The danger is not that enterprises will underuse AI. It’s that they’ll scale usage they cannot explain.
Every enterprise is trying to answer the same question: what marginal value will the next token produce?
As AI adoption scales, token consumption has become one of the few metrics companies can see clearly. But once tokens become the scoreboard, Goodhart’s Law takes over. Usage starts to look like capability.
High usage can mean useful AI work, or waste dressed up as adoption. Low usage can mean the AI became more efficient, or that the obvious use cases never made it into the workflow.
The same token curve can describe opposite realities.
Building @asymptotelabs has given me a front-row seat to how Fortune 500 CIOs and CISOs are confronting enterprise AI adoption. The mandate is real, but the governance model is still being written.
The questions keep coming back to access, data boundaries, agent autonomy, and how to preserve accountability as AI systems start taking actions. The hardest question is value: how do you know whether AI is creating real leverage, not just more activity?
Many teams assumed visibility would improve as AI adoption matured. In my experience selling into large enterprises, the opposite is happening. The deeper AI moves into the stack, the harder it becomes to break down spend, attribute usage, and connect activity to business outcomes.
Enterprise AI adoption is moving in 3 stages. At each stage, token-to-value attribution gets harder: which AI usage created which outcome?
1. Human-in-the-loop AI
Which employee used AI, and did it make their work better?
At this stage, the company can usually identify the user, the tool, and the spend. But it still struggles to understand intent, quality, and outcome.
2. Delegated agents
Who owns the work when execution moves away from the employee?
Agents run in cloud or on-prem environments, act through a delegated identity, and touch systems outside the user’s direct control. Ownership gets harder to trace.
3. Product-embedded AI
How do you measure AI when it becomes part of the product’s behavior?
Model usage now affects product behavior and business performance. Attribution means tying that usage back to the user, workflow, or system that caused it, then understanding what outcome it produced.
I’ve seen teams build surprisingly sophisticated AI systems before they’ve established basic visibility into who or what is generating the activity. In many organizations, governance still assumes a world where every action has a clear human owner.
Agentic systems break that assumption.
That is the visibility gap: enterprises are scaling AI activity faster than they can explain it.
Human-in-the-loop AI
Earlier this year, I got to spend meaningful time with the cybersecurity leadership team of one of the world’s largest financial institutions.
They were rolling out Github Copilot across thousands of engineers, beginning with AI-assisted development inside the IDE. Even at that stage, the conversation was already moving beyond copilots. Before enabling more agentic software development, they were asking the harder question: how do you govern the system once AI moves from suggesting code to executing work?
The first version of this problem shows up in human-in-the-loop AI. A developer asks a coding agent to refactor a service, generate tests, explain a codebase, or summarize a pull request. The workflow still begins with a human, and the control points look familiar: developer identity, coding tool, authentication path, repository, and spend.
That looks like governance, but it’s mostly perimeter visibility. The enterprise can see who used AI, where it showed up, and how much it consumed. What remains invisible is the work itself: whether the system created leverage, introduced risk, or simply generated more activity.
Uber’s COO lamented this month that the company has not yet seen a clear link between higher AI token consumption and more useful consumer-facing features. That is the core measurement gap: enterprises can see AI consumption rising before they can explain what the consumption is actually producing.
The deeper problem is fragmented visibility.
Security teams may see API calls, endpoint events, and alerts. IT teams see access and spend. Engineering leaders see adoption. Finance sees cost. But no one has a normalized view of the agent workflow itself: what the agent was asked to do, which tools it invoked, what systems it touched, and what outcome it produced.
That is where the existing approach breaks down.
Most agent security vendors still rely on closed control points. They see only the activity that crosses their layer, lock telemetry into proprietary schemas, and give enterprises another partial dashboard instead of a source of truth they can own.
At @asymptotelabs, we came to a different conclusion: the telemetry layer for AI agents should be open.
