AI Agent Cost Controls: The Agency Due-Diligence Checklist

Published September 4, 2026By ABD Legacy LLC
AI agent cost controlsagency due diligenceAI media buying agentsAI token pass-through pricingagent drift detection

If your agency runs AI agents on your media account, the agents are spending your money — and most clients never see the meter. Media agencies are now deploying agentic tools for audience targeting, campaign set-up, and media execution, and the ones doing it well have discovered the tech only delivers savings if it is monitored (Digiday, Sept 4 2026). Agentic tools can hallucinate and burn through tokens when left to run by themselves. Gartner estimates that 60% of organizations using AI will face AI-related cost overruns caused by a lack of usage tracking, and that 56% of companies still implement AI tools without clear usage policies.

This page is the AI agent cost-controls due-diligence checklist for clients: what to ask before you let an agency run agentic buying tools on your budget, which controls separate the disciplined shops from the expensive experiments, and where the hidden costs actually hide. It covers financial governance only — audit logs, token budgets, drift detection, kill switches, and pass-through pricing — not the code-provenance and security questions covered in our AI agency security vetting guide.

Why cost control became a client question

For most of 2025, AI-agent spend was an agency-internal problem. No longer. As agentic buying tools move from demos into live accounts, agencies are building their own tracking and audit tools — and the reason is blunt. As Dept's global EVP of technology Jonathan Whiteside put it: “It can get out of control very, very quickly.” (Digiday, Sept 4 2026).

The named cases show what disciplined testing looks like:

The numbers that make this a due-diligence question

Two Gartner data points frame the risk (both reported by Digiday, Sept 4 2026, from an April survey of 1,300 senior marketers):

For an SMB client, the translation is direct: an agency that cannot show you how its AI agents are metered, audited, and bounded is asking you to accept a cost risk that most companies cannot even see in their own operations yet.

The due-diligence checklist: five questions to ask any agency

Before you sign an agency that runs agentic planning or buying tools — or before your current agency turns one on — ask for answers to all five:

  1. Will you show us audit logs? Not a summary — the log of what each agent did on our account, when, and why. PubMatic's audit log, which Rise uses, records every agent change with a timestamp and the details of how the change was made (Digiday, Sept 4 2026). Your agency should be able to produce the same class of record.
  2. How do you detect agents drifting outside pre-set parameters? Drift is when an agent deviates from the brief — changing targeting, bids, or creative choices that no human approved. Ask what parameters are set, who sets them, and what happens when the agent crosses them (Rise's PubMatic-based tests watch for exactly this).
  3. What kill switches and token budgets are enforced? PMG built a tool called “Alli For You” that gives users a daily cap on AI token usage; Dept runs an AI gateway that routes each request to a centrally chosen model — because, Whiteside says, people have burned through 1.5 million tokens in a day without controls. If your agency has no equivalent, your budget is the uncontrolled variable.
  4. Is AI-token pass-through separate from your management fee? Token spend should appear as its own line item — actual usage at agreed rates — not be absorbed into a fee where it cannot be audited. If the agency cannot separate the two, you cannot tell whether you are paying for results or for an unmetered model that was the wrong tool for the task.
  5. Will you alert us on overages before they happen? A control that only shows up in a monthly invoice is not a control. Ask for spend alerts at defined thresholds and a human approval gate before any agent exceeds its budget.

Strong-control signals vs. red flags

Strong-control signals (green flags)Red flags & hidden cost risks
Agency shows audit logs on request and can reconstruct what an agent did and whyNo audit trail; agent actions only visible as “results” on a dashboard
Drift detection: agents are monitored against pre-set parameters per campaign or per clientAgents given an open brief with no parameter enforcement
Token budgets and kill switches exist (daily caps, per-agent limits, automatic stops)No budgets; story of an unexpected “token spike” is treated as normal AI cost
AI-token pass-through billed as a separate line item at agreed ratesToken spend buried inside a management fee or a vague “AI usage” surcharge
Model selection is deliberate — cheapest model that meets the need, chosen per taskTop-tier model by default on every task; Gartner analyst Nicole Greene says much rising token consumption is people “not choosing the right model to meet the need of the activity”
Human approval gates before big spend; accountable human on every deliverableNo human checkpoint; “the AI did it” as an acceptable answer
Overage alerts at defined thresholdsClient finds out about overage in the invoice

Where hidden token costs actually hide

The agencies closest to this problem say the biggest cost lever is model choice, not volume. Gartner analyst Nicole Greene: “A lot of the token consumption costs are because people are literally not choosing the right model to meet the need of the activity.” (Digiday, Sept 4 2026). That is why Dept removed individual staffers' ability to pick a model — its AI gateway directs each request to the model chosen centrally for commercial and legal reasons — and why PMG codifies best practices into agents using “Skills” so the agent stays on the rails.

