Key takeaways
- Enterprise anger over unexpected AI token costs is a governance failure disguised as billing.
- GRC teams are absorbing workload created directly by ungoverned AI use both internally and externally, including rising volumes of financial crime, AI-drafted complaints and employment tribunal claims.
- AI use is outstripping AI governance, but the companies capturing most economic value from AI are those with the best governance processes.
- Open-weight models can solve the sovereignty problem but risk creating a new, cyber-security, one.
- The answer is not slower AI. It is value-based, mindful governance: conscious, evidenced oversight that observes what AI does rather than simply absorbing its output, and keeps a human being in charge of the decision.
Introduction: the hidden costs of AI for GRC teams
In May, engineers at Uber found that they had spent an entire year’s AI budget in just four months. The culprit was Claude Code, rolled out enthusiastically across the organization to speed up software development. It worked. It also cost so much, so fast, that leadership had to step in and cap what individual engineers could spend.
Alex Karp, CEO of Palantir, expressed the broader issue on CNBC in July.
“Every single enterprise I deal with, these people are livid. They’re like, ‘I am paying for tokens that create no value.’”
Alex Karp, CEO, Palantir
Karp’s language was typically combative, but his underlying complaint is sound: enterprises are handing frontier AI labs a blank check, and nobody inside those enterprises can say with confidence what that check is buying, who approved it, or what happens when the bill keeps rising.
That may be a finance problem, but it’s also a governance problem that has been quietly building since generative AI moved from pilot to production, and it sits alongside others that GRC teams are only now starting to connect:
- Who really controls the model, the data and the compute an organization relies on?
- Can compliance capacity keep pace with the workload AI itself is creating? And…
- Who is accountable when an AI-assisted decision turns out to be wrong?
CoreStream GRC’s existing guide to Effective AI-enabled GRC sets out how to make individual AI outputs defensible: evidence, ownership, governance, workflow and defensibility, tested output by output. That work still matters, but events of the past few months point to a question sitting one level above the workflow: is the AI relationship itself, the spend, the vendor and the capacity behind it, governed at all?
This guide sets out what “yes” looks like.
The ungoverned ledger: why token spend is a governance gap, not a bill
Every finance function knows how to control a line item. Approval thresholds, budget owners, monthly variance reviews: the machinery exists, and it works well enough for renewing a software license or a cloud storage contract. But, so far, it hasn’t worked for AI tokens.
Uber’s experience was not a one-off. The same pattern is seen across other large, technology-forward firms: usage-based AI pricing, sold as a way to pay only for what is used, has instead produced bills that nobody had budgeted for and nobody was watching closely enough to catch early.
Karp’s CNBC appearance crystallized why. He described what some in the industry now call “tokenmaxxing”: AI labs and the tools built on top of them structurally incentivized to maximize token consumption rather than solve the problem in front of the user, because token consumption is the metric that determines the vendor’s revenue. Palantir followed the interview with a nine-point “AI sovereignty” manifesto, arguing that “data retention is your treasure”.
The strategic challenge is highlighted by OpenAI’s recent generosity. In May, Sam Altman, OpenAI’s chief executive, said he would hand $2 million (£1.5 million) worth of “free” ChatGPT usage to each of the 170 start-ups in the most recent batch at Y Combinator, the Silicon Valley accelerator that helped launch Airbnb, Stripe and Coinbase. Free tokens today are rarely free tomorrow. Habits form around a tool priced to be irresistible, and the bill catches up once the free allocation runs out and usage has become embedded in how a team works.
For GRC and finance teams, the practical question is not whether AI is worth paying for. It is whether anyone owns the token budget the way they would own any other material spend: with a named approver, a usage ceiling, a review cadence and an escalation path for when the number moves faster than expected.
