AI cost governance in a nutshell
The AI cost panic is loud, but it’s a symptom. The real problem is that we’ve built a generation of autonomous spenders and haven’t decided who governs the identities and contracts they spend against. The meter sees the pool. It can’t see the person — or the permission. Closing that gap isn’t the brake that slows your AI program down. It’s the one that lets you go fast.
Most days, the mail is just mail. Bills. Flyers. Something addressed to “Resident.” You flip through it on autopilot. But every once in a while, there it is — a red light camera ticket. And my heart sinks.
It’s our car, no question. Right there in the envelope, a color photo of it running the light. And it’s one of us — me or my wife. If the picture doesn’t settle it, you log in and watch the whole video, squinting to make out who was behind the wheel.
Fast forward a couple years. Both my teenage sons are driving now. The ticket still comes, it’s still our car — but now it could be any of four of us. My first instinct is to tell myself it’s a one-in-four chance it was me. Twenty-five percent. Split it evenly.
But I know that’s a lie. Some of us drive more. Some of us drive worse. The flat math is the story I tell myself so I don’t have to find out the real one.
That’s where companies are with AI right now, except worse. With the camera, at least there’s a photo to squint at. When the AI bill arrives, the meter doesn’t even give you a face. One employee can run a dozen agents against a shared pool of credits — no envelope, no plate, no video — and no way to trace a single charge back to the person who caused it. Let alone whether they were allowed to.
The AI cost governance reckoning is just starting
Per-seat licensing breaks when one agent does the work of five employees, and investors noticed.
Speaking at a conference in Berlin, Thoma Bravo’s Orlando Bravo said the “SaaSpocalypse” is over and called AI an enormous tailwind for software. He’s right that the panic phase is ending. But read what he said next: the open questions now are governance, cybersecurity, and returns. He called it a period of discovery that puts pressure on the whole system.
That’s the part almost no one is ready for. The crash was loud and fast. The AI cost governance reckoning will be quiet, expensive, and slow — and it lands on whoever can answer one question the loud phase never did: who spent this, and were they entitled to?
The flat math of AI cost allocation is a lie
Watch where the whole market is running, because it’s all running to the same place. Major firms publish multi-layer frameworks for the total cost of an agent. A new standards body forms. Most of the cost-management and observability field bolts on meters for tokens, PI calls, and GPU time. Every one of them lands on the same plane: measure what was spent. The cost-management and observability field is real, and it’s getting better — it traces what agents do, debugs them, meters tokens, calls, and GPU time. But almost all of it lands on the same plane: it measures the work and the spend. It still can’t tell you which governed identity to attribute the draw to, or whether the contract you hold ever covered it.
Measuring spend is necessary. It’s also becoming the easy part. And it tempts you toward the twenty-five-percent answer — divide the pool by headcount and call it allocation.
Consumption isn’t uniform, and the data proves it. Recent analysis from EY suggests the cost of an AI interaction can be around 30× higher than it was two years ago—not because tokens have become more expensive (they’ve become cheaper), but because many enterprise AI interactions have evolved from a single prompt into multi-step agentic workflows involving multiple model calls, tools and reasoning. A small number of workflows drive a wildly disproportionate share of the bill. Splitting costs evenly isn’t fair. It’s fiction.
The meter shows you the pool. It cannot show you the distribution. That’s where every current tool stops.
The AI cost attribution gap
This is the identity gap, and it’s the red light camera all over again. The meter records that the pool drained. It can’t tell you which human was behind the wheel.
I named this Shadow SaaS 2.0 earlier this year. The agent doesn’t log in. It runs on a personal API key, a developer’s credit card, a CI/CD pipeline, a cloud function. Your SaaS management tools were built around identity and login events. The new unit generates neither. One person, many agents, one shared bucket — and nothing reconciles that consumption back to a single governed human identity.
This isn’t hypothetical. Across conversations with large enterprise customers, the same structure keeps surfacing: AI billed against a shared organizational token pool, with no attribution back to the individual user, and credits that quietly bleed across departments when one runs dry. The spend is real. The trail to a person was never built.
The question underneath: were they even entitled to?
Identity is the gap people can see. Entitlement is the one underneath it, and it’s the one nobody has claimed.
Knowing who spent is only half the answer. The other half is whether the license or contract that person holds ever covered the work the agent just did. I’ve called this discipline contract-to-inference rationalization — matching each inference back to the model, the meter, and the contract you actually have in your repository. Not a rate card. Not a vendor deck. The contract sitting in your environment today.
There’s a lot of talk right now about who owns the single source of truth for a business domain, and how data gravity decides the AI future. That’s real. But data gravity decides what an agent can reason against. It says nothing about what the agent was authorized to spend, or whether the human behind it was entitled to the work. That’s a different source of truth — the contract — and it governs cost and authorization, not data. It’s still wide open.
ServiceNow calls itself the control tower, and it’s a real one — it finds every agent, watches it, can even shut it down. What it still doesn’t do is reconcile that spend against the contract you signed: whether the entitlement you hold ever covered the work the agent did.
