One Microsoft employee reportedly logged $28,000 of AI usage in 28 days. Learn why AI governance starts with visibility, ownership and oversight.

01

The bigger question is visibility

Recent reporting described a voluntary internal spreadsheet in which roughly 350 Microsoft employees shared estimates of the AI resources they had used over 28 days. The median reported value was around $300. The highest entry was approximately $28,000.

Those figures were self-reported and came from a small, voluntary group. They are not representative of Microsoft's workforce. The highest figure also does not mean an employee personally bought $28,000 of subscriptions. It was an estimate of computing resources consumed through workplace AI tools.

The useful business question is simpler: if one employee in your organisation suddenly became a very heavy AI user, would management know which system they were using, what business task it supported, what data was involved, who owned the use case and whether the output was being reviewed?

02

'Use AI' is not an AI policy

Telling employees to experiment with AI can encourage useful innovation. It can also create invisible activity if there are no practical boundaries around that instruction.

A workable AI policy does not need to stop experimentation. It should make the important questions visible.

  • Which AI tools are approved?
  • Which business purposes are permitted?
  • What company, customer or employee information may be entered?
  • Who is responsible for each use case?
  • When must an output be checked by a person?
  • Can the organisation see unusual usage, cost or risk patterns?
03

Compliance starts with knowing what AI you use

The EU AI Act does not require businesses to impose token budgets, set AI spending caps or use a particular inventory format. Those can still be sensible internal controls.

Article 4 requires providers and deployers to take measures supporting the development of AI literacy among relevant staff. In its practical guidance, the European Commission starts with a basic question: what AI is used in our organisation?

A short AI register can connect technology, purpose, ownership, data, risk and cost without turning governance into a large documentation exercise.

Example AI register
AI systemBusiness useOwnerData allowedRisk / reviewCost visibility
ChatGPTResearch and draftingMarketingApproved business informationHuman verificationYes
Microsoft CopilotProductivityOperationsApproved Microsoft 365 dataStandard controlsYes
Recruitment AICandidate screeningHRPersonal dataHigher-risk review requiredYes
04

Cost controls can be governance controls too

Usage monitoring is not only a finance issue. A sharp increase in AI consumption may reveal a new workflow, a poorly configured process, an employee using an unapproved tool or a task that has become operationally dependent on AI.

A sensible response is proportionate: define approved access, assign owners, review unusual usage and give staff a clear route to ask for new tools or higher limits. The aim is not to monitor every prompt. It is to prevent important AI activity from becoming invisible.

05

The SME lesson

A 25-person company may not generate a $28,000 AI usage entry. It can still face the same governance problem on a smaller scale: several subscriptions, overlapping tools, unclear data handling and no single view of which systems influence work.

The headline number is memorable. The practical lesson is more valuable. Useful AI governance begins when a business can explain what AI it uses, why it uses it, who is responsible and how important outputs are checked.

S

Sources

Primary and authoritative sources used for this Insight.

  1. Business Insider: Microsoft employees reveal how much cash they're burning on AI, 24 August 2026
  2. TNW: Microsoft employees' AI spend spreadsheet, 26 August 2026
  3. European Commission: AI literacy questions and answers
  4. European Commission: AI talent, skills and literacy
  5. Regulation (EU) 2024/1689, current consolidated EU AI Act
Share this Insight