Cloud cost monitoring has a blind spot. Most organisations running FinOps programmes know roughly where their infrastructure spend goes - compute, storage, data transfer, licences. What the standard tooling was not built to catch is AI consumption: the token-based API calls, the model inference costs, and the AI feature usage accumulating inside SaaS tools that never appear on a cloud bill at all.
That blind spot is getting expensive. Global public cloud end-user spending reached $723 billion in 2025 according to Gartner, and the fastest-growing component is AI-driven workloads. The FinOps Foundation's 2026 State of FinOps report, drawing on data from organisations managing over $69 billion in cloud spend, found that 98% of FinOps practitioners now manage AI spend, up from 31% just two years ago. That 67-percentage-point jump in two years is not a gradual trend. It is an industry acknowledging that AI consumption costs appeared faster than the monitoring frameworks built to track them.
The question for any CFO or IT Director running a cloud cost programme is not whether AI consumption needs to be in scope. It does, and most organisations know it. The question is whether the monitoring approach they have now can actually see all of it, or whether a significant portion of their AI spend is accumulating in places the tooling was never designed to look.
How AI Changed the Cloud Billing Model
Traditional cloud cost monitoring was designed for a specific billing model: provisioned infrastructure, metered by time and resource. You spin up a VM, you pay by the hour. You store a terabyte, you pay by the gigabyte-month. The relationship between resource consumption and cost is direct and predictable. The monitoring tools built around this model are good at what they were designed for.
AI consumption pricing is a different model entirely. The unit of consumption is not a provisioned resource but a transaction; an API call, a token processed, a model inference run. Costs accumulate not in steady, predictable increments but in bursts driven by usage patterns that engineering teams and end users generate independently of any infrastructure provisioning decision. A developer integrates an LLM API into a product feature. End users trigger inference calls every time they use it. The cost accumulates per call, in real time, with no ceiling unless one is explicitly set.
This creates a monitoring gap that is structural, not accidental. Traditional cloud cost monitoring tools watch infrastructure-layer spend. AI consumption often sits at the application layer - inside a SaaS product, consumed via API, billed by the vendor under a pricing model that exists nowhere in the cloud infrastructure bill. A FinOps team with excellent AWS Cost Explorer visibility and solid tagging discipline can still have no line of sight into the AI consumption costs that are running through the organisation's SaaS tools every day.
Where Cloud Cost Monitoring Misses AI Spend
Most of the AI spend that organisations are not tracking falls into one of three places, and each is invisible for a different reason.
AI Consumption Embedded in SaaS Tools
When a SaaS vendor enables AI features in their product, the CRM that now drafts emails, the project tool that now summarises meetings, the analytics platform that now generates AI-powered reports, the AI processing cost is absorbed into the vendor's infrastructure and passed through as part of the SaaS subscription. It does not appear as a separate line item on a cloud bill. It does not show up in AWS Cost Explorer or Azure Cost Management.
Every major SaaS platform has shipped AI features in the past two years. Most have either increased pricing to cover AI costs or introduced usage-based AI add-ons. The organisation that renewed its CRM at last year's price may be generating significantly more AI consumption cost this year, running through a tool that has been in the environment for years, under a contract that predates the AI features by at least twelve months, and invisible to every cloud monitoring dashboard the FinOps team uses.
Direct AI API Consumption Outside Procurement
AI API consumption - calls to OpenAI, Anthropic, Google Gemini, or similar - is increasingly happening outside formal procurement channels. Developers integrate APIs directly into products and internal tools. Individual employees sign up for API access on company cards to build personal productivity workflows. Teams adopt AI tools in exploration phases that never go through IT review. Each of these generates real, accumulating cost under an enterprise risk management lens: financial exposure without visibility, and data processing without governance.
The FinOps Foundation's 2025 State of FinOps survey found that AI spend management doubled from 31% to 63% of FinOps practitioners in a single year, which is another way of saying that in the prior year, 69% of FinOps teams had no formal process for managing AI consumption costs. For many organisations, those costs were accumulating untracked.
