@ArneBab Yeah, anything that identified itself as GPTBot came from 4.227.0.0/16 for me too – but at least in my case, that was just a small fraction of the request spikes I saw.
Currently, I'm only outputting any agents/IPs that made at least 10 requests so I don't just get 100k lines of output for one incident, but even with that limited perspective, I can immediately see a cluster in 172.68.0.0/16, one in 172.71.0.0/16 and possibly another one in 217.113.0.0/16