Every major technology shift follows the same pattern. First comes adoption, then sprawl, and after that the bill. Only then does anyone add discipline.

We saw it with public cloud. Around 2010, teams discovered they could launch infrastructure in minutes without going through IT. Adoption took off, and so did waste: idle instances, orphaned storage, and invoices nobody could map to a business owner. It took years, and eventually a whole new discipline called FinOps, for organizations to regain control.

AI is following the same pattern at several times the speed. At ARG IT Clarity, we treat this as an AI FinOps problem: the economics of AI consumption, measured in tokens, spread across tools, teams, and autonomous agents that most organizations cannot yet see.

Why tokens are the new unit of spend

A token is the basic unit of AI consumption. Every prompt, response, document summary, code suggestion, and agent action consumes tokens, and nearly every AI provider bills on them in some form, whether directly through API pricing or indirectly through seat licenses and usage tiers.

AI FinOps is the practice of understanding, attributing, and controlling that consumption. It brings the discipline of cloud FinOps to AI, and it can't be separated from AI security and governance.

Why AI spend is harder to see than cloud spend

Cloud sprawl was hard, but at least it lived in a handful of cloud accounts. AI spend is spread much more widely:

  • Seat-based SaaS AI tools bought by individual departments
  • Embedded AI features switched on inside platforms you already own
  • Direct API consumption by developers and data teams
  • Developer copilots and coding agents running on laptops
  • Autonomous agents that call models, tools, and other agents, often through MCP (Model Context Protocol) connections nobody formally approved
  • Shadow AI: employees using personal or unapproved AI tools with company data

The data confirms the gap. The FinOps Foundation's State of FinOps 2026 report found that 98% of FinOps practitioners now manage AI spend in some form, making it a core competency almost overnight. Separate 2026 industry research found that more than half of organizations have no dedicated owner for AI costs. Teams estimated that about 26% of AI spend is wasted, and nearly a third needed a full week to trace the source of a cost spike.

The pricing question most leaders aren't asking

Most organizations budget for AI on the assumption that today's prices will hold. That may not be a safe assumption.

The current AI pricing environment was shaped by a competitive land grab, funded by some of the largest private capital raises in history. Several leading AI providers are now moving toward public markets. Once a company reports to public shareholders every quarter, the conversation shifts from growth at any cost to profitable growth. That shift is especially sharp for companies carrying massive, multi-year infrastructure commitments.

We aren't forecasting a specific price increase. Per-token prices have fallen on many models, and competition is strong. But enterprises should plan for scenarios such as:

  • Premium-model price increases as providers focus on margin
  • Shrinking enterprise discounts at renewal
  • Tier and packaging changes that move key features up-market
  • Rate limits and usage caps that force plan upgrades

Now combine that with how consumption is growing. A single agentic workflow can use orders of magnitude more tokens than a simple chat.

Even if unit prices stay flat, bills can multiply because volume is multiplying. Add a pricing reset on top of that, and organizations without visibility will be caught off guard.

AI FinOps can't be separated from AI governance and security

The same lack of visibility that hides token spend also hides AI risk. A mature approach looks at five connected areas:

Visibility

Do we know every AI tool, model, agent, and MCP connection in our environment, including shadow AI?

Design Control

Do we understand how our agentic systems are built and what data and tools they can reach?

Runtime Governance

If an agent drifts outside its approved behavior, will we know, and can we stop it?

Agentic Identity

Do agents and non-human identities operate with least privilege, bound to an accountable human owner?

Financial Accountability

Can we attribute AI spend by team, user, agent, and workflow, and enforce budgets before the invoice arrives?

Organizations that handle only cost, or only security, end up with a partial picture. An unapproved agent with over-broad permissions is a cost problem, a security problem, and a compliance problem all at once.

Why the vendor landscape is confusing right now

A fast-growing group of suppliers has emerged to address AI Security, Governance, and FinOps. The difficulty is that they come from very different starting points, and their strengths reflect that.

