Every other story in this series is about AI doing something wrong: giving bad advice, deleting data, inventing sources, screening people out. This last one is different. Here, the AI worked perfectly. It did exactly what it was asked, at scale, around the clock, for a whole month. That was the problem.
According to a consultant who described the incident to Axios this spring, an enterprise gave its employees open access to an AI platform with no spending caps and no usage limits. People used it. Enthusiastically. At the end of the month, the bill was about $500 million.
Half a billion dollars, in 30 days, because nobody switched on the equivalent of a spending limit. It's the least dramatic failure in this series and, for a lot of mid-market businesses, the most likely one to actually happen to you. So it's a fitting place to end.
How a bill gets that big
The mechanics are almost boring, which is exactly why they're dangerous. Most serious AI tools are priced by usage; you pay per unit of text processed, often called tokens. A quick question costs a fraction of a cent. That's what makes it feel free, and that feeling is the trap.
The cost scales with three things that all move in the wrong direction at once when usage is unrestricted. Heavier tasks cost more: an engineer running an AI agent across a large codebase, or feeding it huge documents, can rack up hundreds or thousands of dollars a month alone. More powerful models cost more per unit. And more people using it multiplies everything. Reports around this incident put heavy individual users in the range of $500 to $2,000 a month each. Multiply an uncapped version of that across thousands of employees, all reasonably believing each small query is trivial, and the total compounds into something no one is watching until the invoice lands.
No single person did anything unreasonable. Each query was cheap. Each employee was being productive. The failure was purely structural: there was no ceiling, no meter anyone was watching, and no alert that fired when the number crossed from sensible into absurd.
The part worth sitting with
The controls to prevent this existed. The platform in question offered admin dashboards, per-user limits, and spending controls. They simply weren't turned on.
That's the whole lesson in miniature, and it echoes every other article in this series. Air Canada had policy pages the chatbot could have been synced to. Replit had the ability to separate development from production. In each case the safeguard was available and unused, because someone treated deployment as the finish line instead of the starting line. Turning the AI on is easy. The governance is the actual work, and it's the part that gets skipped under the pressure to move fast.
It's worth being clear about what this is and isn't. It isn't an argument that AI is too expensive to use, the productivity these tools deliver is real, and used well they pay for themselves many times over. It's an argument that AI is an operating expense like any other, and no competent business runs a major operating expense with no budget, no monitoring, and no cap.
The governance that would have caught it
Set hard spending caps, not soft intentions. A budget you're "keeping an eye on" is not a control. A hard cap that actually stops or throttles usage when a threshold is hit is. Set them per user, per team, and per organization, so that even if everything else fails, there's a ceiling the bill physically cannot exceed.
Monitor usage in real time, with alerts. The $500 million bill was invisible until it arrived, because nobody was watching the meter mid-month. A simple dashboard showing spend as it accrues, plus automated alerts when usage crosses defined thresholds, turns a month-end catastrophe into a same-day question: why did today's number jump?
Match the model to the task. The most powerful model is not the right tool for every job, and it's the most expensive per use. Routine, low-stakes work can run on cheaper, lighter models, with the premium reserved for tasks that genuinely need it. A large share of runaway AI cost is simply expensive models doing cheap work.
Control who can access what. Not everyone needs unrestricted access to the most powerful, most expensive capabilities. Role-based access, where the heavy tools are available to the people whose work requires them and not switched on for everyone by default, limits both cost and risk without slowing anyone down who actually needs the horsepower.
The real lesson, and the thread through all seven
We build and manage AI systems for businesses, and cost governance is part of every deployment we run, because a tool that quietly bankrupts a budget isn't a productivity gain; it's a liability with good reviews. Metering, caps, model selection, and access controls aren't the exciting part of AI. They're the part that determines whether the exciting part is sustainable.
Which is the thread running through this entire series. Across seven cases- a wrongful chatbot promise, a robotaxi cover-up, a report full of fabricated sources, an agent that deleted a database, a support team automated at the wrong target, a hiring tool that discriminated at scale, and now a bill that hit nine figures overnight- the failures were never really about the technology. The technology mostly worked as designed. The failures were about the missing layer around it: the verification, the human oversight, the disclosure plan, the guardrails, the right goal, the accountability, the budget.
That layer is unglamorous, and it is the entire difference between AI that grows a business and AI that becomes its cautionary tale. The companies in these stories all had the resources to build it. They moved fast and left it out. The good news is that the layer is knowable, buildable, and mostly a matter of deciding to do the work before you flip the switch, not after the invoice arrives.





