AI's Rising Costs Are Giving CISOs an Opening


By: Kaushik Shanadi, CTO

For the past few years, enterprises have experimented with AI. They adopted it. And they arguably moved too fast. Now, many are arriving at two big “oh s***” moments: How secure is all of this? And how much is it costing us? Both matter, but nothing gets the attention of the C-suite quite like a massive bill.

And as AI costs climb, that sticker shock may be giving CISOs something they haven’t always had in the race to adopt AI: an opening to talk about security and governance without being seen as a roadblock.

The economics of agentic AI are becoming difficult to ignore. Gartner recently predicted that AI inference costs per agentic workflow will increase more than fivefold through 2028 as increasingly sophisticated workflows consume more tokens. Uber’s system offers a real-world example. After burning through its annual budget for Claude Code earlier this year, the company introduced a $1,500 monthly spending limit per employee for individual agentic coding tools. More recently, Uber said weekly AI agent requests had increased 9.4 times since February, while overall AI costs remained flat since April.

Cost may be driving the conversation but getting control of AI spend requires something security teams have been asking for all along: visibility. You can’t control what you’re spending on AI if you don’t know what AI is running across the business…and you can’t secure it either.

That is becoming increasingly difficult as employees adopt AI tools, agents, and developer technologies independently. Organizations can quickly accumulate systems that security teams cannot see, much less govern.

This gives CISOs an opportunity to broaden a conversation that is already happening. As the business starts taking inventory of AI usage to understand costs, security can use that same exercise to understand which agents and tools are operating, where they connect and what they are able to do.

From there, organizations can establish policies around approved tools and acceptable behaviors, monitor AI activity and enforce guardrails where necessary. Employees can keep experimenting with AI while security teams gain the visibility and control they need to manage the risks that come with that adoption.

That’s an important change in how security and governance fit into AI adoption. Instead of showing up later as a perceived blocker, CISOs can help the business understand what it has, decide what it trusts and create a foundation for scaling AI responsibly.

Rising token costs may be what finally gets the C-suite’s attention. For CISOs, the massive AI bill isn’t just a cost problem. It may be the opening they’ve been waiting for to have the security and governance conversation, too.

Ready to secure your agents?

See what's running in your organization today. Talk to our team.

Contact Us