Seventy-three percent of enterprises overshot their AI cost projections last year. That’s not a startup statistic. It comes from the FinOps Foundation’s 2026 State of FinOps report, built on survey data from nearly 1,200 practitioners managing more than $83 billion in annual cloud spend.
For MSSPs, that number isn’t a finance department problem to watch from the sidelines. It’s a preview of the conversation your clients are about to have internally, and a chance to be in the room before it happens.
Tokens Don’t Bill Like Anything IT Has Priced Before
A virtual machine bills by the hour. Storage bills by the gigabyte. Both are knowable in advance.
Azure OpenAI Service bills by the token, and tokens are not knowable in advance. The same prompt can return 200 tokens or 1,200 depending on how the model responds. A retried call still consumes the tokens from the failed attempt. A fifty-turn conversation compounds context with every exchange, so the last message in the thread can cost several times more than the first.
Provisioned Throughput Units were supposed to fix this. Reserve capacity, get a flat hourly rate, forecast with confidence. In practice, PTUs only pay off above roughly 80 percent utilization . Buy for peak demand that doesn’t materialize and the enterprise pays for idle throughput every month, the AI equivalent of over-provisioned compute that FinOps teams spent a decade learning to catch.
Fine-tuned models add a second trap. A deployed fine-tune bills hourly whether it answers zero queries or a million. Teams that spin up a fine-tune for a pilot and forget to decommission it are carrying a standing invoice for a project that never shipped.
The Real Problem Isn’t the Bill. It’s Who’s Watching It.
Here’s what should concern security and services leaders more than the invoice total: AI spend is landing on the books through channels procurement never sees.
Business units are adopting AI capabilities bundled into existing SaaS contracts, or through consumption-based API access that doesn’t trigger a purchasing review below certain thresholds. Analysts tracking enterprise software spend have flagged this pattern as a meaningful driver of 2026 budget growth: AI consumption that never passed through the controls built to catch runaway cost.
That’s the same failure mode security teams have fought for a decade under a different name. Shadow IT meant data sitting somewhere it shouldn’t. Shadow AI means data actively moving through a system nobody is watching, often shaping a model’s behavior in ways that are hard to reverse.
The Cloud Security Alliance’s 2026 research on enterprise AI visibility found that 86 percent of organizations lack clear insight into how data flows to and from the AI tools already running in their environment. Only 37 percent have a formal AI governance policy in place. IBM’s most recent breach cost research puts a number on what that gap costs: incidents involving shadow AI now factor into one in five breaches, adding roughly $670,000 to the average cost of a breach where it’s present.
A finance team that can’t explain why the Azure invoice tripled and a security team that can’t explain where sensitive data is flowing are looking at the same blind spot from two different departments.
What This Means for the People Who Secure These Environments
MSSPs and vCISOs are already positioned to see this before finance does. Cost anomalies in Azure Cost Management often show up as usage spikes tied to a business unit or application that never went through a security review. That spike is a governance signal before it’s a budget line.
A few moves make the difference:
- Make AI cost visibility as a security control, not just a FinOps task. Treat unexplained consumption growth with same scrutiny as unexplained network traffic.
- Ask clients which AI capabilities arrived through vendor add-ons rather than a deliberate deployment decision. Most CIOs can’t answer this today, and that’s the finding, not a knock on them.
- Fold AI governance into existing security reviews instead of treating it as a separate initiative competing for budget and attention.
The organizations closing this loop fastest are the ones where FinOps and security are no longer separate conversations. Per the FinOps Foundation, 78 percent of FinOps practices now report into the CTO or CIO organization rather than finance, a shift that puts cost governance and security governance under the same reporting line for the first time.
That’s an opening. The MSSPs who can speak fluently about both the invoice, and the exposure will be the ones enterprise clients call first when the AI bill lands on the CFO’s desk and nobody in the room can fully explain it.
If you advise enterprise clients on security posture, the AI cost conversation now belongs in that same review. It’s worth raising before their finance team raises it for you.