The banking sector shows both how fast adoption is moving and how far governance is lagging:
- 77% of banks have now actively launched or soft-launched GenAI applications, up from 61% in 2023 (EY-Parthenon). But…
- 78% of business executives lack strong confidence they could pass an independent AI governance audit within 90 days (Grant Thornton). And…
- 46% cite governance or compliance gaps as the reason for AI underperformance. (Grant Thornton)
And, the organizations closing that gap are not the ones moving slowest. PwC’s 2026 AI Performance Study found that:
- ¾ (74%) of AI’s economic value is being captured by just one-fifth of companies
- 1.7x Those leading companies are 1.7 times as likely to have a formal, responsible AI framework
- 1.5x And 1.5 times as likely to have a cross-functional AI governance board.
Governance is not what slows AI down. It is what determines whether the spend produces anything worth having.
Sovereignty: the GRC issues behind who really controls your model, your data and your compute
Token spend is the more visible issue but beneath it sits a potentially more significant one: who actually controls the intelligence an organization is renting.
Microsoft’s chief executive, Satya Nadella, put the case in a recent blog post. Enterprises using AI models from labs such as OpenAI and Anthropic, he argued, are “paying twice”: once in tokens for the work the model does, and a second time by handing over the proprietary knowledge that makes the model useful in the first place.
“Models learn from exhaust; the prompts people write, the tools agents use, and especially the corrections people make when the model is wrong. Every correction is distilled into institutional know-how.”
Satya Nadella, CEO, Microsoft
Of course, that’s a strategically convenient argument for the chief executive of a company that sells the alternative, private, tenant-bound AI infrastructure, but it is also a valid governance argument. If every correction an employee makes to an AI output is quietly training a model that a competitor, or the vendor itself, can later draw on, an organization’s AI usage policy is a data governance question whether or not anyone has labelled it one.
Karp, whose company sells a rival model of enterprise control, reaches a similar conclusion from a different direction. His argument centers less on model training and more on data exposure and vendor lock-in: enterprises want to know whether they are keeping their data, and whether the vendor selling them intelligence is quietly preparing to compete with them.
Both arguments describe the same underlying failure that CoreStream GRC’s guide to Effective AI-enabled GRC already identifies for internal AI outputs: without evidence, ownership and defensibility built in, an organization cannot show how an output was produced, or trust what it is built on. As CoreStream’s own GRC Strategy Director, Paul Cadwallader, puts it:
“AI is powerful for automation, but its impact depends entirely on how it’s applied within each organization. Human judgment still leads the way; AI gives people the time to use it well.”
Paul Cadwallader, GRC Strategy Director, CoreStream GRC
The sovereignty question simply moves that same test up a level, from the workflow to the vendor relationship.
Can you show where your data goes once it leaves your systems?
Can you show what a model has learned from your corrections, and who else can draw on that learning?
Can you switch providers without losing the institutional memory built into the relationship?
Nadella’s proposed fix, running AI inside a “proprietary learning environment” with an “orchestration layer” that lets an organization switch between providers, is really a governance answer dressed as an infrastructure one: retain ownership of what you generate, and avoid becoming structurally dependent on a single vendor’s goodwill.
For GRC teams, sovereignty belongs on the same register as any other third-party risk: which AI vendors hold your data, what they are contractually permitted to do with it, and what happens if that access is withdrawn, as organizations were reminded when the US government temporarily blocked access to a frontier model in June 2026. CoreStream GRC’s reporting on that episode, “When the US government switched off AI: what the Anthropic shutdown means for your GRC program,” is worth revisiting for any team that has not yet mapped what a sudden loss of AI vendor access would mean for its critical workflows.

The workload nobody budgeted for: AI is not shrinking the GRC caseload
Every conversation about AI spend seems to assume the goal is to spend less. For compliance teams, the more urgent problem is often the opposite: AI is generating more work, not less, and it is coming from outside the organization as much as from within it.
3 trends illustrate how the GRC workload is growing.