AI Consumption on Personal and Free-tier Accounts
The third category is the hardest to monitor: AI tool usage on personal accounts, free tiers, or consumer subscriptions that employees use for work. This does not generate a company cloud bill at all. It does not appear in expense data if the employee is using a personal payment method. It is detectable only through signals that look at what data is leaving the organisation, which is a governance question as much as a cost question.
Harmonic Security's Q3 2025 analysis of over three million enterprise prompts found that 11.84% of sensitive data exposures occurred through personal or free-tier AI accounts. Those incidents do not appear on any cloud bill, any expense report, or any FinOps dashboard. The organisation that has not looked for them does not know they are happening.
The FinOps Scope Problem
The FinOps discipline was built around a clear scope: public cloud infrastructure spend. That scope made sense in 2015 when AWS was the dominant cost centre and the job was getting visibility into EC2 and S3 costs. It made sense in 2020 when the scope extended to multi-cloud environments. It is no longer sufficient in 2025, when AI consumption has become a significant and fast-growing cost category that sits mostly outside the infrastructure layer.
The FinOps Foundation recognised this in its 2026 report, updating the discipline's mission from 'advancing the people who manage the value of cloud' to 'advancing the people who manage the value of technology.' That is not a rebranding exercise. It is an acknowledgement that the cost management problem has expanded beyond what the original framework was designed to handle.
The same 2026 report found that 98% of FinOps practitioners now manage AI spend, up from 63% the prior year and 31% two years before. The pace of that shift suggests that AI consumption costs became visible to FinOps teams not gradually but suddenly: something happened - a large invoice, an unexpected bill, a finance query that nobody could answer, and it forced the question into scope.
For organisations that have not yet had that moment, it is worth asking whether the absence of AI consumption in the FinOps scope reflects the absence of AI consumption, or the absence of visibility. The answer, for most mid-market organisations with any meaningful SaaS estate, is almost certainly the latter.
What Complete AI Cost Visibility Requires
The tooling question, which platform to use for AI cost monitoring - tends to get asked before the scope question, which is why most organisations end up with a tool that monitors the AI spend they could already see, not the portion they could not.
SaaS-embedded AI is a SaaS inventory problem before it is a cost monitoring problem. You cannot see AI feature costs inside SaaS subscriptions until you know which SaaS tools have active AI features and how intensively they are being used. A cloud cost monitoring tool pointed at infrastructure bills will not surface this. The starting point is knowing what is in the SaaS estate - which tools exist, which have AI active, and what the pricing implications are at renewal.
Direct AI API consumption is a tagging and attribution problem. Once the API spend is in scope, the discipline is the same as FinOps applied to infrastructure: cost centres attached, teams identified, use cases mapped, and a process for asking whether the spend is generating value commensurate with its cost. Most organisations that manage cloud infrastructure costs well can extend the same practice to AI API consumption - the gap is usually in scope, not in capability.
Personal account and free-tier usage is genuinely harder, and it is worth being direct about why. Cloud billing data cannot reach it. Expense reports miss it when employees use personal payment methods. The only signals that can detect it are the ones that look at what data is leaving the organisation - email metadata, SSO activity, browser signals, rather than what invoices are arriving. That is not a FinOps capability today; it is a discovery capability that feeds into FinOps scope. Getting there requires the two disciplines to connect, which most organisations have not done yet.
Most of the FinOps programmes that I go through are well run. Good tagging discipline, solid cloud cost attribution, regular optimisation reviews. The gap is not in how they manage what they can see - it is that a growing portion of AI spend is not in any system they look at. The SaaS vendor absorbed the AI processing cost into the subscription. The developer put the API key on a personal card, the team has been using a free tier, and none of this is in the cloud bill. The question that usually opens this up is simple: what did we spend on AI last month? When three people in the room answer with three different numbers and none of them can explain the gap, that is the moment the scope problem becomes visible. - Ankur Arora, Co-Founder, Montro |
The AI Governance Dimension of Cost Visibility
Ungoverned AI consumption is not just a FinOps problem. It sits inside the same visibility gap that creates regulatory exposure, and fixing one tends to fix the other.
