HomeArticle

Long-established foreign software vendors have started to charge toll fees.

王智远2026-09-18 11:35
Collect rent when the door is closed, and also collect rent when the door is open.

I'd like to start with a statistic:

On average, each enterprise currently runs more than 12 AI agents. Half of these agents operate independently, with no connection to one another. Many companies don't even have a clear record of the names of these agents, isn't that chaotic?

It is definitely a total mess, but established vendors have divided the market into two distinct camps.

The first camp is SAP.

In April this year, SAP revised its API policy. In short, external AI agents are not allowed to call SAP interfaces directly, no matter for independent planning or independent execution. If they want to run workloads on the platform, they must go through its native assistant Joule.

On June 9, security patches were rolled out to block non-compliant calls directly at the technical level. Bypassing approaches such as proxy servers, gateways, custom code, and identity spoofing are all blocked as well.

At the same time, its integration gateway started charging based on the number of calls, which is referred to by industry insiders as the "agent tax". In addition, the free access period for Joule Studio only lasts until the end of this year, and the charging rules for next year have not been announced yet.

It can make such a move because it holds unique resources that no other competitor has: 50 years of financial, supply chain, and procurement data stored in customer systems, and the cost of switching to another vendor is calculated on an annual basis.

At its Sapphire conference, it launched more than 200 agents and over 50 assistants at one go.

But it also faces its own difficulties. In February, DSAG, the German-speaking user group, conducted a survey showing that only 3% of customers use SAP's native AI in production environments.

Among enterprises that have deployed AI, 77% use third-party tools such as Microsoft Copilot. SAP raised objections to the sample size of the survey, but its policy tightening in April came only two months after the survey was released.

The other side of this policy is migration.

Support for SAP's legacy system ECC will expire at the end of 2027. More than 10,000 customers who have not completed migration now have to face both system migration and AI migration on the same timeline, which is fully scheduled by SAP.

The second camp is Salesforce.

Its approach is completely the opposite. It made a decision two years ago, officially described as "rebuilding Salesforce for agents". The promise was fulfilled in April this year: all capabilities on the entire Salesforce platform have been converted into APIs, MCP tools and command lines, adding up to more than 60 tools and over 30 skills.

Executives made a bold statement: why would you need to log in to Salesforce at all in the future?

The result is that a salesperson can complete the entire workflow without opening the CRM. By sending one message in Slack to query customer information, update business opportunities, and check the pipeline, all tasks can be done in the conversation, and the CRM will run in the background to support the work.

According to official data, the number of custom agents mounted on Slack has tripled since January.

ServiceNow, which provides IT service desk solutions, has also opened up all the processes, approvals, and directories it has accumulated over 20 years to external agents, so that any vendor's agent can perform these operations on behalf of customers.

It dares to open all these permissions because 89% of the problems on its customer service desk have already been handled by AI autonomously.

Google is even more thorough. The A2A protocol was initiated by it, and its enterprise AI products are simply positioned as "the new front door for workplace AI". KPMG is the fastest-adopting customer, with 90% of its employees using the product, and more than 100 agents built in the first month.

Atlassian, the owner of Jira, has also opened the interface of its knowledge graph, with support for command lines and MCP.

Workday, the HR software provider, stands in the middle of the two camps. On one hand, it strictly manages customers' human resources data, and on the other hand, it spent 1.1 billion US dollars to acquire Sana, an AI interface company, to build the first interface that employees open every day.

Microsoft is a separate case that covers both sides. It is not only an access point but also an established vendor itself, with more than 30 million paid seats for Copilot alone.

The confidence of both sides comes from their customer base. SAP dares to tighten its policy because it is confident that customers cannot easily switch away; Salesforce dares to open all permissions because the cost of switching to another CRM is far less prohibitive than switching to a new ERP.

Therefore, vendors with locked-in customers collect rents, while vendors with easy-to-switch customers open their platforms to the public.

......

The two approaches are respectively loosening and tightening, but after reviewing their moves in the past six months, I found that they are heading in the same direction. What is that direction? I'll put the answer here first: it is the same business, helping enterprises manage their agents well.

Agents have already been deployed in enterprises to handle real work, but the supporting tools to manage them are not yet fully prepared.

