There is a line in the cost model of almost every AI company that was not there when the model was built, and the founders who have found it did so the hard way. Not compute, which everyone plans for. Not the model provider, whose invoice arrives on schedule. The line is fraud and abuse, and it behaves less like a risk to be managed than like a raw material cost that scales with the product’s success. The more capable and more accessible an AI product becomes, the more attractive it is to people who want to extract that capability without paying for it, and every one of those people consumes real inference at real cost while producing no revenue. Stripe has written about how much more fraud AI startups see than the broader market, and the reason is structural rather than bad luck.

The structure is simple. An AI product usually offers a free tier or a trial, because that is how the category acquires customers. It usually exposes an API key, because that is how developers integrate. And every request it serves costs money, because inference is not free the way serving a static page is. Put those three together and you have a product that hands strangers a metered resource and asks them nicely not to take too much. Trial farming, key resale, credit stuffing and chargebacks on high-ticket plans are the predictable result, and they arrive in proportion to how good the product is.

The metric everyone skips

Founders who do track fraud usually track successful fraud: the disputes lost, the refunds issued, the accounts caught and closed. That number is real but it is the smaller one. The larger cost is attempted fraud, because every attempt that gets as far as an inference call has already spent money whether or not it succeeds. A trial account that generates ten thousand tokens of output before being flagged has cost the company those tokens. A scraper hitting a free endpoint has cost the company every response. The metric worth watching is cost per attempted abuse, multiplied by the volume of attempts, and in a product with real inference costs that figure compounds in a way that has no equivalent in traditional software.

This is why the fraud line ends up looking like cost of goods sold rather than like a loss provision. In a conventional SaaS business, a fraudulent signup costs a few cents of hosting and is mostly a nuisance. In an AI business, a fraudulent signup can cost more than a legitimate customer’s monthly payment, and if the abuse is automated it can cost that many times over before anyone notices. A model that prices the product on the assumption that only paying customers consume inference is a model that is wrong by exactly the fraud rate, and the fraud rate is not small.

Make abuse expensive for them and cheap for you

Since the exposure comes from the shape of the product, the most effective defences live in the pricing and packaging rather than in the fraud team. The question to ask of every tier, credit and limit is what it costs an attacker to exploit and what it costs an honest customer to comply with, and the aim is to widen that gap. A free tier that requires a verified payment method before any expensive operation runs loses very few real customers and defeats almost all trial farming at a stroke. Credits that are metered per expensive call rather than per seat make resale unprofitable. Rate limits that step up with account age reward the customers who stay and starve the ones who churn through identities.

A model that prices the product on the assumption that only paying customers consume inference is wrong by exactly the fraud rate, and the fraud rate is not small.

None of these controls need to be felt by a legitimate user, and that is the design test: friction that honest customers never notice and attackers cannot avoid. A verification step at the first high-cost action is invisible to someone who intended to pay anyway. A cap that a real user would take a month to reach is invisible to that user and fatal to a script. The controls that fail are the ones that make the honest path harder in order to make the dishonest path impossible, because they cost customers without changing the economics for anyone determined.

Instrument before you scale spend

The second half of the defence is evidence, and it has to be collected before it is needed rather than after. Chargebacks on AI products are frequently product-not-received disputes, and those are won or lost on whether the company can show that the service was delivered to the person who paid for it. That means logging usage against identity from the first day, keeping the signals that tie a session to a person and a payment method, and storing them in a form that can be produced in a dispute. Stripe’s own analysis of what evidence wins these disputes points at exactly this kind of record, and the companies that lose are usually the ones that had the data and did not keep it.

Velocity signals deserve the same treatment. The pattern of an abusive account looks different from the pattern of a customer almost from the first minute: the speed of requests, the shape of the inputs, the absence of the exploratory behaviour real users show. Those patterns can be caught cheaply if the instrumentation exists, and cannot be caught at all if it does not. A founder about to scale marketing spend should check whether the product can tell the difference between a customer and an attacker before paying to bring in more of both.

A rule and a review

The rule is blunt. If fraud losses are not a line item in the financial model, the model is wrong, and it is wrong in the direction that makes the business look better than it is. Put a number in, even a rough one, and let it be uncomfortable. A margin that survives an honest fraud estimate is a margin that will survive contact with the market. A margin that only works if nobody abuses the product is not a margin at all.

Putting the number in early has a second benefit, which is that it changes what the product team builds. A founder who has seen the fraud line in the model asks different questions at the pricing review, at the free-tier design, at the API launch. The question stops being how do we get more people using this and becomes how do we get more of the right people using this while making it unprofitable for the wrong ones, and that reframing is worth more than any fraud tool the company will later buy.

The review is small. Once a month, two people, an hour: what abuse did we see, what did it cost including the attempts, which control would have stopped it, and what does that do to the pricing. Most AI companies never hold this meeting because fraud is seen as someone else’s department. It is not. It is a unit-economics problem wearing a security costume, and the founders who treat it that way from the start keep margins the rest discover they never had.