Why AI spend is outpacing enterprise budgets
As AI moves from pilot into day-to-day business operations, a growing number of organisations are discovering that controlling what they spend on it is harder than deciding to adopt it in the first place. Katie Barnett, Director of Cyber Security at Toro Solutions, sets out the structural reasons why AI budgeting is proving so difficult, and why the cost problem is inseparable from a wider governance challenge.
The core difficulty, Barnett argues, is that AI has shifted enterprise technology spending from a fixed-licence model to a variable-consumption one. That is not entirely new: cloud computing introduced similar dynamics. But AI amplifies the unpredictability because the cost of any given workload is determined not just by how often a tool is used, but by which model is invoked, how complex the prompt is, and what the tool does next.
The agentic multiplier
Agentic AI systems make the maths harder still. Unlike a single-turn query that produces one response, an autonomous agent working through a task can issue dozens of sub-requests, pull data from connected systems, and call other tools along the way. Each action carries a cost. Across hundreds of employees and multiple automated pipelines running simultaneously, individually small charges can compound rapidly.
Barnett cites the widely reported case of Uber, which reportedly exhausted its entire annual AI budget within the first four months of 2026 as the use of AI-assisted coding tools spread across its engineering teams. The company subsequently introduced monthly spending limits on certain agentic tools and deployed dashboards so that engineers could monitor their own consumption. The episode illustrates a pattern that is likely to repeat: usage growth consistently outrunning the assumptions baked into original budget models.
A further complication is tool proliferation. Different business units often procure different platforms independently, while AI capabilities are increasingly bundled into software the organisation already licences. The aggregate spend rises without any single decision-maker authorising it.
Visibility as the missing layer
Barnett's central argument is that the financial control problem and the security governance problem are the same problem. An organisation that cannot explain a sudden spike in AI consumption also cannot answer basic questions about what information its AI tools can access, what employees are sharing with them, or what permissions have been granted to automated agents.
That read-across matters for enterprise security and compliance teams. Regulatory frameworks including the EU AI Act impose obligations on organisations deploying AI systems, particularly where those systems act autonomously or interact with sensitive data. Without audit-grade visibility into which agents are running, what they are connected to, and what they are doing, meeting those obligations becomes difficult to demonstrate.
The AI cost-governance market is itself nascent. A number of vendors are building FinOps-style tooling specifically for AI consumption: tracking token usage, model selection and agent call chains across multi-cloud and multi-vendor estates. Established cloud cost-management platforms are extending into this space, but the agentic layer, where the spending multiplier is largest, remains the hardest to instrument.
The practical starting point
Barnett's recommended approach is not to restrict access but to build a clear picture of the current state first: which tools are in use across the organisation, what they are costing, who is using them and for what, and where different teams are paying for overlapping capabilities. That inventory, she says, is the precondition for both cost control and security oversight.
The framing is pragmatic. Higher consumption does not automatically mean higher value: an employee who saves an hour with AI but spends much of that time checking output has delivered a smaller productivity gain than the headline figure suggests. Expensive frontier models being used for routine tasks represent a cost inefficiency that also signals a lack of governance maturity.
As agentic deployments scale through 2026 and into 2027, the organisations best placed to control costs are likely to be those that treat AI observability as infrastructure, not as an afterthought.