AI threat catalogueAttacks on the Running Model and ServiceProduction
Cost Harvesting / Repurposing
Attackers use a company's paid AI services without authorisation and at its expense, for example with stolen access keys. The costs and the load fall on the owner.
Description
Paid AI services are billed by usage. Attackers gain access to the account or the API key, for example through stolen credentials or keys accidentally published in code, and run their own workloads through it. Reselling the access to third parties via an intermediary proxy is also common. One variant aims solely at driving up costs through massive usage (denial of wallet). Unlike a pure overload attack, the goal is co-opting the service at someone else's expense or causing financial harm, not an outage.
Possible impact
The company faces unexpected and sometimes substantial cloud and compute costs. The unauthorised access may also violate terms of use or be misused to generate harmful content, which is charged back to the owner's account. Finances, operations and, indirectly, reputation are affected.
Example
A developer accidentally uploads an API key to a public code repository. Within hours strangers use the key to run their own requests through the company's AI service; at the end of the month the bill runs to several thousand euros.
Recommended mitigations (5)
Every mitigation states its control type, effect, implementation level and the reason for the classification.
API key rotation and secrets managementTechnical
- Effect
- Preventive
- Implementation level
- Application, API & agents, Infrastructure
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “API key rotation and secrets management” is primarily technical: Machine-enforced identity, permission, or scope rules constrain unauthorized access and actions; complemented by binding workflows.
Usage anomaly detectionTechnical
- Effect
- Detective
- Implementation level
- Application, API & agents, Use & operations
- Reason for the classification
- “Usage anomaly detection” is primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators.
Spending limits and alertsTechnical
- Effect
- Preventive, Detective, Impact-limiting
- Implementation level
- Application, API & agents, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Spending limits and alerts” is primarily technical: Automated resource controls, budget limits, or runtime boundaries constrain overload, abuse, cost, and cascading failures; complemented by binding workflows.
IP allowlistingTechnical
- Effect
- Preventive
- Implementation level
- Application, API & agents, Infrastructure
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “IP allowlisting” is primarily technical: Machine-enforced identity, permission, or scope rules constrain unauthorized access and actions; complemented by binding workflows.
Audit logs for API usageTechnical
- Effect
- Detective
- Implementation level
- Application, API & agents, Use & operations
- Complementary control type
- Organizational & process-based
- Reason for the classification
- “Audit logs for API usage” is primarily technical: Software or analytical tools systematically produce and evaluate measurements, deviations, or attack indicators; complemented by binding workflows.
Framework mappings
Verified locations in OWASP, NIST AI RMF, MITRE ATLAS, the EU AI Act and further frameworks. The mappings are taxonomic, not evidence of compliance.
Verified references (5)
Every reference states the framework, the exact location and the publishing organisation.
- OWASP LLM Top 10 LLM10:2025 Unbounded ConsumptionLLM10:2025 Unbounded Consumption, official category page OWASP FoundationOriginal
- MITRE ATLAS AML.T0034 Cost HarvestingATLAS.yaml technique object with id AML.T0034 (pinned release v5.6.0) MITREOriginal
- EU AI Act Article 26(5) Obligations of deployers of high-risk AI systemsArticle 26(5) European Union (EUR-Lex)Original
- EU AI Act Article 55(1)(d) Obligations of providers of general-purpose AI models with systemic riskArticle 55(1)(d) European Union (EUR-Lex)Original
- EU AI Act Article 9(1), 9(2)(a), 9(2)(d) Risk management systemArticle 9(1), 9(2)(a), 9(2)(d), read with Article 9(3) European Union (EUR-Lex)Original
Related threats
More entries from the topic group Attacks on the Running Model and Service.
Assess this threat in your own system
The live demo contains all 52 threats of this catalogue, including the EU AI Act and GDPR assessment. The free single modules cover AI risk, the EU AI Act and GDPR. No sign-up; the assessment runs locally in your browser.
Cite this entry
For reports, policies or internal documents; the link leads directly to this entry.
“Cost Harvesting / Repurposing”. Versatile AI Risk Assessment, AI threat catalogue, as of July 2026. https://www.versatile-ai-risk-assessment.com/en/wissensbasis/threats/cost-harvesting/