Costrails are AI guardrails measured by a second metric: tokens not spent. A guardrail that checks a prompt's scope before it reaches the model, and drops the prompt when it falls outside the application's purpose, does two things at once. It enforces a security boundary, and it prevents an inference call that would otherwise have been billed. Every other AI cost control in use today, from model routing to prompt caching, makes a call cheaper. A scope guardrail is the only one that makes the call not happen. This post explains why that distinction matters more for AI agents than it did for chatbots, shows the math, and lays out how to run guardrails as a cost control without weakening them as a security control.
Key takeaways
- Off-topic and abusive prompts cost exactly what legitimate prompts cost. A model does not discount for irrelevance.
- Agents multiply the stakes. Gartner measures an agentic task at 5 to 30 times the tokens of a chatbot exchange, and predicts inference cost per agentic workflow will rise more than fivefold through 2028 even as token prices fall.
- FinOps tooling optimizes calls that happen. A pre-call scope guardrail eliminates calls that should not, including every retrieval, tool call and re-sent context behind them.
- The check is cheap and the call it prevents is not. A small classifier evaluates a user message for a fraction of a cent; the frontier-model call it blocks costs orders of magnitude more.
- Measure tokens avoided per guardrail and report it next to cache hit rate. A security control that shows up as avoided spend gets funded by the AI program, not the security budget.
- Scope guardrails do not stop an on-topic agent that is spiraling. That needs spend caps and circuit breakers. Scope is the front door, not the whole house.
The $1 Tahoe was the cheap part
In December 2023, a software engineer asked the chatbot on the website of Chevrolet of Watsonville to write a Python script that solves the Navier-Stokes equations for fluid flow. It did. That same week another visitor talked the same bot into agreeing to sell a new Tahoe for one dollar, "no takesies backsies." The Tahoe went viral. The fluid dynamics was the more expensive joke. For a few days, a car dealership was paying to be the internet's free physics tutor, because its assistant was a general-purpose model with a dealership logo on top, and most of what people brought it had nothing to do with cars.
Everyone read that incident as a security story or a brand story. It was also an invoice. In 2023 the invoice was small enough to be funny. It stopped being small when the chatbot became an agent.
Why did AI cost become a CIO problem in 2026?
Three numbers explain the shift.
Agents burn tokens differently. In March 2026, Gartner reported that agentic tasks consume between 5 and 30 times the tokens of a standard chatbot exchange. An agent reasons, calls tools, reads results, and re-sends its entire accumulated context on every step. Stanford's Digital Economy Lab estimated that re-sent context alone accounts for roughly 62 percent of an agent's inference bill.
Cheaper tokens did not mean cheaper AI. On August 17, 2026, Gartner predicted that inference cost per agentic workflow will increase more than fivefold through 2028, even as the price of an individual token keeps falling. Gartner calls this the inference paradox: falling prices tempt teams to build more complex workflows, and the extra consumption swallows the savings.
Budgets broke. The FinOps Foundation's State of FinOps 2026 survey found that 73 percent of organizations exceeded their AI cost projections. Uber, having rolled an AI coding agent out to thousands of engineers, exhausted its entire 2026 budget for those tools by April; its CTO told reporters the company was "back to the drawing board." Gartner separately predicts that more than 40 percent of agentic AI projects will be canceled by the end of 2027, and names escalating cost as one of three reasons.
CIOs responded the way they respond to any runaway line item. They built a discipline around it: usage dashboards, model routing so a cheap model handles the easy ninety percent, prompt caching, per-team budgets. All of it is worth doing. All of it shares one property. It makes each call cheaper. None of it asks whether the call should happen at all.
The customers noticed before the vendors did. Databricks CEO Ali Ghodsi said this year that his company built its AI gateway for security reasons, and that "the main thing people use it for" is putting a budget on it.
What is the difference between a cost optimizer and a costrail?
The first three optimize consumption. The last one prevents it. On a chatbot the difference is one call. On an agent, where a single off-topic prompt can trigger a dozen reasoning steps and tool invocations, the difference is the whole loop.
How do scope guardrails work?
Every mature guardrail stack has the same shape at the front door. A user message arrives. Before it is assembled into a prompt with system instructions, retrieved documents and conversation history, a set of lightweight checks runs against it: prompt injection, sensitive data, restricted keywords, and, in the setting most teams never tune, restricted topics.
A restricted-topics check is typically a small classifier, often a zero-shot natural-language-inference model with a few hundred million parameters, that scores the message against a configured list of allowed and denied topics. It returns in tens of milliseconds. Public cloud providers price the equivalent check at fractions of a cent per text unit. If the message is out of scope, the request is answered with a fixed refusal or handed to a human, and the model is never called.
The economics rest on an asymmetry worth stating plainly. The guardrail inspects the user's question. The model would have processed the entire context. A forty-word customer question is one text unit to a classifier. To the model, the same request is that question plus a system prompt, plus retrieved passages, plus history, often thousands of tokens, and for an agent, that payload is re-sent at every step of the loop.
This is also why "just put stay-on-topic in the system prompt" is not the same control. A system prompt asks the model to police itself and bills you for the asking. A pre-call classifier decides before the meter starts.
The firewall analogy, and exactly where it breaks
The obvious comparison is the firewall, and it is worth following to the point where it stops working. A firewall drops packets that do not belong. For thirty years, nobody put the firewall on the finance team's agenda, because a dropped packet was free anyway. The packet never cost anything to begin with.
That is where AI departs from every network control before it. A dropped prompt is money. The control and the cost lever are the same object, and the security team already owns it.
