Skip to main content
Abstract image: glowing AI brain with financial charts, symbolizing uncontrolled enterprise AI spending.

Editorial illustration for Survey: 20% of enterprises lack real-time controls for AI spending sprees

20% of Enterprises Can't Control AI Spending

Survey: 20% of enterprises lack real-time controls for AI spending sprees

4 min read

One in five enterprises still can't shut off an AI agent's spending once it starts running, according to new VB Pulse survey data covering 107 enterprises. That gap sits inside a bigger pattern: companies are no longer betting their agentic AI strategy on one vendor. The median enterprise now runs three orchestration platforms at the same time, and 85% use at least two. Only 15% have settled on a single tool.

That's not just about dodging vendor lock-in, though flexibility is part of the calculus. The bigger driver is trust, or the lack of it. Enterprises don't fully believe any single vendor's security and permissioning setup can handle what they need, so they're stacking platforms and building their own guardrails on top. Microsoft holds the lead in current usage, while Anthropic is pulling ahead by a wide margin when enterprises are asked what they're evaluating next.

But adoption has outpaced control. Token usage tracking and real-time visibility into what agents are actually spending remain unresolved for a meaningful share of respondents, exposing how far operational discipline still has to go before agentic AI runs unsupervised at scale.

Builders are using various strategies to try to keep agent spending in line: 30% rely on native platform controls (built-in budget caps or throttling) and 25% have built custom gateway plumbing (proxy middleware to intercept runaway agents).

Why this matters

The three-orchestrator pattern tells us enterprises have already priced in vendor failure, but the spending-controls gap tells us they haven't priced in agent failure. Those are different risks, and only one of them has a kill switch. If 20% of enterprises can't throttle a runaway agent's API calls or cloud spend in real time, then all that multi-vendor hedging against lock-in is happening alongside a much more immediate exposure: a misconfigured agent racking up costs faster than anyone can react.

For developers building on Microsoft AI Foundry, OpenAI's Agents SDK, or Anthropic's Claude Platform, that's a design problem, not a procurement one. Permissioning and spend caps need to be built into the orchestration layer itself, not bolted on after finance flags an anomaly. For founders selling into this market, the opening is obvious: enterprises are explicitly asking for controls vendors haven't shipped yet.

Watch whether the platforms with 70% and 68% penetration respond with real circuit breakers, or whether enterprises end up building their own guardrails on top of tools they still don't fully trust.

Common Questions Answered

What percentage of enterprises lack real-time controls to stop AI agent spending?

According to the VB Pulse survey of 107 enterprises, 20% of companies cannot shut off an AI agent's spending once it starts running. This gap represents a significant vulnerability in enterprise AI deployment, as these organizations have no real-time kill switch for runaway agents that could rack up unexpected costs.

How many orchestration platforms does the median enterprise currently run simultaneously?

The median enterprise now runs three orchestration platforms at the same time, with 85% of surveyed companies using at least two platforms. Only 15% of enterprises have settled on a single orchestration tool, indicating a widespread strategy to avoid vendor lock-in and maintain flexibility across multiple AI agent systems.

What are the main strategies enterprises use to control AI agent spending?

Builders employ two primary approaches: 30% rely on native platform controls such as built-in budget caps or throttling mechanisms, while 25% have built custom gateway plumbing using proxy middleware to intercept runaway agents. These strategies represent different levels of investment and control, with native controls being simpler but potentially less flexible than custom solutions.

Why is the spending-controls gap considered more immediate than vendor lock-in concerns?

While enterprises have hedged against vendor failure by using multiple orchestration platforms, the spending-controls gap represents a more immediate exposure: a misconfigured agent can rack up costs faster than any vendor could fail. The article emphasizes that enterprises have priced in vendor failure but haven't adequately addressed agent failure, which poses a direct financial risk with no kill switch for 20% of companies.

LIVE23:17Grok's gibberish responses affect small subset of users