The first is financial crime. Fraud is already moving faster than most firms’ monitoring can follow. UK Finance’s Annual Fraud Report 2026 recorded £1.28 billion lost to payment fraud in 2025, a 4% rise on the previous year, with authorized push payment fraud, where a victim is tricked into approving the transfer themselves, up 19% to £576.4 million. As Jaypee Soule, VP Compliance and MLRO at PensionBee, observes on CoreStream GRC’s recent Spotlight on Women in GRC podcast:
“Fraudsters are already getting ahead with AI and deepfakes. The only way to stay on top and keep people safe is to learn the system yourself and get ahead of it.”
Jaypee Soule, VP Compliance and MLRO, PensionBee
The second trend is complaints; arguably less visible than fraud, but no less real. In the same conversation, Soule describes a pattern compliance teams are beginning to see:
“People are even using AI for complaints. [They] are using AI to write complaints and they can do it within five minutes when it would usually take them a couple of days to draft a good complaint… so if people are then getting complaints, complaints data has gone up, right?”
The same pattern is showing up in employment tribunals. HR News reported that workers are increasingly turning to AI to draft and pursue claims, adding to a tribunal system already facing significant delay. For compliance and HR teams already stretched, AI is not just changing what complaints and claims look like. It is changing how many land, and how fast.
The third trend is quieter, but more strategic: skills atrophy. The same overreliance that is inflating AI budgets is also eroding skills across the workforce. A May 2026 global survey of 2,500 workers and IT leaders, conducted by IT firm GoTo and reported by HR Dive, found that 39% of all workers, and 46% of Generation Z employees, say their reliance on AI has weakened their own skill sets and made them less intelligent, even as 60% said they felt pressured to use AI to increase productivity. This is not a finding about GRC teams specifically. It is a wider, more strategic signal about how organizations resource and retain skills across the whole business, and it is a difficult combination for any GRC function to manage: more pressure to use AI, and a workforce that increasingly reports being worse, not better, at doing the job without it.
AI is causing the GRC workload to grow but, applied properly, it could also be part of the solution:
“AI, the rise of AI, will define the next era of governance, risk and compliance because, at the moment, everyone’s using AI to do admin type stuff like editing policies and drafting procedures … But I feel like we’re moving to the phase where AI is going to become like an agent, and GRC leaders will have to not only think about the risks of auditing human beings, but also auditing AI.”
Jaypee Soule, VP Compliance and MLRO, PensionBee
To be effective, AI needs to be used as monitoring infrastructure rather than administrative convenience. Used that way, agentic monitoring becomes a way of absorbing rising caseload rather than adding another tool for a stretched team to babysit. Left ungoverned, it becomes one more system nobody can fully explain when a regulator asks who was watching it.
Accountability and governance don’t move when the model does
Every pressure covered so far, spend, sovereignty and workload, converges on the same question: who is actually responsible when something goes wrong?
The answer, generally, is that responsibility sits with senior management. Nothing changes because a model is involved. For example, in UK financial services, the Senior Managers and Certification Regime (SMCR) states that a named Senior Manager is accountable for outcomes in their area of responsibility, and that accountability does not transfer to the model, the vendor or the system that produced the output. The FCA’s executive director, David Geale, told the House of Commons Treasury Committee in January 2026 that individuals at regulated firms are “on the hook” for harm caused to consumers through AI.
Firms waiting for guidance before building an evidence base are taking an unnecessary risk, because the accountability already applies. What tends to be missing is not the rule but the paper trail behind it: an inventory of every AI tool in use, a plain-language explanation of what each one does and influences, a documented review-and-approval trail for AI-assisted decisions, and a working process for human override that can be evidenced, not just asserted. That is the same test CoreStream GRC’s existing AI guide sets for individual outputs, evidence, ownership, governance, workflow and defensibility, now applied across an organization’s whole AI estate rather than one workflow at a time.
