Why Your AI Spending Needs the Same Authorization Controls as Travel and Procurement
Is your AI spending authorization framework as mature as your travel policy?
Your delegation of authority matrix has a limit for every category of spend except the one growing fastest.
The Situation
An employee opens an AI tool, starts working, and commits your firm to a real-time, metered obligation with no pre-approval step and no ceiling. Your delegation of authority matrix assigns a spending limit to every material expense category except this one, because that framework was built for fixed monthly bills, not for AI's shift to token-consumption pricing. A travel request gets a limit and an approver. A month of AI usage gets neither.
The Exposure
Uber burned through its entire 2026 AI budget by April, four months into the fiscal year, after usage outran the projections its finance team had budgeted for. The company's own COO has since said they still can't draw a clear line between that spending and any customer benefit. The result: significant spend, no clear return, discovered after the fact. The Linux Foundation's FinOps Foundation, whose 2026 survey drew on 1,192 practitioners managing over $83 billion in annual cloud spend, found that 98% of organizations now actively track AI costs, up from 31% two years ago. But tracking a number after it's spent isn't the same thing as controlling it. That's the gap Uber fell into.
The Judgment Call
The developing practice in most companies is to build in reporting and rely on disclosure as the management system, but that's the wrong fix at the wrong layer. No amount of disclosure can adequately manage a cost that can grow exponentially in a single reporting period. The only way for organizations to avoid Uber's outcome is to extend their existing authorization framework, the same one that already governs travel, procurement, and expense approval, to cover AI consumption before it happens. Limits need to be set by function, rather than a single cross-company figure, because engineering's usage will run far ahead of finance's or legal's. Usage reporting isn’t enough; instead set a hard spend limit per function or per user, enforced at the point of use either directly through your AI vendor (Anthropic and OpenAI both have this capability now) or through a gateway tool that sits in front of every vendor you use if you use multiple LLMs (e.g. Portkey).
Risk: Setting function-specific limits requires someone to decide, by function, what "normal" consumption looks like, which is a slow, and imprecise process.
Benefit: You turn uncontrollable spending risk into a managed deployment that matches the actual shape of AI usage in your organization.
This Week’s Action
What to do: Pull your current AI vendor or gateway tool and check whether per-user or per-function spend limits have been configured. If they haven’t, set an initial limit for your two or three highest-usage functions based on last month's actual spend.
Who to involve: Whoever administers your AI vendor accounts (usually IT or a platform lead) and the head of your highest-consumption function, typically engineering, to confirm the initial limit won't block legitimate work.
What outcome to achieve: At least one function operating under a managed, not just monitored, spend limit, with a named owner for reviewing and adjusting it monthly.
Time required: 90 minutes to pull current spend data, set initial limits, and confirm them with the function owner.
Artifact
AI Spend Authorization Checklist
Use this to assess whether your organization is managing AI cost or just watching it. Rate each item and remediate any that aren’t fully documented and current.
Enforcement mechanism: A hard spend limit is configured at the vendor or gateway level for at least one function, not just a report that someone might see after the fact.
☐ Not addressed ☐ Partially addressed ☐ Fully documented and currentFunction-specific limits: Spend limits vary by function based on actual usage patterns, rather than a single company-wide number.
☐ Not addressed ☐ Partially addressed ☐ Fully documented and currentNamed owner: A specific person, not a committee, is responsible for reviewing spend against each function's limit and adjusting it.
☐ Not addressed ☐ Partially addressed ☐ Fully documented and currentIncrease request path: There’s a defined process for a function to request a higher limit.
☐ Not addressed ☐ Partially addressed ☐ Fully documented and currentReview cadence: Limits are revisited on a set schedule, rather than left at whatever number was set when the control was first built.
☐ Not addressed ☐ Partially addressed ☐ Fully documented and currentCross-vendor coverage: If your organization uses more than one AI provider, limits are enforced consistently across all of them, not just the one IT initially set up.
☐ Not addressed ☐ Partially addressed ☐ Fully documented and current
When the stakes exceed your internal capacity:
AI Exposure Diagnostic: A 2-hour strategic evaluation for risk, compliance, and legal leaders to identify your highest-priority governance gaps and deliver a 90-day remediation roadmap.
12-Week Governance Sprint: Translate regulatory requirements into audit-ready policies, control frameworks, and accountability structures.
Ongoing Advisory Retainer: Embedded judgment for policy updates, vendor assessments, and board prep as regulations and technology evolve.
Fractional Chief AI Officer: A standing officer seat with the authority to ship or stop AI deployments, and the accountability to answer for that decision to your board and regulators. You get the officer without the full-time hire.
Reply with "Diagnostic" or “Sprint” to schedule a conversation for next month.
Chris Cook writes Judgment Call weekly for compliance and risk officers navigating AI governance.
Former IBM Vice President and Deputy Chief Auditor. Published in the AI Journal, speaker at Yale.
Chris Cook
Managing Partner & Founder
Blackbox Zero
Forwarded this by a colleague? Subscribe to Judgment Call