Isolio

Blog /

The Bill You Don't See Coming: Cost Governance and Access Limits for AI Agents

Spending ceilings, hard stops and tightly scoped access are the third question most businesses adopting AI still aren't asking. Why an agent's permissions should be stricter than an employee's, not looser.

Isolio

Governance

Published 2 September 2026

If the first two questions a business has to answer about AI are "what's the return?" and "what will this actually cost?", the third, according to IT consultant Akos Voros, is the one most companies still aren't asking: how do we keep this from spiralling out of control?

In a conversation with Tamas Feher on Isolio's podcast, Voros laid out a case for treating AI cost governance and access control with the same seriousness businesses eventually applied to mobile data plans and cloud infrastructure, ideally before, rather than after, the first painful bill arrives.

This is the third article in a series drawn from that conversation. The first argued for starting from a measurable business benefit. The second explained why today's AI pricing is a temporary phase.

We've seen this film before

Voros's starting point is a bit of institutional memory. Twenty-odd years ago, mobile data started out sold in fixed packages, and going over that package could produce a genuinely nasty surprise on the next bill. The market's answer was to build usage-tracking tools that let people see their own consumption in real time and get ahead of it, well before carriers themselves built that visibility into the product.

He thinks AI spending is about to go through the identical cycle, and businesses don't have to wait passively for the industry to solve it for them. The fix is to design usage limits, budget ceilings and automated alerts into an AI system from the very beginning, not bolt them on after the first oversized invoice shows up.

He raises a second, sharper version of the same risk: cloud security incidents. There are well-documented cases of attackers breaching a company's cloud environment over a weekend, running cryptocurrency mining operations on the compromised infrastructure and disappearing, leaving the business with a bill in the hundreds of thousands for compute it never intended to use.

An AI agent system with generous, unmonitored access to compute and to paid model calls is exposed to a close cousin of that same risk, he argues, whether from a malicious actor or simply a bug: something that causes an agent to loop endlessly on a runaway task, silently chewing through months of budgeted usage in a matter of hours. He doesn't dismiss this as science fiction. He says plainly that "people have done this too", meaning the damage doesn't require malice, just an unsupervised process and no circuit breaker.

Build the limit in, don't hope for the best

The remedy, in Voros's telling, isn't exotic. If a given account or server exceeds a defined threshold, the system should stop itself, automatically, before the cost compounds further.

That single design habit, hard limits paired with alerts, converts a worst-case scenario, a five- or six-figure surprise invoice, into a manageable, contained one: a triggered alert and a quick manual review. He's careful to note this won't happen often; a well-run system with these guardrails rarely trips them. But the entire point of the safeguard is that when something unexpected does happen, whether it's a malicious intrusion or an honest human error, the damage is capped rather than open-ended.

Tamas adds that this connects directly to the broader question of guardrails, since an ungoverned agent can generate real financial or reputational damage well beyond just running up a token bill.

Agents need job descriptions too, and stricter ones

The conversation's most pointed idea might be this: businesses already know, at least in principle, how to manage risk from human employees. Every employee has a defined role, and within that role, defined access: specific systems, specific permissions, nothing more than the job requires.

Voros argues AI agents need exactly the same treatment, drawing a direct line back to the digital employee framing from earlier in the conversation. An agent should have a job description. It should have access scoped precisely to what that job requires and, he insists, that scoping should arguably be even stricter than what's granted to a human employee.

His reasoning is worth sitting with. An AI agent isn't a "reliable, good character" in any meaningful sense, because it has no character at all. It's a statistical model, doing its best to guess a plausible next output based on patterns in its training and instructions.

A human employee who technically has access to sensitive information, like colleagues' salaries, can generally be trusted to exercise judgment about when sharing that information would be inappropriate, because that judgment is precisely what a person brings to a role. An AI agent has no equivalent judgment to fall back on if it's asked the wrong question by the wrong person. It might simply produce the requested answer, because producing plausible answers to prompts is fundamentally what it does.

Voros makes the point with a simple example: he doesn't know what his colleagues earn, and one reason is simply that he doesn't have access to that data. His argument is that the same design principle, access as a limiting factor rather than trust as a limiting factor, matters more for an AI agent than it does for a person, not less.

The paperwork nobody's excited about: licences

Both participants note a less glamorous consequence of this same shift: licence management. As companies add more AI subscriptions, more agent platforms and more model providers, someone has to be able to answer basic questions. What are we actually subscribed to, why, and what does it cost us?

Voros frames this as an inevitable, almost boring maturation step, the point where what he calls the current "happy, hippie peacetime" of AI adoption gives way to ordinary business rationality. He's confident this transition isn't optional or avoidable. AI companies and the investors behind them are not going to subsidise usage indefinitely; monetisation is coming, in his view, quite quickly, and businesses that haven't already built the internal tracking to know what they're paying for and why will be the ones caught flat-footed. He compares the current phase to gambling: the players who understand the odds least are usually the ones from whom money gets extracted fastest.

Cost data is also management data

There's a more constructive angle buried in this same discipline. Once a business has a working cost-monitoring system for its AI usage, it isn't just a defensive tool; it becomes a genuinely useful management signal.

If a company can see which client, which product line or which division is generating the most agent activity, the most flagged errors or the most escalations to human review, that pattern is worth investigating on its own terms. High usage or high error rates in a specific area might simply reflect volume, but they might also be pointing at a deeper organisational issue, in much the same way that unusually high staff turnover in one part of a business is itself a signal worth digging into, not just an operating cost to absorb.

Voros frames this as an extension of ordinary sales-operations thinking into a new data source that most companies don't have yet: which relationships or processes are quietly expensive, and why.

This is organisational work, not just an IT project

Both participants return, near the end of the conversation, to a broader point. This transformation isn't purely a technology rollout that sits inside the IT department. It touches how work itself gets organised, how roles are defined, and how organisational development teams think about structure and change.

Voros half-jokingly suggests that a lot of organisational development consultancies haven't yet grappled with the fact that digital employee job descriptions are going to become a real category they'll need fluency in, alongside the more familiar work of managing human teams through change. He describes the broader shift as inevitable and, in the long run, healthy, comparing an organisation mid-transformation to a turtle that's been flipped onto its back: it looks stuck and chaotic for a while, but it eventually rights itself and moves in a genuinely different way afterwards, in every part of the business, not just the parts that touch AI directly.

The episode closes on the same note it opened with: this outcome isn't predetermined to be good or bad. Both agree that the deciding factor won't be the technology itself; it will be the deliberateness of the choices companies make around it, spending limits, access scopes and honest cost accounting included, well before those choices are forced on them by a bill, a breach or a headline they'd rather have avoided.


This article is drawn from a conversation on Isolio's podcast between Tamas Feher (Isolio) and Akos Voros, an IT consultant whose career spans IBM and ELTE's Applied AI Center.

Related articles

Ready to embed AI inside your product?

Book a Call