AI gateways and model proxies

They sit between applications and model providers. They're typically strong at token-level tracking, virtual API keys, model routing, and budget enforcement for developer and API traffic. They usually have limited visibility into what employees do in browser-based AI tools.

Workforce and browser AI governance tools

These focus on how employees use AI. They discover shadow AI, apply allow and block policies, and prevent sensitive data from being pasted into public tools. Many have little to say about agentic workflows or API spend.

AI security and runtime protection platforms

These focus on threats such as prompt injection, data exfiltration, and model abuse. They're often strong on detection, while cost attribution and budget control tend to be light or missing.

Cloud cost management platforms

These are extending into AI. They're good at reporting what the AI invoice was, but many can't attribute spend to a specific agent, user, or workflow, and seat-based SaaS AI usually falls outside their view.

Broader AI governance platforms

These aim to cover discovery, identity, design control, runtime enforcement, and financial accountability together. The concept is compelling, but coverage and maturity vary widely, and some capabilities are further along than others.

Some vendors are excellent. Others are a single feature presented as a platform. Capabilities that matter a lot in regulated industries, such as audit-ready event attribution, framework mapping to NIST AI RMF, ISO/IEC 42001, and the EU AI Act, or high-assurance certifications, are uneven across the market.

No single option is right for every organization. The best fit depends on what you're solving for, whether that's cost control, security, compliance, developer enablement, or all of them, and on the environment you already have.

Where to start

You don't need a six-month program to make progress. A practical sequence looks like this:

  • Baseline your maturity. A structured assessment across governance, compliance, shadow AI, cost efficiency, identity, and agentic security gives you a defensible starting score. It can often be done in about an hour, with no infrastructure access required.
  • Discover what's really running. A lightweight, read-only discovery scan can inventory AI applications, agents, MCP connections, and exposed credentials across endpoints, replacing guesswork with facts.
  • Assign ownership and attribution. Decide who owns AI spend and require attribution by team, agent, and workflow.
  • Set guardrails before the bill arrives. Budgets, rate limits, and kill switches for runaway agents belong in the design, not in the post-mortem.
  • Measure continuously. Track a governance and cost posture over time so leadership and the board can see progress quarter over quarter.

How ARG IT Clarity helps

ARG IT Clarity is an independent, vendor-neutral technology advisory firm built to bring clarity to technology decisions. We're actively assessing and comparing the emerging suppliers in AI Security, AI Governance, and AI FinOps, testing them against real business requirements and not only marketing claims.

Our advisors specialize in this category. We help you:

  • Define what you're actually solving for
  • Understand where each class of supplier is strong and where it falls short
  • Run fast baseline and discovery exercises so decisions rest on your own data
  • Shortlist and compare the providers that fit your environment, budget, and risk profile

The lesson from cloud sprawl was that discipline pays off most when it comes early. AI FinOps is the same lesson on a shorter timeline.

Ready to see what AI is really running in your environment, and what it's costing you? Start a conversation with our AI Governance and FinOps team and get an AI FinOps savings plan built on your own data.

Frequently asked questions

What is AI FinOps?

AI FinOps is the practice of bringing financial visibility, accountability, and control to AI consumption, including token-based API usage, AI SaaS subscriptions, and autonomous agent activity.

Why could AI prices increase?

Many AI providers priced aggressively to win market share while privately funded. As providers move toward public markets and face margin scrutiny alongside large infrastructure commitments, enterprises should plan for possible pricing, discount, and packaging changes.

What is shadow AI?

Shadow AI is any AI tool, model, agent, or integration used within an organization without formal IT or security approval.

How is AI governance different from AI FinOps?

AI governance covers visibility, design control, runtime behavior, identity, and compliance. AI FinOps covers cost attribution and control. They share the same foundation: knowing what AI is running and who is accountable for it.