You’re paying for SaaS licenses for work that’s already gone
There’s a second cost to ignoring entitlement, and it runs the other direction.
As agents absorb work people used to do, the licenses that work once justified don’t light up for review. The seat an agent has effectively replaced keeps renewing. A premium tier bought for a task now handled by inference keeps billing. Microsoft reportedly revoked its developers’ access to one AI coding tool after the bill outran what its own staff cost. Uber reportedly burned its entire 2026 AI coding budget in four months — its CTO said the budget he thought he’d need was blown away already.
It’s paying for a parking spot after you’ve sold the car. The work is gone; the entitlement is still auto-renewing, because nothing connected the two. The gap between when an agent absorbs the work and when you reclaim the entitlement is real money, sitting unrecovered, on the far side of the same blind spot.
We’ve built this discipline before: from FinOps to SaaS management to AI cost governance
None of this is rocket science, and none of it is new. Every time the unit of work moved, we built the discipline to govern it. The shift to cloud gave us FinOps. The rise of SaaS gave us SaaS management. Each one borrowed from what came before and added what the new model demanded. AI is the next turn — new disciplines, yes, but built on the same decades-old muscle: knowing what you bought, who’s using it, and whether the contract covers it. Reconciling usage back to an entitlement isn’t a problem no one has solved. People have done it for thirty years. The only open question is who extends it to agents first.
What real AI governance protects
Here’s the part most leaders have backwards.
Governance sounds like the thing that slows your AI program down — another control, another gate, another reason to wait. So teams skip it to move fast. Then the bill arrives, nobody can explain it, and they slam on the brakes the hard way: freeze spend, pull licenses, cancel projects. That’s not speed. That’s a crash followed by a crawl.
But think about what brakes are actually for. A race car doesn’t have powerful brakes so it can go slow. It has them so it can go fast — into the corner, late, with confidence, because the driver knows the car can stop. Take the brakes away and you don’t go faster. You go slower, because now every corner is terrifying.
Reconciling consumption back to a governed identity, under the contract held, is the brake system for AI spend. It’s not the tax on going fast. It’s the thing that lets people run agents hard — because you can finally see who’s driving, what it costs, and whether it was allowed. The companies that win the next 18 months won’t be the ones watching the meter most closely. They’ll be the ones who can floor it without flying blind.
Where to start: three AI cost governance steps for this quarter
You don’t need a finished answer to start closing the gap. You need three things in motion this quarter.
- Find the contracts with consumption clauses. Inventory which of your SaaS and AI agreements already bill on tokens, credits, or calls — and who, if anyone, is tracking them. You can’t reconcile to a contract you haven’t read.
- Tie agents to humans at registration. Require an owner for every agent the moment it’s created, so consumption has a person attached before the bill does, not after.
- Name the owner of the whole question. Decide who governs AI agent cost and entitlement across the org — because in most companies the honest answer today is no one, and that vacuum is exactly what the spend is exploiting.
What is AI cost governance?
AI cost governance is the discipline of tying AI and AI agent spend back to a specific, governed identity and confirming the license or contract in place actually covers the work performed. Standard AI cost management tools measure how much was spent on tokens, API calls and GPU time. AI cost governance goes a step further and answers who spent it and if they were entitled to.
Why can’t tools attribute AI spend to individual users?
Most AI cost tools meter consumption at the account or organization level, not the person. Agents don’t log in the way humans do. They run on shared token pools, personal API keys, CI/CD pipelines and cloud functions, so the bill shows a drained pool, not a driver. Closing that gap requires tying every agent to a governed human identity at registration.
What is shadow SaaS 2.0?
Shadow SaaS 2.0 is AI software and autonomous agents that bypass traditional SaaS governance by operating through APIs, automation and cloud infrastructure rather than authenticated user accounts, making them difficult for conventional SaaS discovery and management tools to detect.
Can AI agents replace SaaS licenses?
They already do, and the licenses rarely get the memo. As agents absorb work people used to do, the seats and premium tiers that work once justified keep auto-renewing. Reclaiming those entitlements requires connecting the moment an agent absorbs the work to the moment the license comes up for review.
What is AI entitlement management?
AI entitlement management, also called contract-to-inference rationalization, is the process of matching each AI inference back to the model, the meter and the actual contract an organization holds, rather than a rate card or vendor deck. It answers if the license a person or team holds ever covered the specific AI work an agent performed on their behalf.
How much has agentic AI increased enterprise costs?
Costs have jumped even as per-token pricing has fallen. One Ernst & Young analysis found the cost to deliver the same outcome rose roughly 30x in two years, largely because simple, single-step tasks turned into multi-step agent orchestrations under the same billing label. Real-world examples back this up: Uber reportedly burned its entire 2026 AI coding budget in four months, and Microsoft reportedly revoked developer access to one AI coding tool after the bill outran what its own staff cost.
Where should an organization start with AI cost governance?
Start with three things: inventory which SaaS and AI contracts already bill on tokens, credits or API calls; require a named human owner for every AI agent at the moment it’s registered, before it starts spending; and name a single owner accountable for AI agent cost and entitlement across the organization.