How do I stop my AI bill being run up?
Keep the model key on the server, require sign-in for AI features, cap requests and tokens per user per day, cap agent loops and tool calls per request, set a hard spending limit at the provider, and alert on unusual spend. Runaway bills in AI-built apps usually come from a key in the front end or an unlimited endpoint that anyone can call.
Controls
| Control | Stops |
|---|---|
| Key server-side only | Strangers using your key directly |
| Sign-in required | Anonymous abuse |
| Per-user daily cap | One account draining the budget |
| Max tokens per request | Huge prompts and responses |
| Agent step limit | Loops that call the model forever |
| Provider spending limit | Everything else, as a backstop |
The standard name
This is LLM10, unbounded consumption, in the OWASP LLM Top 10.
Setting limits in practice
Most model providers let you set a monthly spending limit and usage alerts in the account dashboard; set both before launch, at a level you could absorb if it were reached. In your own code, store a usage counter per user per day and refuse requests past the cap with a clear message. Cap the maximum tokens per response and the maximum length of user input you forward. For agents, cap the number of tool calls and model calls per user request, and stop any loop that exceeds it.
Free trials and free tiers need tighter caps than paid plans, and email verification before AI features become available. Watch for one account creating many sessions, and for usage at odd hours from new accounts. If usage spikes, a kill switch that disables AI features without taking the whole app down is worth having ready.
Getting it checked
TrazTech offers AI and LLM security assessments, listed from $4,000 CAD. Get at least one other quote on the same scope; the questions to ask a testing firm help compare them.
Related questions
Get a scope for your app
Tell us what you built, what it stores and who is about to use it.
Get matchedCommon questions
My key leaked and the bill is huge. What now?
Revoke the key, contact the provider's support about the fraudulent usage, and move calls server-side.
Do free trials make this worse?
Yes. Trial accounts need tighter limits and email verification.