What is an AI spend policy?
An AI spend policy is a short operating rule for buying, using and reviewing AI tools. It covers subscriptions such as AI assistants and coding tools, usage-based APIs, AI features bundled into existing software, and agents or automations that can create costs without a person clicking a button each time.
The best policy does not try to predict every tool. It defines the decisions that must remain consistent: what requires approval, which data is restricted, who owns the spend, how limits are set, and when unused access is removed.
This is governance at the operating level. The NIST AI Risk Management Framework organizes AI risk work around Govern, Map, Measure and Manage. A lean company can apply the same logic without creating a committee: set the rule, inventory the use case, track the result, and act when risk or cost changes.
Why a 20-50-person company needs a one-page policy
Small companies rarely need a procurement department, but they still need a consistent answer when someone asks to buy a new AI tool. Without one, approvals happen in Slack, expenses appear after the decision, and nobody knows whether an agent still runs after its creator changes role.
A useful policy should make five outcomes possible:
- Employees know what they can buy without waiting.
- Finance can see the full cost across seats, credits, APIs and embedded AI features.
- Every tool and agent has a named business owner.
- Sensitive or personal data is handled under explicit rules.
- Unused seats, duplicate tools and abandoned automations are reviewed on a schedule.
The Information Commissioner's Office guidance on AI and data protection emphasizes accountability, transparency, lawfulness, security and data minimisation. Those principles become much easier to follow when the company can identify the tool, use case, owner and data involved.
The ELI BOUND framework
ELI's BOUND framework turns a static policy into a lightweight control loop. Each AI purchase or agent must pass five checks: Baseline, Owner, Usage, No-go data and Decision cadence.
Baseline: know what exists
Build one inventory that includes employee subscriptions, corporate plans, API accounts, AI features inside existing SaaS, and autonomous agents. Record both fixed commitments and variable usage. A policy cannot control a purchase or workflow that never enters the inventory.
Owner: name one accountable person
Every AI tool and agent needs a business owner, even when Finance pays the invoice and Engineering holds the API key. The owner must be able to explain the purpose, approve access, review outcomes and decide whether the company should renew or stop.
Usage: define the economic boundary
Set the unit that matters for each cost model: seats for subscriptions, credits or tokens for usage-based services, and runs or successful tasks for agents. Add a warning threshold and a hard limit where the provider supports one. A provider limit is a brake; the company budget remains the cross-tool decision.
No-go data: make the boundary explicit
State which data employees may not enter into an AI system unless the tool and use case have been approved. Typical restricted categories include customer confidential information, personal data, credentials, unreleased financial information, proprietary source code and regulated records. The exact list should match your contracts and legal obligations.
Decision cadence: keep, change or cancel
Review fixed-price tools monthly for ownership and active seats. Review variable AI spend weekly when usage is volatile. Before renewal, compare cost, adoption, business outcome, overlap, security changes and exit terms. The result should be a decision, not another dashboard.
Copy-ready one-page AI spend policy template
The wording below is a practical starting point, not legal advice. Adjust the data rules, currency thresholds and approvers to fit your company.
1. Purpose and scope
This policy applies to any AI tool, AI-enabled software feature, model API, agent or automation used for company work or paid with company funds. Its purpose is to support useful experimentation while keeping spend, data and accountability visible.
2. Approved tools and new purchases
- Use an approved tool where it already meets the need.
- Before buying a new tool, check for overlapping features in the current stack.
- Record the tool, use case, owner, cost model and expected monthly cost before payment.
- Free tools still require approval when they process restricted company or customer data.
3. Ownership and budgets
- Every tool and agent must have one named business owner.
- Every purchase must map to a team budget or cost centre.
- Usage-based tools must have a warning threshold and a maximum monthly limit where technically available.
- Any expected overage must be approved before it is incurred, except during a documented incident.
4. Data and acceptable use
- Do not enter restricted data into an AI tool unless the vendor and use case have been approved for that data class.
- Do not share passwords, API secrets, private keys or authentication tokens in prompts.
- Review AI-generated work before it is used for customer, employment, legal, financial or security decisions.
- Follow existing privacy, security, intellectual-property and record-retention policies.
5. Agents and automations
- Record what the agent can access, what actions it can take and which systems can create charges.
- Use the least access required for the task.
- Set a stop condition, escalation owner and spending limit before unattended operation.
- Keep an activity log for workflows that change data, contact third parties or create financial commitments.
6. Review, renewal and offboarding
- Review AI tools monthly for usage, cost, overlap and owner status.
- Begin renewal review before the cancellation notice deadline, not on the contract end date.
