Why Enterprises Need AI FinOps, Security to Scale Responsibly #AI


Agentic AI
,
Artificial Intelligence & Machine Learning
,
Next-Generation Technologies & Secure Development

Enterprises Need Unified Cost and Security Controls to Scale AI Agents Responsibly


September 1, 2026    

Image: Magnific

Two numbers rarely appear on the same board slide: how much an enterprise is spending on artificial intelligence, and how confident its leaders are that AI agents are operating safely. That says a lot about where AI governance stands today. Most organizations address these questions separately, even though they are two sides of the same problem. Treating them as independent challenges makes it difficult to resolve either one of them.

See Also: Inside the 2026 Cyber Workforce: Key Trends, Talent Gaps, Strategic Shifts and the AI Revolution

Nobody Owns the Bill

Ask an engineering leader what next month’s AI bill will look like, and the answer will be a range of token costs or an honest “we’ll find out.” According to Harness’ 2026 State of AI in FinOps report, 72% of organizations experienced an unexpected spike in AI costs over the past year. By the time teams determine the cause, the money has been spent.

It’s not that organizations lack AI cost policies. Rather, few organizations have real-time visibility into the models, agents and workloads driving their spend, making those policies difficult to enforce.

This visibility gap may explain why Harness’ research found that nearly a quarter of AI spend generates no measurable business return. Amazon’s experience earlier this year, reported by the Financial Times, illustrates the challenge at scale. A single Claude task exceeded its budget by $1.8 million, 860% above projections, because nobody noticed what was happening while it was running.

This isn’t a new problem. Cloud computing has exposed similar gaps in cost visibility, often leaving finance and engineering teams to reconcile costs long after they have been incurred. AI raises the stakes. Instead of costs accumulating gradually, a single agent or an inefficient workflow can create significant overruns within hours. Autonomous agents can consume tokens at machine speed, turning a poorly controlled workflow into a large bill within hours. That makes cost policies at both the developer and autonomous agent level table stakes. For some use cases, enterprises may need to set hard cost thresholds that automatically stop an agent when those limits are reached.

The Blind Spot Becomes the Vulnerability

Cost visibility is only one part of the governance challenge. Organizations also need visibility into what their AI systems are doing.

Harness’ State of AI-Native Application Security report, published toward the end of last year, found that many security teams can’t identify every large language model operating inside their environments. One can’t secure what can’t be seen and many organizations have experienced unauthorized agents accessing data or performing actions that were never intended.

AI is spreading through enterprise environments faster than governance frameworks can keep pace. Gartner expects task-specific AI agents to become embedded across enterprise applications this year and has identified identity and access management for AI agents as one of the industry’s most pressing security challenges. Agents are increasingly being granted system access like employees without equivalent governance.

Open standards such as the Model Context Protocol have accelerated adoption by making it easier for agents to interact with enterprise systems. But they weren’t designed to enforce security by default.

Attackers have noticed this.

Researchers recently uncovered a campaign involving roughly 7,600 malicious GitHub repositories, including more than 800 disguised as AI tools, agents or MCP servers. These repositories were designed to be surfaced by coding assistants, increasing the likelihood that developers would unknowingly introduce malware into production environments.

The implication is significant. The target is no longer just the developer using AI – it’s the AI itself and the trust organizations automatically place in it.

Securing AI means looking beyond the model. Organizations need visibility into what AI agents are doing, the systems they access, actions they take and the data they interact with.

Yet only about one-third of the developers involve security teams before starting AI projects and barely half of them do so before deployment. The challenge isn’t a lack of intent. It’s that AI development is moving faster than traditional security review processes.

Under these circumstances, organizations can’t manage cost and security in isolation. Understanding what AI is costing without knowing how it behaves leaves organizations exposed. Also, knowing that an AI system is secure without understanding what its cost makes it difficult to judge whether it’s delivering meaningful business value. Enterprises need visibility into both.

During conversations with enterprise customers, it’s clear that many organizations are still in the early stages in developing AI security and governance frameworks. They are implementing the right tools and policies, even as the use of AI agents grows. This could become a real barrier when companies start deploying agents at scale, especially in highly regulated industries that require tighter control over what an agent can access and the actions they can take.

Where Governance Needs to Live

Policies alone won’t solve the problem. Organizations need operational visibility into every model call, agent action and tool invocation, along with the cost and outcome associated with every activity.

FinOps teams need real-time attribution rather than monthly reports. Security teams need complete visibility into every AI agent operating across the enterprise, including the ones nobody formally approved. Most importantly, both teams must work from the same data instead of reconciling separate reports weeks or months later.

Enterprises that scale AI successfully won’t necessarily be those that spend the most. They’ll be the ones that build visibility and control into both the cost and risk from the start.

Without those capabilities, AI adoption isn’t simply moving faster – it’s becoming harder to govern, justify and, ultimately, scale.



Click Here For The Original Source.

——————————————————–

..........

.

.