Skip to main content
    All shows

    CFO Daily · Saturday, September 19 · 6 min

    CFO Daily · Saturday, September 19, 2026

    0:00-:--
    Speed

    Transcript

    Hi, this is Koko from Koko Knows.

    Let's get right into it, because there's a number out today that should change how you think about your AI risk exposure. Deloitte's newest UK survey found that one in three employees using generative AI at work are doing it without their employer knowing. Sixty-three percent have used it at work regardless of what policy says. Read that twice. That means the licenses you've approved, the pilots your IT team is tracking, the spend you're reviewing in your AI budget line — none of that captures the real footprint of AI use inside your company. Adoption isn't the gap anymore. Visibility is.

    And here's what makes today interesting: that finding landed the same day Neo4j's chief scientist, Jim Webber, made a related point about cost. His argument is that when finance teams respond to token shock by capping prompt length or setting per-seat limits, you're not fixing the spend problem, you're just degrading the output and hiding the bill. The real driver of high token costs is usually poor context architecture forcing the model to work harder for the same answer. Put those two stories together and you get a clean read on where the actual governance gap sits right now. It's not adoption, and it's not raw spend. It's the fact that usage, cost, and context are all diverging from what your policies assume is happening.

    So here's what I'd do with that today. Don't run a token-cost review in isolation. Pair it with an actual usage audit — not a spend audit, a usage audit — because the risk living outside your sanctioned tools is completely invisible to anything that only looks at the invoice. And when you do sit down with IT on the token-cost conversation, ask about context architecture before you ask about usage caps. If they can't tell you why the model needs that many tokens to answer a routine query, capping the query isn't a fix, it's a bandage.

    Now, three infrastructure stories worth knowing where you sit, even if they're once removed from your immediate to-do list. Nscale filed to go public — another AI-infrastructure name testing whether public markets will pay growth-stage multiples for capital-intensive AI buildouts. Crusoe raised three point nine billion dollars at a thirty point nine billion dollar valuation for data centers, and notably added a sitting Cloudflare CFO to its board. That's a signal the financing window for AI infrastructure is still wide open, even with this week's noise around agent safety incidents. If you're evaluating exposure to this space through treasury or corp-dev, take it as confirmation capital is still flowing, not as a cue to chase valuations.

    And EQT is backing a two-billion-dollar push into small battery capacity specifically to speed grid connections for data centers. That one's worth sitting with for a second, because it tells you the binding constraint on AI buildouts is shifting from chip supply to power access. If your company has any capital riding on AI infrastructure, model energy-access timelines into the case, not just compute cost. Power, not chips, is becoming the thing that determines when these projects actually go live.

    One more thing I want to flag for your board conversations, because it connects to the shadow-AI story. Every major frontier lab — OpenAI, Anthropic, Meta, and now Google — has disclosed an agent security failure during testing this year. That's not a vendor-selection problem anymore. You can't solve it by picking the "safe" lab, because there isn't one with a clean record. Before you approve the next agent deployment, ask your CIO which of your vendors' models were involved in incidents this year and what contractual protection you actually have if it happens on your systems. That question belongs in the same conversation as your usage audit, because agentic tools are exactly where shadow use and security exposure start to overlap.

    And if you're negotiating renewals soon, know that Anthropic and Accenture are each putting over a billion dollars into independent model evaluation. That's a real signal that oversight infrastructure is becoming its own cost category industry-wide. If your vendors can't show comparable investment in evaluation, price that gap into your risk assessment now, because it's going to show up in licensing terms eventually anyway.

    So today, three things worth carrying into your next meeting: run a usage audit alongside any token-cost review, ask IT about context before you ask about caps, and get a straight answer from your CIO on agent-incident exposure before the next deployment gets signed off.

    That's your rundown. Thanks for listening, this has been Koko Knows.