A vendor turns on an AI feature inside a product your organization already owns. No new purchase order, no new line item anyone remembers approving. Three months later, someone in finance asks why a single product’s invoice jumped by six figures, and nobody on the technical side can point to the one thing that changed.
That’s not a usage spike. That’s multi-vendor AI billing exposure: a metering change that most enterprise buyers never see coming, because they’re still reading AI pricing the way they read a software license, one price, one meter, one number to track.
That assumption is what’s costing organizations money right now. AI features from Salesforce, Microsoft, and a growing list of other enterprise vendors don’t bill on a single meter. They bill on two, three, sometimes four independent constructs running inside the same contract, and vendors are still rewriting the pricing models behind those constructs in real time. This page is a working reference for what that exposure looks like, how to find it in your own contracts, and what to check before your next renewal.
This is a companion piece to MD360’s enterprise AI visibility and cost control page, which covers Microsoft’s Copilot and Azure AI billing mechanics in depth. This page covers the same exposure category across the broader vendor landscape, with Salesforce as the deep-dive case study.
When a vendor adds a new module to a traditional software product, the commercial model usually stays familiar: more seats, a higher tier, maybe a new SKU. AI features broke that pattern. Instead of replacing the seat-based model, most vendors layered consumption metering on top of it, and in several cases added a third and fourth layer beyond that. The result is a pricing architecture, not a price tag: multiple independent billing constructs, each capable of moving on its own schedule, each invisible to the others unless someone is deliberately reconciling them.
A single enterprise agreement can now carry a per-user license fee, a consumption-based credit pool, and a per-request or per-token charge. All three can apply to features that sit inside what looks like one product, and none of the three constructs caps or replaces the others. A team can stay flat on seats, stay flat on adoption, and still see AI spend climb because the credit pool and the request-based meter are moving independently of headcount. MD360’s earlier analysis on token-level AI spend visibility goes deeper on why consumption-based billing is the hardest of the three constructs to forecast, because it moves with behavior, not with any number in your org chart.
This is a lens for evaluating any AI-enabled vendor in your estate, not a single-vendor pitch. The vendor MD360 currently has the sourced mechanics to demonstrate all three vectors against, in depth, is Salesforce.
Four meters, one interaction: per-conversation, Flex Credits, per-user Agentforce, Einstein Requests. Salesforce’s AI billing is genuinely hybrid, and Salesforce says so on its own rate card: generative AI use “may also consume Data Cloud credits as well as Flex Credits or Conversations.” Depending on how a customer is set up, a single Agentforce interaction can pull from up to four separate meters at once:
None of this is a hidden charge. Salesforce discloses it on its own pricing documentation. The exposure isn’t that the meters exist. It’s that four independent constructs can move on the same interaction, and most customers are only tracking one of them at renewal time.
A standard Flex Credit action costs 20 credits, about $0.10 at the $500-per-100,000 rate. The number that matters more is what Salesforce calls a silent multiplier: actions that process more than 10,000 tokens consume multiple credit blocks per action, not a proportional fraction of one.
A single complex AI action, the kind that ingests a long document or reasons across several data objects, can cost several times the standard rate with no change to your contract terms and no alert when your usage crosses a threshold. The action still shows up as “one action” in the interface. The credit consumption behind it does not.
Until September 2025, Salesforce customers paid Data Cloud (now Data 360) credits to ingest their own first-party Salesforce CRM data into the platform’s AI layer. That’s a genuinely vendor-acknowledged “paying to use your own data” pattern, not an inference from usage logs. Salesforce made ingestion of that first-party data free going forward.
The fact that Salesforce changed it is itself the evidence the pattern was real. It matters for two reasons: it confirms customers weren’t imagining the exposure, and “going forward” means it does not retroactively reverse consumption already billed under the old model.
A Flex Credit pool doesn’t stop billing when a customer exceeds the contracted amount, and it doesn’t trigger a hard limit. Consumption above the pool continues billing at the contracted rate. There is no built-in circuit breaker. Whether that’s a problem for a given organization depends entirely on whether someone is watching consumption against the pool in real time, which is a visibility question, not a pricing question.
Salesforce has introduced five distinct Agentforce pricing constructs in approximately 20 months. That’s not five price increases. It’s five different ways of structuring how Salesforce bills you, in under two years. A pricing model Salesforce is still rebuilding at that pace is harder to negotiate against and harder to forecast, because the terms you negotiate this renewal cycle may not describe how the next cycle’s usage gets billed.