It is also why the audit itself is still immature. PubMatic's tool does not yet tell users what a specific path cost in AI tokens, so Rise triangulates cost from licensing and token spend, employee time, and how much of the campaign budget became working media. Rise's SVP of client technology, George Forge, calls it “a very rough math equation at this point” (Digiday, Sept 4 2026). If the agencies building the controls admit the per-path cost accounting is rough, a client that does not even ask the question has no protection at all.

Brainlabs frames the stakes plainly. Founder and CEO Daniel Gilbert says monitoring agent spend is not optional: “We want people to spend. We just want them to do it usefully” — and called the monitoring “existential.” (Digiday, Sept 4 2026).

Put it in writing

Checklist answers are only as good as the contract behind them. Make the five questions above into SOW and contract terms: the agency commits to audit-log access, drift detection, token budgets and kill switches, separate pass-through pricing, and overage alerts with a human approval gate. Our AI agency contract tips cover the clauses to negotiate, and the how-to-choose guide walks through the rest of the vetting process. If you are already paying an agency and cannot get these answers, that is a review trigger, not a paperwork gap.

Frequently asked questions

What are AI agent cost controls?

AI agent cost controls are the policies and tooling an agency uses to keep AI-agent spend metered, audited, and bounded: token budgets per agent or per client, spend alerts, audit logs, drift detection outside pre-set parameters, kill switches, and human approval gates. As agencies deploy AI agents for media planning and buying, clients need to verify these controls exist before signing — because agentic tools can hallucinate and burn tokens when left unmonitored, and Gartner estimates 60% of organizations using AI will face cost overruns from a lack of usage tracking (Digiday, Sept 4 2026).

How do I know if my agency is metering its AI agent usage?

Ask for the receipts: does the agency show you audit logs of what its AI agents did on your account, can it detect agents drifting outside pre-set parameters, does it enforce kill switches and token budgets, does it separate AI-token pass-through costs from management fees, and does it alert you on overages? Agencies at the leading edge are building exactly this kind of tracking — Rise (Quad agency group) uses a PubMatic audit-log feature to monitor AI media-buying agents working a supermarket account, and PubMatic says every change an agent makes is time-stamped and stored with details of how the change was made (Digiday, Sept 4 2026).

What is AI agent drift in media buying?

Agent drift is when an AI agent starts operating outside the pre-set parameters a human gave it — deviating from the brief, changing targeting or bids without authorization, or improvising its own course of action. Performance agency Rise monitors its AI media-buying agents for exactly this with a PubMatic audit-log feature, so a staffer can ask why the agent made a change and reconstruct what happened; PubMatic is running similar agentic-buying tests with Butler/Till and Abovo Maxlead (Digiday, Sept 4 2026).

Should agencies pass through AI token costs separately from management fees?

Yes — separate AI-token pass-through costs from management fees so you can audit both. If token spend is buried inside a management fee, nothing stops an agency from running a more expensive model than the task needs, because the client cannot see the line item. Agencies already separating these costs track licensing and token spend, time saved or spent by employees, and what share of the campaign budget ended up as working media — though Rise's own team calls the current math "a very rough equation" (Digiday, Sept 4 2026).

What is an AI token budget or kill switch?

A token budget caps how many AI tokens an agent or team can consume in a period; a kill switch (or circuit breaker) stops an agent's spend when it exceeds parameters or starts looping. Examples in the market: PMG built a tool called Alli For You that gives users a daily cap on AI token usage, and Dept runs an AI gateway that routes each request to a centrally chosen model after staff burned through 1.5 million tokens in a day at some points (Digiday, Sept 4 2026).

Why do 60% of AI adopters face cost overruns?

Gartner estimates 60% of organizations using AI will face AI-related cost overruns caused by a lack of usage tracking, and 56% of companies still implement AI tools without clear usage policies — an April survey of 1,300 senior marketers found marketing leaders are especially unlikely to assign financial controls to AI usage. For agency clients the translation is direct: if your agency's AI agents are not metered, audited, and bounded, your media budget is where the overrun shows up (Gartner via Digiday, Sept 4 2026).

Want an agency that treats AI-agent spend as a governed, auditable cost?

Browse Vetted AI Agencies →

AI Agent API Costs: How Agencies Should Bill Agent Usage

Sources

Accuracy note: All named agencies, quotes, and statistics on this page are attributed to Digiday's Sept 4, 2026 report and were verified against that article on publication date. Gartner figures (60% cost overruns from lack of usage tracking; 56% of companies implementing AI without clear usage policies) are as reported by Digiday from Gartner's April survey of 1,300 senior marketers. Rise's supermarket client is unnamed per the source. Quotes are as published: Dept's Jonathan Whiteside (“It can get out of control very, very quickly”), Gartner analyst Nicole Greene (model-selection cost driver), Rise SVP George Forge (“a very rough math equation”), and Brainlabs CEO Daniel Gilbert (“We want people to spend… usefully”; monitoring is “existential”). This page covers financial and usage governance only; security and code-provenance vetting are covered in the linked security guide.