TL;DR: AI spend governance fails when invoices, provider consoles, and cost centres do not share a common identity and policy model, leaving teams unable to see who is spending, on what, and why, according to Stacklok. The real control problem is not budget capping alone, but governing access, attribution, and fallback without interrupting legitimate work.
NHIMG editorial — based on content published by Stacklok: What good AI spend governance looks like
By the numbers:
- The average enterprise now has 69% more machine identities than human ones.
- 59% of companies face greater difficulties auditing machine identities, primarily due to lack of clear ownership and limited visibility.
- Only 38% have automated certificate lifecycle management in place.
Questions worth separating out
Q: How should teams govern AI consumption when spend is spread across multiple tools?
A: Start by assigning one control owner for AI consumption governance and require shared evidence from finance, IT, and security.
Q: Why do AI budgets fail when they are based only on invoices?
A: Invoices report what was charged, not which identity consumed the service, which workload generated it, or whether the activity was intended.
Q: What do organisations get wrong about AI spend visibility?
A: They often confuse partial dashboard coverage with complete governance.
Practitioner guidance
- Unify AI access through a governed endpoint Place model calls, tool calls, and agent traffic behind a single identity-aware control point so usage, policy, and audit context are consistent across providers.
- Map spend to organisational ownership before setting hard limits Tie budgets to users, groups, projects, or cost centres so finance can allocate cost and security can identify unmanaged credentials or workloads.
- Treat unmanaged API keys as spend and security risk Review developer laptops, application configuration, and direct provider access for credentials that can keep consuming after the creator has moved on.
What's in the full article
Stacklok's full blog insight covers the operational detail this post intentionally leaves for the source:
- How the AI Gateway normalises multiple provider APIs behind a common endpoint for identity and policy enforcement
- How token usage, gateway health, and rate-limiting activity flow into OpenTelemetry, Prometheus, and Grafana
- How model fallback is configured so approved workloads can shift to lower-cost models without losing auditability
- How local credential bridges reduce unmanaged keys when tools only support static API access
👉 Read Stacklok's analysis of AI spend governance and identity control →
AI spend governance: are your identity and budget controls aligned?
Explore further
AI spend governance is really NHI governance with a finance surface. The article shows that the control problem is not just invoice management, but attribution across models, tools, and workloads that are already acting as non-human identities. When credentials, usage, and organisational ownership are fragmented, finance sees cost while security sees only partial access. Practitioners should treat spend governance as an identity governance problem first and a cost problem second.
A few things that frame the scale:
- The average enterprise now has 69% more machine identities than human ones, according to The Critical Gaps in Machine Identity Management report.
- Machine identity auditing remains weak, with 59% of companies reporting greater difficulty auditing machine identities because ownership and visibility are unclear.
A question worth separating out:
Q: How do you know if AI fallback policies are working?
A: They are working when substitutions are deliberate, visible, and limited to approved workloads. You should be able to see which model handled the request, why the fallback triggered, and whether the change preserved acceptable quality. If users cannot tell when a model switch happened, the policy is hiding cost decisions rather than governing them.
👉 Read our full editorial: AI spend governance depends on identity, attribution, and control