KeyBanc Capital Markets, in an analyst note published July 2026 and corroborated by CIO.com, cited this pricing-model volatility as a factor in a broader trend of enterprise buyers deprioritizing Salesforce spend. That’s not MD360’s read on the market. It’s an independent analyst observation that the pace of pricing-model change is itself showing up as a buyer-behavior signal.
Microsoft’s AI cost risk, covered in depth on MD360’s Microsoft AI cost control page, centers on adoption-value mismatch and a specific metering change. Organizations pay for Copilot seats that go underused, and Microsoft has shifted toward consumption-based billing for certain Copilot interactions.
That’s a real risk, but it’s a comparatively stable pricing architecture around it. Salesforce’s risk is different in kind: it’s a metering model that is still visibly in motion, with five structural changes in under two years. Buyers evaluating both vendors need to plan for two different failure modes, not one generic “AI cost risk” category.
Applying the low end of that range, 8%, to a $500,000 annual AI credit pool, with no increase in usage at all.
Salesforce’s standard Order Form carries an annual uplift clause of 8-10%, consistently reported across independent licensing advisories. MD360 has not independently confirmed that figure against a live Order Form specimen for any specific account, so treat it as directionally reliable rather than contractually verified until you’ve checked your own agreement’s actual language.
Held against a flat $500,000-per-year baseline, that’s $253,056 in cumulative extra spend across the three uplift years, before a single additional AI interaction occurs. No new users, no new features, no expanded rollout. The contract’s own uplift clause produces that number on its own.
The FinOps Foundation and the ITAM Forum announced a formal strategic partnership on June 2, 2025. That June announcement treated AI as one thread among several, alongside SaaS, licensing, and data center spend. That matters more than it sounds.
Their October 30, 2025 follow-up, “Unifying FinOps and ITAM,” goes further and explicitly folds AI cost governance into that convergence. Read together, the two announcements show where the industry actually is: AI didn’t create the need to unify software asset management and cloud financial operations, but it made the case for it considerably more urgent.
Software licensing covers who has what and what’s entitled. Cloud or AI cost governance covers what’s actually consumed and billed. If your organization still treats these as two separate functions with two separate owners, the multi-meter exposure described above falls exactly into the gap between them.
A license renewal team can miss a Flex Credit overage entirely if nobody on that team owns consumption reporting. The reverse happens just as easily: a cloud cost team can miss a contractual uplift clause if nobody on it reads Order Form terms. The convergence the FinOps Foundation and ITAM Forum are describing is a direct response to that gap.
Gartner’s November 19, 2025 press release, based on a 302-person survey of cybersecurity leaders, found that 69% of organizations suspect or have evidence of unauthorized generative AI use inside their environment. That figure describes usage prevalence, meaning how common unsanctioned AI use is, not how much it costs. There is no substantiated Gartner figure for AI shadow-spend growth in the form that circulates in marketing content, and this page does not use any such number. If unauthorized use is happening at that scale, some portion of it is running against the same stacked meters described above, entirely outside anyone’s renewal planning.
Gartner’s February 17, 2026 press release forecasts AI governance platform spend at $492 million in 2026, growing to over $1 billion by 2030. That’s a secondary data point relative to the usage-prevalence figure above, but it’s a useful signal in its own right. The market is already pricing in the scale of this problem, which is a reasonable indicator that this isn’t a niche concern confined to a handful of early adopters.
Three checks, in order, before you sign anything:
Count the meters in your own contracts. For every AI-enabled product in your estate, list every independent billing construct: per-seat, per-consumption, per-request, per-token, credit pool. If you can’t name all of them without pulling the contract, that’s the first gap to close.
Ask what the Order Form locks in beyond the headline price. Annual uplift clauses, overage terms, and credit-pool caps (or the absence of a cap) usually live in the boilerplate, not the pricing summary. A vendor rep quoting you a per-unit price is not the same as a vendor rep walking you through the uplift clause.
Confirm your own reporting shows consumption by meter, not just a total invoice. A single line item on an invoice can be the sum of several different billing constructs. If your internal reporting can’t decompose that number back into its component meters, you’re managing this risk with less visibility than the vendor has.
Traditional enterprise software licensing bills per seat or per core, on a predictable cycle. AI features frequently bill on some combination of per-seat access, consumption credits, and per-request or token metering, sometimes from the same vendor in the same contract. That combination, not the existence of AI itself, is what creates the exposure this page covers.
Salesforce’s AI billing is genuinely hybrid, and up to four separate meters can bill a single interaction: a per-conversation charge, Flex Credits, a per-user Agentforce add-on, and Einstein Requests (see the exact rates above). Salesforce’s own rate card states that generative AI use “may also consume Data Cloud credits as well as Flex Credits or Conversations,” so Salesforce discloses the stacking itself; MD360 is not inferring it.
