The CFO-CIO Reality Check: Governing DevSecOps and AI Costs

The CFO-CIO Reality Check: Governing DevSecOps and AI Costs

Enterprise leaders are seeking greater visibility into AI workflows and consumption as usage-based costs make technology spending harder to predict. Image: Generated by ChatGPT

CIOs and CFOs face rising AI costs, DevSecOps tool sprawl, and software supply chain risk. Learn how to strengthen oversight, cost controls, and ROI.

Written By
Zeus Kerravala
Zeus Kerravala
Sep 21, 2026

Highlights from SwampUP on how tool sprawl, supply chain risk, and surging AI token costs are compelling CIOs and CFOs to rewrite the enterprise technology playbook.

Enterprise AI costs are becoming harder to predict just as technology leaders face pressure to simplify sprawling development and security stacks.

At JFrog’s SwampUP conference, I joined JFrog CFO Ed Grabscheid for a fireside chat about maintaining software delivery speed while controlling DevSecOps spending, software supply chain risk, and rising AI consumption costs.

For CIOs and CFOs, the challenge is no longer simply approving new technology. They need shared measurements that show whether development tools and AI services improve delivery speed, reduce risk, or produce measurable business value.

I’ve spent 25 years as an industry analyst — and before that, I sat in the CIO chair. I can tell you that the relationship between finance and technology has never been more critical or more misunderstood. Here is my take on what happened, where the industry is headed, and what IT leaders need to do now to avoid flying blind.

Tool Sprawl Is a TCO Trap—Not Just a License Expense

When finance teams review technology budgets,tool sprawl is often one of the first things on their radar. Seeing five renewals across the team that appear to do the same thing makes line-item cuts seem like a no-brainer. But as Grabscheid rightly pointed out, tool sprawl doesn’t stem from reckless spending. “You have to understand why you have tool sprawl,” he told the audience. “It’s not one bad decision. It’s a series of 5, 10, maybe 20 very reasonable, reliable, and justified decisions. However, finance, procurement, and the office of the CFO see this layering effect on costs.”

The hidden killer of point-tool sprawl isn’t just software licensing costs but the massive operational drag. When developers spend their days context-switching between fragmented tools and managing custom integrations, remediation stalls. That’s why enterprise Mean-Time-To-Remediate (MTTR) for critical CVEs remains stuck in the unacceptable 30-to-60-day window.

One key discussion point is how IT leaders can distinguish real consolidation from fake consolidation. Beware of the P&L shell game. “Fake” consolidation cuts SaaS licenses by 20% but forces you to spend a fortune on custom API work, professional services, or hidden cloud infrastructure fees. Effective consolidation should reduce total operating costs, simplify workflows, and improve remediation times. If license savings are offset by integration work, professional services, or additional infrastructure, the organization may have shifted costs rather than eliminated them.

Advertisement

Supply Chain Security Requires Boardroom Rationality

Software supply chain attacks have captured the board’s full attention. But if you think that means a blank check for security tools, think again. Budgets aren’t necessarily easier to secure; they are being scrutinized under a magnifying glass. “Predicting risk is a bit of a guessing game,” Grabscheid observed. “From a finance perspective, we look at outcomes… It’s about bringing scenarios to the board with reason and rationality so they can make informed decisions.”

In my research at ZK Research, 80% of CIOs rank supply chain integrity among the top three enterprise risks—yet only 30% have automated, binary-level protection in place at ingestion. That gap is staggering. To close it, CISOs must stop relying on fear-based insurance pitches. Show the board how securing the software supply chain at ingestion automates risk out of the pipeline without slowing developers. When done right, security stops being the “Department of No” and becomes an operational accelerator.

The AI Reality Check: Managing the “Utility Bill”

The most active part of our discussion focused on the shift in AI economics, also known as “tokenomics.” Heading into 2026, most organizations budgeted for AI tools like traditional SaaS—predictable per-seat costs of about $50 to $100 per head.

Instead, high usage intensity turned AI spend into an unpredictable utility bill, with some teams blowing past forecasts and hitting $1,000+ per developer. “What happened in AI… was this AI utility and an intensity of usage,” Grabscheid explained. “In the first half of the year, the mandate was: ‘Run as fast as you can adopt.’ Now we’re living with the reality of figuring out how to offset that… It’s about building discipline.” This utility model reminds me of AWS’s early days. Everyone rushed into the cloud, loved the agility, and then faced sticker shock when the bill arrived. AI is going through the same maturity curve.

Advertisement

My Advice for Enterprise Tech Leaders

If you want to maintain innovation velocity while keeping your CFO from pulling his hair out, here is where you need to focus over the next 12 months:

  1. Drive “Showback” Before You Enforce “Chargeback”

Forcing direct departmental chargebacks right now often backfires, prompting managers to artificially restrict AI access and undermine productivity gains. Start with Showback. Build API proxy layers and FinOps dashboards that show engineering leads exactly how much their team’s prompts, agent tasks, and pull requests cost. Transparency changes behavior faster than mandates.

  1. Use Intelligent Caps to Force Architectural Maturity

Granting developers unlimited access to flagship LLMs for every minor task is like driving a Ferrari to cross the street. As one engineering leader noted during our Q&A, implementing intelligent usage caps didn’t stall work—it forced teams to innovate. Developers began routing simple tasks to smaller, fine-tuned, or on-premises models, reserving high-cost tokens for complex problems.

  1. Track Token Cost by Workflow, Not Just Headcount

Stop measuring AI spend solely by developer seats. Forward-thinking enterprise teams tag API usage at the pipeline level—tracking total token cost from requirement spec through pull request to build. Allocate 80% of your AI spend to core, structured workflows and reserve 20% for personal developer experimentation.

The Bottom Line

As we head into 2027 planning, boardrooms will no longer accept developer adoption metrics or token usage as proof of success. High token spend only shows activity; it doesn’t prove an outcome. “ROI isn’t just about how many people are using a tool,” Ed concluded. “The real ROI is tying that to top-line outcomes—driving product releases, faster time-to-market, and ARR growth.”

For CIOs and CFOs, the next step is not simply to cut tools or restrict AI access. It is to establish shared measurements for software delivery speed, security outcomes, and AI consumption, then use those measurements to decide where consolidation or spending limits would help. Organizations that can connect technology costs to faster releases, lower operational risk, or measurable revenue gains will be better prepared to defend their budgets during 2027 planning.

Read more: AI agent cloud costs are making enterprise budgets harder to predict, underscoring why IT and finance teams need workflow-level visibility as token consumption becomes more variable.

Zeus Kerravala

Zeus Kerravala is an eWEEK regular contributor and the founder and principal analyst with ZK Research. He spent 10 years at Yankee Group and prior to that held a number of corporate IT positions. Kerravala is considered one of the top 10 IT analysts in the world by Apollo Research, which evaluated 3,960 technology analysts and their individual press coverage metrics.