There is a set of statistics that caught my attention when I reviewed related materials:

72% of global enterprises believe that they have a clear grasp of AI management. But when asked a simple question "how much did your agents spend this week", very few can give a definite answer.

Only 13% of enterprises claim that their AI governance is fully in place. According to another survey, 60% of enterprises build AI tools and processes without going through the IT department. There is even a company that ran more than 900 agents in less than a year before realizing it needed to set up a dedicated governance committee.

If agents cannot be managed well, there will be demand for dedicated management services, and this is where the business starts.

Microsoft is the first to make this business widely known. It launched a set of management services for agents called Agent 365, priced at 15 USD per user per month.

What it manages includes: the identity of the agent, what tasks it is allowed to access, what operations it has performed, and whether it has violated compliance rules.

Two months after this service was launched, nearly 40 million agents from various enterprises have been registered on the platform, and more than 500,000 agents are running inside Microsoft itself.

Some people have summed up this business very clearly: governance is product. What you pay for is not the software itself, but the right to "know exactly what your agents are doing".

ServiceNow uses a more granular charging method, which is calculated by each operation.

When any external agent comes to handle tasks on behalf of customers, every step must pass through its "control tower", and each pass through the tower is counted as one operation called assist. This tower was originally built to manage its own internal operations, and now it has been expanded to manage "any AI in any system".

Its official statement is quite bold:

Other vendors only let agents read and write data, but we let agents perform operations under full governance. Some observers checked its latest quarterly financial report and found that half of its new orders are no longer priced by the number of users. It currently has 8,400 enterprise customers with a 98% renewal rate.

Workday even posted its price list publicly, with the billing unit called point. Checking for missing entries in the payroll costs 5 points, screening resumes costs 6 points, and one round of talent recruitment costs 750 points. Users need to contact the sales team to buy additional points after using up the quota, and the unit price of points is not publicly disclosed.

The first batch of customers that got the quota include Accenture, Nike, and Merck. On its platform, 1.7 billion AI operations were performed in the last fiscal year.

For Salesforce, in addition to the detailed pricing table calculated by each operation (about 0.1 USD per operation), it has also built a dedicated governance console. When multiple agents from different vendors work together, their collaboration rules, approval requirements, and accountability mechanisms for incidents are all managed on this console.

Google is more straightforward. From July to September this year, four services on its agent platform started charging one after another: skill registration, agent gateway, memory base, and session service.

There is another item on the list called "semantic governance policy". Starting from August 1, governance itself has a clear price tag.

Atlassian follows the same rule. Starting from December 3, any user that uses its context data to train its own AI will be billed by points, and the over-limit usage is priced at 1 cent per point. These two vendors always advocate "openness", but they have started to charge for access at the entrance of their open platforms.

SAP's "agent tax" follows the same logic: operations passing through its gateway are charged by the number of calls.

It is easy to see that the rules for managing agents and the price list for charging are the same set of systems. The names of these charges are getting more and more obscure, but the core operation is the same: all operations must go through my gateway and be recorded in my bill.

The gateway manager also takes charge of billing. Since he controls the entrance, he knows exactly who comes in and how many agents are running, so it is natural for him to collect the fees.

An English-language institution that specializes in "non-human identity" research pointed out: pricing design is inherently part of access governance. In plain terms, the way you charge is the way you manage agents.

Therefore, despite the fierce verbal disputes between the two camps, what they are all busy with is the same thing: taking full control of the identity, permissions, operation logs, and billing records of agents.

Some people estimate that by 2030, 40% of the revenue of enterprise software will be charged based on usage, operations, and results. The profit pool is shifting from the low-margin "intelligence" service to the scarce "governance" service.

......

Next, unexpected bills start to come to enterprises, and the first abnormality is that the figures do not match expectations.

Among the customers of Zendesk, a customer service software provider, some users did not know that the over-limit usage had been silently charged for a long time until they checked their bills. Where did this extra fee come from?

It starts with the billing method:

In the past, when you bought a software license, you paid a fixed monthly fee for a specified number of users, and you did not need to worry about extra costs after signing the contract. Now, the new price lists of all vendors are tied to usage, operations, and even results. Every completed task will generate a corresponding billing record.

