TL;DR: AI agent rollouts can consume 5 to 30 times the tokens of comparable chatbot interactions, and some enterprises have already blown through budgets by 4 to 11 times within 90 days, according to WorkOS and Gartner analysis. The governance gap starts in authorization: without per-agent identity, tool-level scoping, and session boundaries, cost attribution stays invisible and unusable.
Editorial analysis by NHI Mgmt Group, based on content published by WorkOS: “The token bill is an identity problem”.
Key questions
Q: What breaks when AI agents are connected through personal accounts or shared credentials?
A: Shared or personal credentials break accountability, lifecycle control, and revocation.
Q: Why do AI agent programmes need tool-level authorization for cost control?
A: Because the tool boundary is also the spend boundary.
Q: How do organisations know if AI governance is actually working?
A: They should be able to reconstruct a live interaction from identity context, policy outcome, accessed resources, and enforcement evidence.
Practitioner guidance
- Issue distinct identities for each agent Separate agent credentials from human user accounts and from other agents so every model call can be attributed to one runtime actor.
- Scope tools at the authorization layer Grant each agent access only to the tools it needs, because tool-level authorization is also the cost boundary for token spend.
- Bind access to task sessions Use session-scoped tokens that expire with the task so spend cannot continue after the visible workflow is complete.
Bottom line: AI agent token spend becomes difficult to govern when identities are shared, access scopes are broad, and sessions are not enforced at task boundaries.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Token spend is now an identity governance problem, not a finance afterthought. The article is right to treat cost attribution as the visible symptom of a deeper authorization design flaw. When agents share credentials or inherit human identities, the organisation loses the ability to bind spend to a specific actor, workflow, or owner. The practical implication is that chargeback fails wherever identity boundaries are vague.
A few things that frame the scale:
- Claude Code-assisted commits leaked secrets at a rate of 3.2%, more than double the human-only baseline of 1.5%, with peaks reaching 31 secrets per 1,000 commits in August 2025, according to the State of Secrets Sprawl 2026.
A question worth separating out:
Q: What should security teams do when an AI agent keeps consuming tokens after the task ends?
A: Treat that as a session-boundary failure. The agent should lose access when the task closes, and any credential that survives beyond the workflow should be reviewed as over-persistent. Persistent access is what turns a bounded task into open-ended spend.
👉 Read our full editorial: Token spend is an identity problem for AI agent governance