A Flex Credit pool is $500 per 100,000 credits, with a standard action consuming 20 credits (about $0.10). The risk is what Salesforce calls a “silent multiplier”: actions that process more than 10,000 tokens consume multiple credit blocks per action, so a single complex AI action can cost several times the standard rate without any change in your contract terms.
Flex Credit pools also carry no contractual overage cap, so consumption above the contracted pool simply continues billing at the contracted rate rather than stopping or triggering a hard limit.
Until September 2025, Salesforce customers paid Data Cloud (now Data 360) credits to ingest their own first-party Salesforce CRM data, a genuinely vendor-acknowledged “paying to use your own data” pattern. Salesforce made ingestion of that first-party data free going forward.
It matters because it confirms the pattern was real (Salesforce’s own change is the evidence), and because “going forward” means it does not retroactively address consumption already billed under the old model.
Salesforce’s standard Order Form carries an 8-10% annual uplift clause (consistently reported across independent licensing advisories; not independently confirmed against a live Order Form specimen, so treat the exact figure as directionally reliable rather than contractually verified for any specific account). Applied to a $500,000 annual AI credit pool at the low end of that range (8%) with zero usage growth: Year 2 = $540,000, Year 3 = $583,200, Year 4 = $629,856.
Held against a flat $500,000/year baseline, that is $253,056 in cumulative extra spend across the three uplift years before a single additional AI interaction occurs.
Yes, and this is the risk that doesn’t have a clean Microsoft equivalent. Salesforce has introduced five distinct Agentforce pricing constructs in roughly 20 months. KeyBanc Capital Markets (analyst note, July 2026, corroborated by CIO.com) cited this pricing-model volatility as a factor in a broader enterprise-buyer trend of deprioritizing Salesforce spend.
Where Microsoft’s AI cost risk is largely about adoption-value mismatch and a metering change, Salesforce’s risk is a metering model still visibly in motion.
Yes. The FinOps Foundation and the ITAM Forum announced a formal strategic partnership on June 2, 2025 (per both organizations’ own announcements and PR Newswire distribution). Their October 30, 2025 follow-up, “Unifying FinOps and ITAM,” explicitly folds AI cost governance into that convergence.
The June announcement alone treats AI as one thread among several (alongside SaaS, licensing, and data center), so this page cites both together for accurate framing of where AI sits in that story.
Gartner’s November 19, 2025 press release found that 69% of organizations, in a 302-person survey of cybersecurity leaders, suspect or have evidence of unauthorized generative AI use in their environment. That figure describes usage prevalence, not spend growth.
There is no substantiated Gartner figure for AI shadow-spend growth in the form that circulates in marketing content, and this page does not use any such number.
No. MD360 does not sell AI or token-cost governance as a separate, stand-alone service, and has no plans to build one. MD360 delivers AI and FinOps governance as a module inside SAM Compass, MD360’s recurring software asset management program, the same estate-instrumentation method that already governs Microsoft, Salesforce, and other enterprise software licensing, extended to AI consumption, credits, and vendor billing constructs.
If multi-vendor AI billing exposure is a live concern, the right starting conversation is about SAM Compass, not a separate AI product.
This page goes deep on Salesforce, where MD360 has sourced, verifiable billing mechanics, and cross-links to MD360’s dedicated Microsoft AI cost control page for Microsoft-specific detail. This page names other AI-enabled vendors, including Oracle, SAP, IBM, Broadcom, Adobe, ServiceNow, Workday, OpenAI, Anthropic, Google, and AWS, only at a landscape level.
It describes the general pattern of credit-based and hybrid billing, without vendor-specific dollar claims, because MD360 does not yet have primary-sourced mechanics for them at the same depth. Every one of these vendors is moving toward some combination of seat-based and consumption-based AI pricing, but none of them have sourced mechanics detailed enough to publish a dollar-specific breakdown here yet.
AI and FinOps governance isn’t a separate product at MD360. It’s part of how SAM Compass already governs your software estate. The same instrumentation that tracks Microsoft, Salesforce, and other enterprise licensing extends to AI consumption, credit pools, and the multi-meter billing constructs covered on this page. If multi-vendor AI billing exposure is on your radar, that’s where the conversation starts.
Learn more about SAM Compass, Managed Software & Cloud Governance
Our team of experts created these guides to provide deeper coverage of the topics referenced throughout this page.