An organisation that does not know which AI tools its employees are using cannot satisfy its obligations under GDPR Article 30, which requires a record of every processing activity involving personal data. It cannot satisfy DORA's Article 28.3 ICT register requirement if AI tools are being used in connection with financial operations. From August 2026, it cannot demonstrate compliance with EU AI Act Article 26 deployer obligations for any high-risk AI system it is running without knowing it is running.
The AI tool generating untracked consumption cost is almost always the same AI tool with no data processing agreement, no risk classification, and no audit trail. The cost monitoring gap and the governance gap point at the same underlying problem: the organisation does not have a complete picture of what AI is in use. Solving for one addresses the other, which is why a discovery audit that starts as a FinOps exercise tends to end up as the foundation of a governance programme too.
The FinOps Foundation's mission shift, from 'managing the value of cloud' to 'managing the value of technology' - signals that this convergence is where the discipline is heading. For mid-market organisations that cannot run separate programmes for cost management and compliance, it is also where the most practical path forward lies.
Frequently Asked Questions
Why can't standard cloud cost monitoring tools track AI consumption?
Because most AI consumption does not live at the infrastructure layer where cloud monitoring tools look. AI features embedded in SaaS products are billed through the vendor's subscription pricing; they never appear on an AWS or Azure bill. Direct AI API consumption can appear on a cloud bill but only if it goes through the organisation's cloud account and has proper tagging applied. And AI usage on personal or free-tier accounts generates no company billing data at all. Standard cloud cost monitoring tools were built to track provisioned infrastructure spend. AI consumption is distributed across layers they were never designed to reach.
How do I find out which SaaS tools in our environment have active AI features?
Start with your renewal queue and your SSO logs together. Tools coming up for renewal in the next six months are the ones where AI feature activation matters most, that is when you have leverage to ask the vendor directly what AI processing is running and under what contractual terms. SSO logs show which tools employees are actively using, which narrows the list from every tool in the environment to the ones worth investigating first. For tools outside SSO, the ones adopted without going through IT, expense data and email metadata tend to surface them. The combination of those three sources covers most of the estate; the tools that slip through all three are almost always on personal accounts and require a different approach.
Can a FinOps programme satisfy GDPR and EU AI Act requirements at the same time?
Not on its own, but it can produce the foundation both require. GDPR Article 30 needs a record of every processing activity, which means knowing every application that touches personal data. EU AI Act Article 26 needs deployer oversight of every AI system in use. Both start from the same place: a complete, accurate inventory of what the organisation is actually running. A FinOps discovery exercise that maps AI consumption across the SaaS estate, direct API calls, and personal account activity produces that inventory as a side effect. The compliance team then takes it from there; adding legal basis, risk classification, DPA status. The FinOps exercise does not replace compliance work, but it removes the single biggest obstacle to it: not knowing what is in scope.
Our FinOps team manages cloud spend but not SaaS. Is that a gap?
Yes, and it is a widening one. The FinOps Foundation's 2026 State of FinOps report found that 90% of FinOps practitioners now manage SaaS spend or have plans to, up from 65% the prior year. The reason is straightforward: AI features are predominantly delivered through SaaS, not infrastructure. A FinOps programme that covers cloud infrastructure but not SaaS cannot see the majority of where AI consumption costs are actually accumulating. The scope expansion from cloud-only to cloud-plus-SaaS is not optional for organisations with a meaningful AI footprint.
What should be the first step for a CFO trying to get AI consumption into FinOps scope?
Start with inventory, not tooling. Before adding an AI cost monitoring tool, the organisation needs to know what AI it is actually running, which SaaS tools have active AI features, which teams are making direct API calls, and whether there is personal account activity that the monitoring will not catch. A point-in-time discovery audit across the SaaS estate and financial data gives a baseline. Without that baseline, a cost monitoring tool has nothing useful to monitor, it will only show the AI spend that was already visible, not the portion that was never in scope.
.jpg&w=2048&q=75)