That means:
- Collecting telemetry from native agent environments
- Routing telemetry into the systems enterprises already operate
- Capturing workflow-level context across agent activity
- Normalizing agent traces into a shared enterprise format
- Giving enterprises a source of truth they can audit, compose, and own
That is why we open sourced Agent Beacon: https://github.com/Asymptote-Labs/agent-beacon
Agent Beacon captures telemetry traces from 12+ of the most widely adopted coding and knowledge worker agent harnesses, normalizes their telemetry, and makes it easy for security and IT teams to deploy across the enterprise through MDM and SIEM integrations.
The next frontier is connecting those traces to spend, ownership, and outcomes.
Hosted agents
Hosted agents extend the human-in-the-loop problem into a more distributed environment.
They can run in the cloud, inside an enterprise’s own environment, or inside a 3rd party vendor workflow. They can be triggered by a webhook, a scheduled task, or a one-time human request that turns into background execution. The work can happen without a person actively sitting in the loop, which means the activity no longer maps cleanly back to a human session.
Ramp’s Inspect is a useful example of this future. They showed that companies can already bootstrap a production-grade AI SRE by scaling background agents that investigate problems, take action, and verify their work in the same environment as engineers.
That is powerful, but it makes attribution much trickier.
A recent conversation I shared with the CIO of a unicorn fintech described the hosted-agent gap in practical terms. Enterprises need a unified view across the vendors, cloud environments, and internal systems where hosted agents actually run.
A Cursor cloud agent, a Glean workflow, an internal Bedrock agent, and a scheduled automation using a shared API key can all consume tokens while leaving evidence scattered across spend logs, security systems, vendor dashboards, and service accounts.
The result is a deeper version of the same measurement gap.
At this stage, attribution is about understanding whether autonomous work is behaving as intended. Without that visibility, a spike in token usage could mean a useful automation is scaling, a misconfigured workflow is retrying, an agent is using the wrong model, or an orphaned process is spending money nobody owns.
Agent Beacon started with the simple idea that agent activity should be captured as normalized telemetry, not trapped inside disconnected tools. Asymptote’s managed platform takes that same model beyond the endpoint: ingesting traces from cloud and hosted agent environments, mapping activity back to the agent and workflow that produced it, and attaching ownership and cost context.
Instead of treating each cloud agent, vendor workflow, or API key as a separate visibility problem, the platform turns them into a common telemetry problem. It gives enterprises a shared view of what happened across agents, tools, vendors, and environments, so they can attribute token spend to real activity and start measuring whether that activity created value.
Product-embedded AI
The highest-stakes version of the attribution problem appears when AI directly shapes what the customer experiences.
This includes customer-facing agents, AI features inside SaaS products, production prompt chains, internal workflows tied to customer data, and agentic systems that interact with business-critical infrastructure.
At this point, token consumption is no longer abstract usage. It changes the cost, latency, margin, and risk profile of the product.
A support agent can look magical in a demo, then become expensive when every answer requires retrieval, tool calls, and a long reasoning trace. A summarization feature can quietly damage margins by reprocessing the same data on every request. An expense review agent can turn one approval into receipt parsing, policy checks, and routed decisions.
The product still feels simple to the customer, but underneath it carries the cost and risk of a multi-step AI workflow. This is where attribution becomes a business requirement.
If spend spikes, the company needs to know whether the cause was a feature launch, a customer segment, a model choice, an inefficient prompt flow, or unexpected agent behavior. If latency gets worse, the team needs to know which workflow is responsible. If margins compress, product and finance need to understand whether the AI feature is creating enough value to justify its cost. If risk increases, security needs to understand what data and tools were involved.
This is the final step in the progression. Human-in-the-loop AI creates an attribution gap around employee productivity. Hosted agents create an attribution gap around ownership and automation. Product-embedded AI creates an attribution gap around the business itself.
At @asymptotelabs, we believe every enterprise will need a system of record for agentic work. Enterprises should be able to trace AI consumption back to the work that created it: what started the action, what systems it touched, what it cost, what it produced, and whether the outcome was worth it.
Agent Beacon is our bet that agent activity will become core enterprise infrastructure. The telemetry layer has to be open, normalized, and owned by the enterprise, because the next generation of AI governance will depend on knowing what agents actually did before deciding what they should be allowed to do next.
The companies that win with AI will not be the ones that consume the most tokens. They will be the ones that can explain which AI work actually mattered.