1. Objective
To make AI consumption, measured in tokens, credits, messages or currency, attributable and defensible, so that an organization can say who spent what, on what, and whether it was within budget.
2. Scope
All metered AI consumption: model API tokens, platform credits and capacity packs, per-seat AI licences, and consumption by agents and automated flows, whether billed directly or through a cloud provider.
3. Key terms
Consumption event. A recorded unit of AI usage reported by a provider or platform.
Attribution basis. What an event is attributed to: the AI system, the owner only (when the platform reports no system), or nothing.
Unaccountable spend. Consumption that cannot be linked to an AI system with an owner of record under AIGS 100.
Collection freshness. How recently consumption data was successfully collected, as distinct from when consumption last occurred.
4. Requirements
5. Evidence
- Consumption report by AI system and owner, with attribution basis.
- Budget register and alert history.
- Unaccountable spend trend over at least three periods.
- Price table with sources and effective dates.
- Licence reconciliation records.
6. Metrics
| Metric | Definition |
|---|---|
| Unaccountable spend | Consumption not linked to an owned AI system, divided by total consumption, per period. |
| Attribution quality | Share of consumption attributed by system, by owner only, and unattributed. |
| Budget adherence | Owned systems within budget, divided by owned systems with budgets. |
| Seat utilization | Active AI seats, divided by licensed AI seats. |
7. Basis for conclusions
Total consumption is already visible in most provider consoles; what organizations lack is accountability for it. The draft therefore centers on unaccountable spend rather than total spend. Requirements 200.3, 200.5 and 200.8 address failure modes observed in practice: platforms that omit the system name, budgets scored against lifetime totals, and silent collection failures that look like falling usage.
8. Questions for respondents
- Are 80% and 100% the right default alert thresholds?
- Should owner-basis attribution be acceptable indefinitely, or only as a transition state?
- How should shared or platform-wide consumption be allocated?