- When an employee leaves or changes role, remove access and reassign or disable their agents, API keys and automations.
- Cancel unused tools and reclaim inactive seats or credits where contract terms allow.
7. Exceptions
Exceptions require a written owner, reason, time limit and approver. An exception expires unless it is reviewed and renewed.
Recommended approval thresholds for a lean company
The figures below are operating recommendations, not universal benchmarks. Set lower thresholds for sensitive data or actions and higher thresholds only where ownership and monitoring are strong.
- No-cost trial with public or synthetic data: business owner may approve.
- Any tool using customer, employee or confidential data: privacy or security review before use, regardless of price.
- New recurring spend up to £100 per month: team budget owner approves and records it.
- New recurring spend above £100 per month or any annual commitment: Finance or founder approval.
- Any agent that can purchase, publish, delete, message externally or change production data: explicit action approval plus a kill switch.
- Any forecasted variable-spend increase above 20% in a month: owner explains the driver and confirms the expected business outcome.
How to implement the policy in 48 hours
- Discover the current stack. Pull subscriptions from cards, expenses, invoices, SSO and browser or workspace data. Add API accounts, embedded AI features and agents.
- Assign owners. Ask each team lead to claim the tools and automations they rely on. Escalate anything unclaimed.
- Classify cost. Mark each item as seat-based, fixed subscription, usage-based, hybrid or bundled inside another contract.
- Set boundaries. Choose approval thresholds, restricted data classes, warning levels and hard limits.
- Publish one page. Put the policy where employees request tools and link it from onboarding materials.
- Start the review loop. Review volatile spend weekly and the full inventory monthly. Log keep, change, consolidate or cancel decisions.
For a 20-50-person company, one founder, COO or finance lead can own the system. Team leads own individual tools. You do not need a procurement committee; you need complete records, visible thresholds and a recurring decision date.
What to track in the AI inventory
Keep these fields in one system of record:
- Tool or agent name and vendor
- Business purpose and workflow
- Business owner and technical owner, if different
- Users, service accounts, agents and API keys
- Data categories accessed or submitted
- Pricing model, commitment, current spend and forecast
- Budget, warning threshold and hard limit
- Contract owner, renewal date and cancellation notice date
- Usage signal and business outcome
- Last review, decision and next review date
The inventory is not complete if it lists only vendors. AI spend can be created by a seat, an API key, an agent, an embedded feature or a workflow that calls several services. Track the spend surface and the accountable owner together.
Common AI spend policy mistakes
Treating the document as the control
A policy in a folder cannot detect a new subscription, a rising token bill or an agent that still runs after its owner leaves. Connect the policy to discovery, approval, alerts and review.
Approving a vendor instead of a use case
The same tool can be low-risk for public research and high-risk for customer records. Approval should describe the tool, data, action and owner.
Budgeting only by vendor
Vendor totals help reconcile invoices, but they do not show which team, workflow or customer created the cost. Add attribution before usage grows.
Using one review cadence for every cost
A fixed annual subscription and an unattended usage-based agent do not move at the same speed. Match monitoring to the cost and action model.
How ELI turns the policy into an operating system
ELI gives lean companies one layer for software and AI operations. It discovers tools, subscriptions, seats and agents; assigns owners and budgets; connects fixed and variable spend; surfaces overlap and waste; tracks renewals; and runs recurring back-office workflows. The policy defines the decision. ELI keeps the evidence and action loop current.
Frequently asked questions
What is the difference between an AI spend policy and an AI acceptable use policy?
An acceptable use policy focuses on permitted behaviour and data. An AI spend policy adds purchase approval, budgets, ownership, cost attribution, renewals and cancellation. A small company can combine them in one document if every element remains explicit.
Does a free AI tool need approval?
Yes, when it accesses restricted data, connects to company systems or creates meaningful operational risk. Price is only one approval trigger.
Who should own AI spend in a startup?
A founder, COO or finance lead should own the company-wide process. Each tool or agent should also have a business owner responsible for purpose, access, budget and renewal decisions.
How often should AI spend be reviewed?
Review volatile usage-based costs weekly and the full inventory monthly. Also review before renewals, after material workflow changes, and when an owner leaves or changes role.
Should every AI tool have a hard spending cap?
Use a hard cap where available and where stopping service will not create greater harm. Pair it with an earlier warning threshold, an escalation owner and a documented exception process.
Put the policy into operation
A one-page policy is the starting point. ELI helps you discover every software and AI cost, attach it to an owner and budget, and turn monthly review into action. Use ELI to make the policy visible in the way your company actually buys and runs software.