There is a clear threshold on each price list: operations within the threshold are included in the monthly fee, and operations exceeding the threshold will be charged separately. The more agents deployed in the enterprise, the faster the billing meter runs. The last time the accounting system was completely changed in this way was when cloud services became popular.

Most of the detailed rules for these calculations are not written in the contract. Only the monthly fee and the number of users are stated on paper, and all the variable parts are stored in the vendor's internal documents. The price will be adjusted once the document is revised, and no negotiation with customers is required.

I saw in a survey that:

78% of IT leaders have encountered unexpected bills, and 61% of them have cut projects due to unplanned software expenses. On the development platform GitHub, the price of a model was adjusted from 7.5 times the base price to 27 times within two months, and users noticed the abnormality first from their bills.

The most annoying part is not the price increase, but that no one notifies you before the price is adjusted.

Some people call this model "enclosure first, harvesting later": vendors give free quotas and discounts in the first two years, and gradually tighten the policy after users get used to the product. This statement is not completely unfair. After the market is fully occupied, every new agent deployed will come with its own price tag.

The second abnormality is the growth pattern of the bill.

Intercom, a customer service chatbot provider, charges 0.99 USD per ticket, and the fee is only collected after the problem is resolved. 76% of the problems it receives can be handled automatically by itself.

The more tasks it completes for you, the more billing records it generates. If it stops working one day, it will not make any money that day.

It seems that buyers get a great deal: 0.99 USD per task is much cheaper than hiring a human employee. But there are two separate sets of accounts: you calculate how much labor cost you have saved, while it counts how many paid tasks it has completed. The more capable it is, the more dependent you are on it, and the more billing records you will get.

Traditional software sells tools, and you know the exact price before purchasing. The new model sells the completed tasks, and no one knows the total workload before you start using it. The bill has no calculation errors, but the total amount is always higher than you expected. The money you saved from labor is collected back through the bill.

There are even more staggering figures: some companies' monthly AI bills have reached 500 million USD, and some developers spent more than 80,000 USD in one week. The scary high bill is usually not caused by a single wrong payment, but the superposition of a large number of small operations.

Nearly half of the companies have slowed down their AI projects due to high AI costs. Looking further ahead, some people estimate that by 2028, the cost of using AI to write code will exceed the salary of a human developer.

Buyers have started to fight back. The most direct countermeasure is to change the billing method: charge only after the task is successfully completed, and no fee is charged if the task fails.

HubSpot, a marketing software provider, has publicly announced this rule. Intercom has achieved hundreds of millions of USD in revenue with this billing model, and it was acquired by Salesforce for 3.6 billion USD this month. Sierra, a customer service agent provider, bills based on results and has reached 200 million USD in revenue.

Zendesk uses a more practical rule: after the problem is marked as resolved, it will wait for 72 hours, and the bill will be generated only after an independent model verifies that the problem is indeed fixed. Intercom also promised a full refund for new customers who are not satisfied with the product within 90 days.

Changing the billing method alone is not enough. The bill must also be fully transparent.

Buyers' requirement is very straightforward: they don't mind paying a higher price, but the bill must be fully consistent with the actual usage. Nearly 30% of companies cannot clearly tell where their AI spending goes.

Some people have started to set usage caps and allocate billing responsibilities to different departments. Some engineers at Netflix have even open-sourced a dedicated tool to strictly monitor AI spending.

In the Chinese industry, Hu Yanping pointed out that the same amount of usage does not mean the same value, which hits the soft spot of usage-based billing: the volume is easy to count, but the value is hard to measure. Buyers can also switch vendors: if the rules are not clearly stated, they will choose another vendor in the next order. More than half of the enterprises plan to replace or add new AI vendors within one year.

The last remaining question is: who should this bill be charged to? Vendors' billing meters are still running, and buyers are also installing their own meters.

Neither side has loosened their stance or made a complete statement. This tug-of-war is not only reflected in the bills, but also in the contracts. The party that first clearly defines the standard for "whether the service is worth the price" will set the price rules for the next round.

Many participants are already testing the operation model of this business. So far, the first half of the model has been implemented: the meters are installed, and the billing process has started. The second half is still uncertain: will the charging process go smoothly? Will the buyers accept the fees? The answer will be revealed in the next two years.

Data sources:

[1].