The EU AI Act tells a parallel story about regulatory pace outstripping organizational readiness. In June 2026, the Council of the European Union gave final approval to delay the Act’s toughest obligations for high-risk AI systems from August 2026 to December 2027, with AI embedded in already-regulated products pushed further still, to August 2028. As CoreStream GRC covered in its own reporting on the change, the delay is less a reprieve than a longer runway. ISACA’s 2026 AI Pulse Poll of more than 3,400 digital trust professionals found that only 38% of organizations have a formal AI policy in place and that 56% did not know how long it would take to halt an AI system in the event of a security incident.
As Baringa Partners recently reported, for every £1,000 invested in AI, only 20p (0.02%) is invested in governance. This compares to data privacy technology that has 5-10% governance investment spend.
CoreStream GRC’s Paul Cadwallader argues that the AI Act’s extra runway is only useful if firms use it: “A regulatory delay is not a reason to stand down. It’s a chance to build AI governance that means something, rather than a policy that only gets tested when a regulator finally asks to see it.”
The common thread across SMCR and the AI Act is that regulators are not waiting for organizations to catch up on spend, sovereignty or capacity before holding a named individual accountable for the outcome. The paper trail either exists before it is needed, or it gets built retrospectively, under far worse conditions.
The open-weight paradox: sovereignty’s hidden risk
The obvious response to both the spend and sovereignty problems is to route around frontier labs altogether: adopt an open-weight model, run it on infrastructure the organization controls, and stop paying token by token for intelligence a vendor can also learn from. Vercel’s AI Gateway data shows open-weight models now account for 29% of the traffic running through it, evidence that the shift is well underway.
However, the obvious answer may not be a complete solution. Katie Paxton-Fear, a cybersecurity lecturer at Manchester Metropolitan University, recently demonstrated how easily an open-weight model’s behavior can be deliberately corrupted. Using around ten training examples and less than $100 of compute, she backdoored a model in roughly an hour, training it to reliably produce code containing a remote-execution vulnerability when triggered, even on prompts it had never seen before. The larger the model, her research found, the easier it was to poison.
An open model brings data and compute back inside an organization’s own perimeter, which addresses the Nadella and Karp arguments directly, but it does nothing, on its own, to prove that the weights an organization downloaded, or fine-tuned, have not been tampered with somewhere upstream. Sovereignty over where a model runs is not the same as assurance over what the model was trained to do.
For GRC teams evaluating a move to open-weight infrastructure, verifiable model provenance must now sit alongside cost and control as a formal assessment criterion: where did the weights originate, how has their integrity been established, what transformations have subsequently been applied, and what evaluation evidence demonstrates that those changes have not produced unapproved behavioural drift?
Governing AI spend and governing AI sovereignty are important, but governing model integrity is a critical third factor that many GRC functions have not yet addressed.
Mindful AI: conscious governance for an unconscious tool
Every gap this guide has described, spend nobody owns, corrections nobody tracks, workload nobody budgeted, weights nobody has checked, has the same root cause. Something is happening inside the organization that nobody is fully watching. Mindful AI governance is the discipline of closing that gap.
Mindfulness, in its original sense, means paying full, deliberate attention to what is actually happening, rather than reacting on autopilot. Applied to AI governance, that translates into 3 practical commitments.
- The first is conscious awareness: knowing, at all times, where AI sits in the business. Not a one-off inventory filed after a project closes, but a live, current picture of which tools are in use, by whom, on what data and to what end. Most of the gaps in this guide, from Uber’s token bill to the open-weight paradox, start with an organization that could not answer that question in the moment it mattered.
- The second is observing rather than absorbing. An AI output is a claim, not a fact, and a mindful organization treats it that way: it checks the reasoning, traces the evidence and tests the conclusion before acting on it, rather than absorbing the answer because it arrived quickly and confidently. That is the same distinction that separates evidence-based compliance tools from generic, ungoverned AI. As Anders Søborg, Co-Founder of SANNOS, CoreStream GRC’s AI partner, puts it:
“Most compliance pain is not strategy. It’s reading, mapping, and proving.”
