CIOs Confront the Hidden Costs of Scaling AI #AI


EY’s Kevin Martelli on Measuring Returns and Governing In-House Development

AI adoption continues to expand even as token costs and internally built applications create new budget, governance and security concerns, according to an EY survey. (Image: Shutterstock)

Rising AI costs aren’t slowing enterprise adoption, but they are forcing CIOs to prove that higher spending is producing measurable business value, according to the latest EY US AI Pulse Survey. EY found that 82% of leaders are concerned about AI token costs, but only 64% say they actively monitor usage and have clear budget guardrails.

See Also: Inside the 2026 Cyber Workforce: Key Trends, Talent Gaps, Strategic Shifts and the AI Revolution

Kevin Martelli, an EY Americas Consulting AI solution development leader who works with organizations on AI investment, application development and governance strategies, said CIOs can take control of token spending by connecting AI investments to business outcomes to decide which applications are worth building internally. He also explained how organizations can keep AI-generated software from creating new security risks, shadow IT and technical debt.

In this interview with ISMG on findings from the EY US AI Pulse Survey, Martelli shared how companies can embed governance into AI development, automate routine controls without giving up human accountability and how to help CEOs and CFOs decide whether to expand, redesign or end an AI initiative.

Edited Excerpts Follow:

The survey found that 82% of leaders are concerned about AI token costs, but only 64% actively monitor usage and have clear budget guardrails. What should CIOs measure, and how should they allocate costs, to determine whether token consumption is creating business value rather than simply driving up cloud spending?

To ensure token consumption drives true business value, CIOs must look beyond surface-level time savings and track the fully loaded cost of an AI solution directly against concrete profit and loss outcomes. That starts with closing a gap since only 64% of senior leaders whose organization is investing in AI report that their organization actively monitors AI token usage and has clear budgetary guardrails in place for how much they spend.

On the allocation side, tech leaders should set up smart routing systems that automatically send everyday tasks to cheaper, fit-for-purpose AI models, saving the most expensive models for high-impact work. CIOs also need to stop dividing AI budgets by department silos and start funding big, cross-functional projects, such as building entire projects from start to finish.

That strategic shift ensures AI spending actually drives real business growth instead of just driving up cost. Finally, CIOs should run this as a value flywheel: Measure the cost of each outcome against the new revenue that value stream brings in or the optimizations achieved, reinvest those savings or new revenue into the next use case and feed what you learn back into deciding which models handle which tasks. That way, token spend becomes an engine for growth rather than a cost to keep contained.

Rising costs appear to be accelerating AI adoption rather than suppressing it: 37% of leaders are expanding their rollouts, while only 15% are reducing them. What distinguishes organizations using cost scrutiny to prioritize high-value AI from those that are merely scaling expensive experiments?

The difference between scaling expensive experiments and driving high-value AI comes down to focus. While some organizations throw money at small, disconnected projects that never move the needle, market leaders use cost pressure as a reality check to double down on what actually works.

Instead of rewarding raw usage, these organizations build strict budgets and guardrails into their projects right from the start. By tying spend to core business goals, they are among the top leaders seeing real, positive returns on their AI investments. In addition, they have the proper feedback loops to monitor and track outcomes to the intended value streams.

Nearly 9 in 10 organizations are piloting or deploying AI-built internal software, yet 72% say these efforts are already encountering obstacles. What criteria should CIOs use to decide which applications are worth building, and which should remain with established software vendors?

When deciding which applications to build and which to buy, CIOs have been asking, “What product should we implement?” But the new question they should be asking is, “What problem are we trying to solve?”

There are two core criteria. First, is the application core to your business and unique IP, or is it a commodity capability that a vendor already handles well? Second, does the build-versus-buy case hold up on total cost of ownership, including maintenance, security and talent requirements? Software being easier to build is not a sufficient reason to build it – there must be real business value behind it beyond simple upfront cost savings, a lesson we saw with custom ETL jobs in the past.

Everyone can access the same tools, so a competitive advantage will come from what CIOs can do with those tools, using their own data. That might mean building applications in house, but it might also mean combining off-the-shelf software with internally developed capabilities and AI-enabled workflows. What really matters is how everything comes together to produce an outcome that’s unique to your business and that’s truly solving business problems.

For those who do choose to build, AI coding dramatically lowers the cost of creating software, but it can also produce shadow applications, security vulnerabilities and a growing maintenance burden. What controls should CIOs put in place before employee-built applications become a new generation of technical debt?

Senior leaders recognize the risks of AI coding. Among those we surveyed, they reported that their top barriers to developing in-house, AI-built software for internal use were the increased risk of shadow IT (34%), regulatory compliance and governance concerns (33%) and increased vulnerability/cybersecurity risks (32%).

For leaders facing those barriers, having controls in place can give them more confidence. But we can’t govern AI the same way we govern traditional technology: It needs to be AI-enabled, with humans above the loop. Using AI, we can codify governance models into human language and integrate them into decisions up front, rather than waiting until after decisions are made.

One of the strongest controls you can provide is the platform itself. CIOs should stand up intent-driven AI development platforms so that where employee-built applications are permitted by the governance framework, team members have the right tooling to build them correctly. Intent goes in, and the platform standardizes the build while embedding controls from the start. As every organization shifts toward becoming product-led, how CIOs enable that shift will decide whether they build real capability or a new generation of technical debt.

EY argues that AI governance must operate at “machine speed” and be embedded directly into decision flows. What does that look like in practice, and which governance decisions can CIOs automate without giving up meaningful human accountability?

As AI becomes embedded into everyday work, governance has to operate at the same speed as the technology itself. That means governance cannot depend on manual approvals or quarterly oversight. It has to be integrated directly into the AI life cycle, enforcing policies in real time while providing complete transparency into how decisions are made.

CIOs can automate rules-based decisions like compliance checks, access controls, model monitoring, drift detection and audit logging. Human oversight needs to remain but should be focused on setting policies, defining risk tolerance, and making high-impact ethical or business decisions. The goal is to automate governance execution while keeping accountability with humans at the center.

The survey shows a persistent gap between projected and actual AI spending, even as 98% of respondents report positive ROI. What evidence should CIOs bring to the CEO and CFO to demonstrate credible returns, and when should they recommend expanding, redesigning or ending an AI initiative?

CIOs need to shift the conversation from how much they are spending on AI to the value it is creating for the business. To build confidence with the CEO and CFO, they should bring evidence that connects AI investments to measurable outcomes, including productivity gains, revenue impact, cost reductions, improved customer experiences, reduced risk and employee adoption.

The decision to scale, rethink or end an AI initiative should come down to business results and strategic fit. Programs that deliver measurable value, gain traction and create opportunities for further impact should be expanded. Initiatives that are showing potential but not meeting expectations may need to be adjusted or redesigned. And when continued investment is not producing meaningful results, leaders should be willing to stop and redirect resources.

None of these decisions is possible without the structure to measure them appropriately. As organizations become product-led and define their value streams, they need to capture outcomes at that level so every initiative is evaluated against the return it was funded to deliver. That clarity is what allows leaders to continue funding what is working and stop what is not, based on evidence rather than instinct.



Click Here For The Original Source.

——————————————————–

..........

.

.