AI spend follows an infrastructure cost model, not a software fee model.
AI spend follows an infrastructure cost model, not a software fee model.
Lack of visibility is the binding constraint for forecasting, governance and ROI.
AI consumption issues are often the root cause of security and financial governance problems.
Most organizations did not decide to spend heavily on artificial intelligence. They discovered they already were.
Enterprise AI spread through the fastest adoption curve in modern technology. It came not through a procurement cycle or a business case, but through bundled licenses, embedded copilots, developer tools and employee initiative. Somewhere in that rush, a distinction was lost. AI is not a software purchase. It is a metered utility, and every prompt, retrieval, reasoning step and agent call carries a variable cost that accrues whether or not it produces anything of value.
The result is now measurable. In May, Gartner forecast that worldwide AI spending will reach $2.59 trillion in 2026, a 47% year-over-year increase. Yet a February 2026 report from Sapio Research and DoiT found that 79% of enterprises reported AI cost overruns in the preceding 12 months, and only 15% could calculate AI return on investment without significant bottlenecks. AI adoption is nearly universal. Financial control over it is not.
In addition, 2025 research from the Massachusetts Institute of Technology’s Networked AI Agents in Decentralized Architecture (MIT NANDA) initiative found that 95% of enterprise generative AI pilots produced no measurable impact on the profit and loss (P&L) statement.
This is not a case against AI investment. It is a case for proper sequence. Organizations that established visibility and governance before scaling consumption are converting AI spend into compounding returns. Those that scaled first are finding that unmanaged consumption compounds, heightening security, compliance and executive credibility risks along with it.
Key insight: The question is no longer “What AI should we buy?” There are now three questions: “What are we already consuming? Who authorized it? What is it returning?” Most organizations today cannot answer any of them.
There is nothing irrational about how organizations got here. AI entered the enterprise through doors that governance does not usually watch, and each step along the way was reasonable.
| How AI entered | Why the control never engaged |
|---|---|
| Introduced as a feature, not a purchase | Copilots and assistants appeared inside tools already bought and approved, with no new vendor, review or budget line. |
| Measured by usage, not value | Early programs were scored on seats activated and prompts submitted. Both reward consumption. Neither measures outcome. |
| Priced in an unfamiliar unit | Finance teams that can model a server, a seat or a support ticket had no reference point for a token. In a June 2026 report, the FinOps Foundation named token cost management the hardest problem now facing its practitioners. |
| Bought below the approval threshold | The procurement gate that governs a $50,000 platform does not exist for a $50 API key that quietly becomes a $500,000 run rate. |
| Repriced after deployment | Providers are shifting from subscription to consumption models, creating the potential for material increases after deployment without changes to client code. |
The myth: “Our AI costs are a line item we can forecast from the pilot.”
The reality: A pilot measures feasibility, not consumption. Production AI scales with usage, and usage scales with tool quality. The more successful the deployment, the higher the bill—and the less accurately the pilot predicted it.
Three dynamics separate AI from every prior category of enterprise technology spend. Together they explain why budgets set in good faith are often exceeded by wide margins.
| Dynamic | What happens | Why the budget misses |
|---|---|---|
| Consumption scales with capability | Agents plan, call tools, retrieve context, verify output and repeat. Shifting tasks from an assistant to an agent increases tokens per task by one to two orders of magnitude (The Next Web, June 2026). | Agents make 3 to 10 times more model calls than chatbots, and actual output is often only 5%–15% of tokens consumed; the remaining tokens consist of context re-sent with each turn (The Next Web). |
| Prices fall, bills rise | Token prices have dropped roughly 98% since late 2022; inference now accounts for about 85% of AI spend (The Next Web). | Cheaper compute is consumed faster. This is the classic pattern of a utility whose price falls while total cost climbs. |
| Failure is billable | A recent catalog documented 63 confirmed production budget overrun incidents across 21 orchestration frameworks in an eight-cluster failure taxonomy (Sajjad Khan, “Token Budgets: An Empirical Catalog of 63 LLM-Agent Budget-Overrun Incidents,” June 2026). | Metric lag means an operator sees $50 on a dashboard while true spend has reached $400; one agent loop ran for 11 days and produced a $47,000 bill (Khan, “Token Budgets”; The Next Web). |
Instrumentation has not kept pace with budget challenges. In a February 2026 report, The FinOps Foundation found that 98% of FinOps practitioners now manage AI spend, up from 31% two years earlier, yet 53.4% still struggle to see that spend and 40.1% cannot quantify its value. Further, Flexera’s 2026 State of the Cloud Report found that cloud waste has climbed to 29% of infrastructure and platform budgets—the first increase in five years, driven by AI workloads that existing commitment frameworks were never designed to handle.
