
What does good AI control look like at this spend?
When two labs take most token dollars and median firms still buy seats, compliance cannot be a binder. It has to ride the invoice and the identity graph.
Compliance programmes love inventories. Ramp’s cash-register view of AI gives you a different starting point: follow the money, then close the gaps the money cannot see.
On the latest token-spend week, Anthropic and OpenAI take about 95% of maker share. That simplifies vendor due diligence for metered APIs — and tempts teams to stop there. It should not. Ramp’s own notes say free and personal use never show up. EU AI Act high-risk obligations that rolled through 2026 still expect inventories, logging, and human oversight for systems in regulated domains — including ones that arrived via a shadow path.
Controls that match the spend picture
1. Tier by intensity, not by slogan. Ramp’s intensity work shows median firms near seat-cost (~$11 per employee per month) and a thin tip spending thousands. Apply lighter controls to low-risk chat seats; put evaluation, access reviews, and retention rules on high-volume API and agent estates. One policy for every use case is how you get ignored.
2. Make the approved path the fast path. If the enterprise tool is slower than the consumer app, compliance is cosplay. Procurement should negotiate terms that include DLP hooks, admin controls, and clear training-data rules — then market those tools internally like a product launch, not a ban memo.
3. Put a name on every high-spend system. CSA’s governance work keeps circling the same failure: responsibility without authority. Token spend without an owner is an audit finding waiting for a date. Ownership should cover procurement, deployment, and retirement — the whole lifecycle.
4. Measure model defaults. Ramp documents firms pushing traffic toward cheaper standard models as frontier prices and performance diverge. That is a control pattern: default to capable-enough, escalate to frontier with a reason code. Cost control and compliance can share a dashboard.
A short checklist that survives contact with Monday
- Map Ramp-visible vendors and top shadow apps from proxy, DNS, or endpoint telemetry.
- Classify systems by use (and by EU/UK risk tier where relevant), not by marketing category.
- Require human review where outputs touch customers, money, safety, or employment decisions.
- Retain prompts and outputs where regulated; delete where they are only a convenience cache.
- Review API keys and agent identities on the same cadence as privileged access.
Good control is not anti-adoption. It is how you keep the licence to keep spending. The firms already writing big AI cheques need that licence most — and they have the telemetry, if they choose to use it, sitting in the same finance systems Ramp uses to build the Index.
Sources: Ramp AI Index · Intensity / spend per employee · Price and default-model trends · CSA — Invisible Enterprise