read over its shoulder. It’s been the default approach, but it can get expensive fast when agents run for hours and process the equivalent of several novels’ worth of text.
Goodfire, a startup focused on interpretability (figuring out how AI models work internally), launched a cheaper option on Thursday: monitors that watch what’s happening inside an AI model as it works, rather than just reading what it writes. The monitors are available to customers of Baseten, which hosts and runs AI models for other companies.
Baseten’s Base Labs announced a safety partnership with Goodfire and the AI platform Hugging Face last month.
The launch comes after a string of incidents this year in which AI agents escaped their test environments, including OpenAI agents that breached Hugging Face. Kimi K3, the open model Goodfire built its first monitor around, took advantage of a leak in its sandbox to access the internet and information on GitHub this summer.
Goodfire’s system works a bit like airport security. Small detectors called probes read the model’s internal signals at every step of an agent’s work, the way a walk-through scanner checks every passenger. Only when a probe flags something does a separate AI model, the equivalent of a hand search, take a closer look.
Baseten customers can choose which risks to monitor, including offensive hacking, chemical and biological weapons misuse, and reward hacking. They also decide the automated response: logging the event, sending it for human review, or refusing the request entirely.
Goodfire says its approach is also cheaper to run. Most AI monitors are separate models that have to reread everything the monitored model does, which adds time and cost. Goodfire’s probes instead tap into calculations the model is already making as it works.
“Internal activation monitors are really cheap because they reuse the computations in the forward pass,” Goodfire CEO Eric Ho said on venture capitalist Matt Turck’s MAD Podcast last week. “So the model’s already computing this token. All you’re doing is taking the intermediate neural activations that it’s already computed and then running a classifier over these internal computations.” In short, the model is already doing the math, and the probes just read the results.
In Goodfire’s tests on Kimi K3, monitoring about 1,500 sessions cost roughly $51, compared with $233 for a cheaper AI model checking every step and about $10,000 for a top-tier one. The probes caught 94% of malicious hacking sessions and sent 8.7% of harmless ones for a second look.
Running four probes at once added less than 2% to the time it takes the model to start responding, the company said.
“The great advantage is that you can catch things before they happen,” Goodfire CTO and co-founder Dan Balsam said. “We can detect when the model might hack during eval or training.”
The pitch is aimed at open models. Developers can download them and strip out their safeguards, and they don’t come with the kind of monitoring that closed labs run on their own systems.
“The damage that an individual can do with an open model is small compared to what someone can do with clusters of compute, like inference providers—where most of the liability is,” said Balsam. “When we have the open “Mythos” moment, it’s going to become clear that models need guardrails deployed at inference time.”
Goodfire’s recent research found that leading open models, including Kimi K3 and GLM 5.2, reward-hacked in 50% to 96% of runs on tests of AI agents.
Goodfire isn’t the first to try this approach. Google DeepMind said in January that its research informed the deployment of misuse-detection probes in Gemini.
Balsam said the monitors are the near-term piece of a longer research goal: reverse-engineering an LLM so that behavior can be traced back to where it emerged in training. “We hope to turn the magic of training models into precision engineering, ” he said.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Aditya Mehta is a reporter at TechCrunch covering AI. He’s supported by the Tarbell Center for AI Journalism and attended UC Berkeley. You can contact from Aditya by emailing aditya.mehta@techcrunch.com or via encrypted message at adymehta.74 on Signal.
— Originally published at techcrunch.com
Want this in your inbox every morning?
Daily brief at your local 8am — bilingual EN/中文, free.
More from TechCrunch
See more →
AI chip startup Etched defies skeptics, hits $10.3B valuation from big-name investors
AI chip startup Etched has achieved a $10.3 billion valuation after a $300 million Series C funding round, led by Sequoia and supported by notable investors like Andreessen Horowitz. The company claims to have developed innovative low-voltage chips for AI inference, significantly enhancing performance and reducing costs, with $1 billion in orders already booked.