Anders Søborg, Co-Founder, SANNOS
Tools built to show their working, with citations traceable back to the source, give a GRC team something to observe. Tools that simply assert an answer invite the organization to absorb it instead, and passive absorption is where governance quietly stops.
- The third commitment is retaining the human element. Rich Eddolls, Co-Founder and Chief Product Officer at CoreStream GRC, set out this principle in the company’s own AI strategy paper:
“AI supplements human activity rather than replacing it. Our aim has always been to help GRC professionals move away from the cumbersome manual tasks and instead give them time back to focus on strategic, value-based GRC activities and outputs.”
Rich Eddolls, Co-Founder and Chief Product Officer, CoreStream GRC
That is the difference between AI that expands human judgment and AI that quietly substitutes for it. A named Senior Manager, a compliance officer reviewing a flagged transaction, a board member signing off an AI framework: mindful governance keeps a person accountable at every one of those points, deliberately, rather than letting accountability drift toward whichever system produced the most convenient answer.
Put together, those 3 commitments are what CoreStream GRC means by value-based GRC applied to AI: governance built around the outcomes an organization is trying to protect and achieve, not just the boxes it needs to tick. In practice, that turns the 4 gaps in this guide into 3 questions a board can actually ask:
- Where, specifically, is AI already being used across the business, including by employees who never asked for permission?
- What evidence exists, today, that could be shown to a regulator, an auditor or a court if that use were challenged?
- And who, by name, is accountable for the outcome?
An organization that can answer all 3 is practicing mindful, value-based governance.
Conclusion: governing AI now means governing four things, not one
Every thread in this guide leads back to the same finding. Most organizations have built a control framework for what AI does inside a single workflow, and CoreStream GRC’s existing guide to Effective AI-enabled GRC is designed to help with exactly that: evidence, ownership, governance, workflow and defensibility, tested output by output. Far fewer have built equivalent controls for what AI costs, who controls the model and data behind it, what happens to caseload when AI both helps and multiplies the work, and who is accountable when something goes wrong.
None of these four gaps is solved by slowing AI adoption down. In fact, as PwC’s research finds, the firms pulling ahead are the ones treating governance as a growth enabler rather than a brake: a formal AI framework, a named budget owner, a cross-functional governance board, and an evidence trail that would survive being handed to a regulator with no notice.
That is what mindful AI governance means in practice. Name an owner for AI spend the way you would for any other material cost. Treat AI vendor relationships as the third-party risk they are. Resource the compliance function for a caseload that AI is expanding as often as it is shrinking. Check the provenance of any model you did not build yourself. And build the accountability trail before a regulator, auditor or board member asks to see it.
The answer, in every case, is not slower AI. It is AI governed with the same discipline an organization already applies to its money, its people and its most important relationships.
Want to start building AI-enabled GRC that your team can trust, verify, and defend?
Frequently asked questions
Token budgeting means tracking and controlling AI spend that is metered in tokens or credits rather than traditional software licenses. It matters for GRC because token-based access often bypasses the procurement and risk-review steps that used to trigger oversight, letting teams adopt AI at scale before anyone assesses the risk.
AI sovereignty is an organization’s ability to choose, control and, where necessary, ring-fence the AI it uses, rather than a vendor or platform deciding by default. It matters for governance because it determines who holds the decision rights over data access, model behavior and the ability to switch AI off.
Value-based GRC aligns governance, risk and compliance with an organization’s strategic goals, not just its regulatory obligations. Applied to AI, it means building governance that makes adoption more defensible and effective, rather than treating oversight as a brake on innovation.
Teams need visibility of where AI is already being used across the business, including by customers and claimants, and processes built for higher volume and faster-moving cases. Connecting complaints, incident and risk data helps patterns, like a rise in AI-assisted complaints, surface early rather than case by case.
Yes, but only when the governing AI is evidence-based and auditable, not generic. Tools built to read source documents, map them to frameworks and show their reasoning can support GRC teams reviewing AI-driven work. Ungoverned, general-purpose AI should never assess or approve its own outputs.