Key insight: Cost tells you what you spent. Unit economics tells you what you bought. Without a cost per resolved case, per document processed, or per engineering hour returned, an AI invoice is a number without a denominator. It cannot be defended or deliberately reduced.
Control gaps are rarely visible at the moment of AI adoption. They surface later as cost, exposure and failed expectations, and by then the symptom is usually blamed on AI itself. The chain is predictable:
Weak visibility → no attribution → no accountability → no forecast → budget surprise at the invoice stage
Weak governance → unsanctioned tools → ungoverned data flows → breach cost, denied coverage and regulatory exposure
The table below summarizes findings from multiple surveys, research reports and industry analyses that link specific AI control gaps to downstream business impacts.
| Control gap | Downstream symptom | Business cost |
|---|---|---|
| No consumption visibility | Spend discovered at invoicing, with no attribution by team or use case. | 79% overrun rate; mean overspend stood at about 31% at the most-instrumented firms (Sapio Research and DoiT, February 2026). |
| No unit economics | Usage reported as a success; value never proven. | 95% of generative AI pilots had no measurable P&L impact (MIT NANDA initiative, 2025). |
| No usage policy or access control | Sensitive data placed into consumer tools, creating shadow AI. | $670,000 average breach cost; 97% of breached firms lacked AI access controls (IBM, “Cost of a Data Breach Report 2025”). |
| No run-time guardrails | Agent runs trapped in retry loops, compromised by delegation leaks or left orphaned. | Documented single-incident losses reached five figures (Sajjad Khan, “Token Budgets: An Empirical Catalog of 63 LLM-Agent Budget-Overrun Incidents,” June 2026). |
| No ownership model | Accountability split between technology and finance. | 55%/53% split; functionally, no one owns cost reduction (Sapio Research and DoiT, February 2026). |
The security dimension is not a footnote to the cost problem. It is the same problem seen from a different seat. In a recent survey, the Cloud Security Alliance (CSA) AI Safety Initiative found that 8 in 10 employees use AI tools their organization had not approved; only 37% of enterprises have an AI governance policy; and an estimated 89% of enterprise AI usage is invisible to security teams. In addition, generative AI is now the single largest vector for corporate-to-personal data movement, accounting for 32% of such transfers.
IBM’s 2025 Cost of a Data Breach Report recognized shadow AI as a formal breach category for the first time: 1 in 5 organizations reported a breach involving unauthorized (shadow) use, at $670,000 in additional cost; 97% of those suffering an AI-related breach lacked proper AI access controls. However, the CSA survey results indicated that where sanctioned tools are provisioned, unauthorized use drops 89%. The remedy is access controls, not prohibition.
The consequences of a data breach now extend beyond the incident itself. Insurance carriers began attaching AI-specific conditions to cyber policies in 2026; based on cyber insurance market analysis, more than 40% of cyber claims are being denied, with 82% of denials tied to controls carriers assumed were in place at underwriting. Coverage increasingly depends on demonstrable AI inventories, access controls and enforced usage policy—evidence most organizations cannot yet produce. In parallel, the EU Artificial Intelligence Act entered broad application in August 2026, with penalties for prohibited practices reaching 35 million euros or 7% of global annual turnover. A June 2026 amendment deferred the heaviest high-risk obligations to December 2027, but an incomplete AI inventory is a compliance problem regardless of the timeline.
The pattern: Ungoverned AI surfaces not as a governance problem but as an invoice, an incident or a denied claim. Organizations then respond by restricting tools, which drives usage further underground and makes the next surprise costlier.