One professional-services firm built an internal chatbot whose entire job was to answer questions about a single headquarters building. Its security lead's framing was exact: anything off-topic there is already misuse. Scope, in that deployment, is both the threat model and the budget.
What does the math look like?
Assumptions are illustrative and should be replaced with your own traffic data. The structure of the calculation is what matters.
On the chatbot, a costrail pays for itself twenty times over. On the agent, the same control at the same price point returns more than 200 to 1. The saving scales with fan-out, which means the place a scope guardrail earns the most is exactly the place most teams have not deployed one: at the entry to the agent loop, before the first tool call.
Two things the table understates. Blocked prompts also never land in the agent's conversation memory, so they do not inflate the context of every later turn. And the share of out-of-scope traffic is rarely known until it is measured, because without a scope guardrail every prompt looks legitimate on the bill.
How should CIOs and CISOs operationalize costrails?
Three practices, in order.
1. Write scope down as policy and enforce it before the call. Define what the application is for in plain language: the topics it handles, the ones it refuses, the ones it hands to a human. Compile that into a pre-call guardrail, not a paragraph in the system prompt. Review it the way you review firewall rules, on a schedule, with an owner.
2. Measure tokens avoided, per guardrail. For every blocked request, record the tokens the accepted request would have consumed, using the application's own averages. Report the total next to cache hit rate and routing savings on the FinOps dashboard. A control you cannot quantify loses every budget review. One that shows up as avoided spend wins them.
3. Put it in front of the agent, not just the chatbot. Most scope guardrails today sit in front of customer-facing chat. The larger saving, and the larger abuse surface, is the internal agent that calls tools. Place the scope check at the agent's entry point, and consider a second check on tool-call arguments for the tools that cost the most.
The people running these systems already feel this, even when their tooling does not show it to them. A platform lead at a Fortune 500 consumer brand, before enabling a single guardrail, asked how many tokens each rule would consume so he could weigh it against the traffic he expected. A manufacturing CISO reviewing his detection pipeline put it more bluntly: noise costs me money in AWS. Those are the right instincts. Costrails give them a dashboard to land on.
What costrails do not do
A scope guardrail will not catch an agent that is on topic and spiraling: a retrieval loop that never converges, a reasoning model burning thinking tokens on a legitimate task, an adversary who keeps every request in scope while maximizing its cost. OWASP now ranks that failure sixth on its 2026 Top 10 for LLM Applications, under the name unbounded consumption, and the community calls the attack pattern denial of wallet. The controls for it are spend caps, per-session token budgets and circuit breakers that halt an agent whose consumption departs from baseline.
Scope is the front door. Spend caps are the smoke detectors inside. Most of the waste, and most of the abuse, walks through the front door, which is why the cheapest control is also the first one to deploy.
Why this changes which budget pays for guardrails
A security tool competes for a security budget, and agent security is still a small share of enterprise AI spend. A control that measurably lowers the AI program's own run rate gets funded by the program. Costrails do not change what a guardrail is. They change what it is worth, to whom, and who signs for it.
Security has spent twenty years answering the question of what it costs. AI is the first place it can answer the question of what it saved. The cheapest token is the one you never send, and the team that decides which tokens never get sent already works for you.
Next steps
Pillar's runtime guardrails enforce restricted topics, restricted keywords and message-size limits before the model is called, alongside prompt-injection and sensitive-data checks, for chatbots and for AI agents calling tools. If you want to measure how much of your current AI traffic is out of scope, and what it is costing you, we will run that analysis with you in monitor mode on your own applications. Request an evaluation.
FAQs
What are costrails?
Costrails are AI guardrails evaluated on a second metric alongside security: the tokens, and therefore the spend, they prevent by stopping out-of-scope prompts before a model is invoked. The term describes a way of measuring and funding existing guardrails, not a new product category.
Do AI guardrails reduce LLM costs?
Yes, when they run before the model call. A pre-call scope or topic guardrail that blocks an out-of-scope prompt eliminates the entire inference cost of that request, including retrieval, tool calls and re-sent context. Guardrails that run only on model output add cost rather than removing it.
How much do scope guardrails cost to run?
A restricted-topics check typically runs on a small classifier and completes in tens of milliseconds. Public cloud guardrail services price the check at fractions of a cent per text unit, orders of magnitude below the frontier-model call it can prevent.
How is a costrail different from model routing or prompt caching?
Routing and caching reduce the cost of calls that are accepted. A scope guardrail prevents the call entirely. On agents, where one prompt can trigger many reasoning and tool steps, preventing the call saves the whole chain rather than a fraction of one step.
Why do AI agents cost so much more than chatbots?
Agents reason over multiple steps, call tools, and re-send their full accumulated context on each step. Gartner measures agentic tasks at 5 to 30 times the tokens of a chatbot exchange and predicts per-workflow inference cost will rise more than fivefold through 2028.
What is a denial of wallet attack?
A denial of wallet attack drives up a victim's AI inference bill by submitting requests designed to maximize token consumption, without necessarily disrupting service. OWASP classifies it under unbounded consumption, ranked sixth in the 2026 Top 10 for LLM Applications. Scope guardrails reduce the surface; spend caps and circuit breakers address the on-topic case.
Is a system prompt telling the model to stay on topic enough?
No. A system prompt instruction asks the model to police itself after the request has been accepted and billed, and it can be overridden by prompt injection. A pre-call classifier enforces scope before any tokens are spent.
How should we measure guardrail cost savings?
For each blocked request, estimate the tokens the accepted request would have consumed using the application's own averages for input, output and, for agents, steps per task. Sum tokens avoided per guardrail per month and report it alongside routing and caching savings.
Subscribe and get the latest security updates
Back to blog
.webp)
%20(1).webp)


.png)







