The line item that grew up overnight.
Twelve months ago AI spend was a footnote. Now it's the fastest-growing line on your P&L, with the loosest controls. Flowstate gives you the tools to take it back — set the rules, watch what's happening, and stop the leaks before they leak.
The same conversation, in every boardroom we sit in.
Lightly anonymised, from a year of CFO and CTO conversations.
I have no visibility into where AI investment is actually going — or whether it’s working.
I would pay anything to know AI costs per project, and what an investment would unlock.
Controlling our AI spend is one of the greatest challenges we have to solve.
We’re wasting millions by not optimising where AI spend goes and how we deploy it.
One project. Four questions. Four answers.
Take the Video Generation feature your team shipped in March. Twelve weeks of build. Three engineers. £12,150$15,300 of OpenAI tokens to prove the architecture. Here’s how Flowstate answers each of the questions a CFO would ask about it.
"Whose tokens were these?"
The OpenAI invoice says £12,150$15,300. The provider can tell you it hit one API key. Beyond that, it’s guesswork — until each request is tied back to a person, a service and a project.
"Is any of this capitalisable?"
Video Generation was in development phase for the whole twelve weeks. That means the £12,150$15,300 isn’t just OpEx — most of it is capitalisable, and a chunk of that qualifies for R&D tax relief. Flowstate splits it automatically because we already know the project stage.
"What’s it going to cost when this scales?"
Now Video Generation is live. Adoption is climbing. There’s no seat-based ceiling like Copilot used to give you — production AI scales with traffic. Your CFO needs a number for the next board meeting.
"How do we stop the leaks before they leak?"
Visibility is the start. Real control means policy you can write down, enforcement that fires when it’s breached, and a graduated response — a quiet nudge first, a manager surfacing later, an evidence pack only if it escalates.
What you actually get
Concrete controls you can wire up. Pick what fits your culture; layer the rest as you grow into it.
Guidelines
Soft, educational nudges. Recommended models, suggested providers, healthy budget norms. The polite first conversation, not a block.
Policies
Hard rules with owners and version history. Approved models, per-team caps, allowed providers per service, capitalisation rules per project stage. Versioned, audited, exportable.
Activity log
Every AI session, every API call, every policy decision — recorded, searchable, filterable, exportable. The audit trail you’d want to hand to a board or a tax investigator.
Alerting
Real-time alerts to Slack, email or your incident channel. Policy violations, anomalous usage, budget drift, unit-cost ceilings being breached.
Budget cut-off
Hard ceilings per person, team, project or service. When spend hits the cap, requests stop. Soft caps too.
Auto banning
Repeat policy violations trigger temporary suspension. Manager surfacing. Manual unblock.
Key revocation
One-click rotation or kill. Compromised key revoked across the whole stack in seconds.
Anomaly response
Service identity verification — if a chatbot key starts being used for something else, the request is rejected.
One model, two faces of AI spend
Developer AI and production AI look different on the surface. The economic questions are the same, so the model should be too.
Claude Code, Cursor, Copilot, Windsurf. The questions are about projects, productivity, and which engineer is suddenly spending £4k$5k a month on Claude.
Chatbots, document extractors, video pipelines. The questions are about contribution margin per customer action, and why your OpenAI bill doubled in May.
How the data lands
Three ways to bring AI activity into Flowstate. Pick the ones that fit how your org works — you don’t need all three to start.
Provider integrations
Direct billing & usage from each AI provider. Reconciled nightly. Nothing to install.
Open-source telemetry
Lightweight CLI you push via Homebrew or your MDM. Detects whichever AI tools your engineers run. Sends features back — never source code.
Stop spend in flight
For services and teams where policy needs to fire mid-request — rate limits, model substitution, mid-session caps, hard cut-offs. Optional.
Your contracts, your keys, your data
An insight and policy layer — not a reseller, not a billing middleman.
No vendor lock-in
Your provider contracts stay yours. Change vendors whenever — Flowstate picks up the new one through the same integrations.
No billing intermediation
Your Anthropic invoice still comes from Anthropic. Your OpenAI invoice still comes from OpenAI. We don’t touch the money.
Prompts stay private
We hold metrics and attribution. Prompt and response bodies are processed in memory and discarded — they never persist on our infrastructure.
Stop flying blind. Then stop the leaks.
Book a demo and see exactly where your AI budget is going — across developer AI and production AI — and what you can actually do about it.