The pattern above is not anecdotal. It is consistent across every major body of research published in the last 18 months.
| What the research shows | What it means |
|---|---|
| AI spending was forecast to total $2.59 trillion worldwide in 2026, up 47% year over year (Gartner, May 2026), with enterprise commitment rising from 0.8% to 1.7% of revenue and 94% of investments failing to yield immediate returns (BCG, “AI Radar 2026”). | Investment is accelerating far faster than the governance and oversight needed to manage it. |
| 79% of companies reported AI cost overruns, rising to 89% of the most FinOps-mature organizations, with a mean overspend of 30.9% (Sapio Research and DoiT, February 2026). | Overruns are the norm. Mature firms detect what less-instrumented firms never measure. |
| 95% of pilots delivered no measurable P&L impact, and externally sourced solutions succeeded about 67% of the time versus about 33% for internal builds (MIT NANDA initiative, 2025). | The primary challenges are workflow integration and workforce training, not model quality. |
| 98% now manage AI spend, up from 31% in 2024, yet 53.4% cannot see it and 40.1% cannot quantify its value (FinOps Foundation, February 2026). | Visibility, not capability, is the acknowledged bottleneck across the discipline. |
| One Fortune 500 company exhausted its annual AI tools budget in four months, while another large company resumed hiring after AI-based workforce reductions led to a 22% decline in customer satisfaction (press reports of public enterprise reversals). | These high-profile policy reversals are now public, named and expensive to explain. |
Acting on the evidence above requires a framework simple enough to survive a board conversation. The model below defines four layers an organization must establish, in order, before AI consumption produces compounding returns. Each layer is a prerequisite for the next.
| Layer | What it requires | Readiness signal |
|---|---|---|
| 1. Visibility: See the consumption | Inventory every AI platform, model, agent and use case. Attribute spend to an owner, a business unit and a workload. Establish run rate and forecast. | Leadership can answer “What did AI cost us last week, and who spent it?” without waiting for an invoice. |
| 2. Governance: Own the decision | Assign accountability for AI spend. Define approval gates for new use cases and models. Enforce access control and data classification. Set guardrails, rate limits and hard budget ceilings. | Every AI workload has a named owner, an approved data boundary and a spend ceiling. |
| 3. Optimization: Engineer the value | Route workloads to the appropriate model tier, cache and compress context, rightsize agentic loops and manage commitments against forecast demand. | Cost per business outcome falls as usage rises. |
| 4. Sustain: Run with discipline | Measure outcomes, monitor spend, refine policies and continuously adjust models, workloads and governance as adoption grows. | AI spending grows predictably, ROI remains visible and optimization becomes a repeatable business process. |
The organizations converting AI spend into defensible returns are distinguished not by larger budgets or better models, but by thorough preparation and disciplined usage.
The bottom line: Average organizations ask, “How do we reduce our AI bill?” High-performing organizations ask, “What is a unit of AI value worth to us, and what should it cost to produce?” Those that will successfully defend their AI investment two years from now are establishing visibility and ownership today, while the spend is still small enough to shape.
As AI consumption grows more complex, understanding its economics becomes critical. RSM delivers an effective first step with a comprehensive AI economics assessment: a focused engagement to establish what AI your organization is consuming, what it costs, who owns it, where the security and compliance gaps lie, and what to address first. Leadership gets an evidence-based baseline before rather than after the next budget cycle.
In addition, the RSM team provides targeted solutions through every layer of the AI economics readiness model:
| Readiness layer | What RSM delivers |
|---|---|
| Visibility | AI footprint and consumption baseline: Inventory of platforms, models, agents and use cases; collection of billing and usage data; mapping of owners and decision rights; and design of reporting and showback based on existing data. |
| Governance | Secure AI adoption and governance: Enablement of Microsoft Copilot and comparable tools; integration of security-by-design controls for data protection; and development of policies, approval gates, an ownership model, training and a center of excellence structure. |
| Optimization | AI cost and value optimization: Total cost of ownership and value realization modeling; model selection and routing strategy; workload segmentation; and cost-per-outcome measurement aligned with chief financial officer and chief information officer decision-making needs. |
| Sustain | AI FinOps operating model: Budgets and approval workflows; tagging and showback logic; forecast cadence; policy guardrails; and integration with existing cloud FinOps targeted services. |
Let’s discuss how RSM can help your organization establish visibility and control over enterprise AI consumption.