Consumption based AI services shift a risk that mattered little under classic licensing. When access is compromised, the damage lands directly on the invoice. Reports from affected users show the pattern: usage climbs noticeably on a single day although the tool was not used at all. The cause is stolen session keys, harvested by malware on the endpoint.
One characteristic is regularly underestimated here. A session key behaves differently from a password. It sits locally on the device, it is already authenticated, and multi-factor authentication no longer helps because the second factor was supplied when the session was created. Hardening only the login secures the wrong layer.
The way usage is presented makes things worse. Many platforms show a single aggregate figure rather than the individual operations behind it. Without that breakdown, neither internal cost allocation nor proof of abuse is possible. Nobody would accept a phone bill without itemised calls today.
For procurement this yields a short checklist: exportable usage records, a defined deadline for terminating compromised sessions, agreed liability for third party consumption and clear conditions for changes to the allowance.