There are two ways an AI project costs more than the number on the proposal. One is the vendor's pricing model — the estimate that becomes a meter, which we covered in Bait-and-Bill. The other is entirely your own side of the ledger, and it's the one nobody quotes because no vendor can.
These are the seven internal costs that reliably surprise people. None of them are anyone's fault. All of them are predictable, which means all of them are budgetable.
1. Your own team's time
The largest hidden line, by a wide margin. Any real AI build consumes your people: subject-matter experts explaining the workflow and its exceptions, IT provisioning access, a data person answering questions about tables nobody documented, and someone senior making decisions.
Budget 10–20% of a technical person's time and a meaningful share of one domain expert's for the duration. On a 90-day build that's real money, and it comes out of work those people were otherwise doing. Vendors don't quote it because they can't, and buyers don't count it because it isn't cash leaving the building. It's still cost.
2. Getting the data usable
Almost every proposal assumes the data is roughly where it should be. Frequently it's in a shared inbox, a spreadsheet with three versions, or a system whose export is a PDF. Poor data readiness is the top obstacle data leaders name for moving pilots to production (Informatica, 2025) — and the cleanup usually falls to you, because it requires knowing which of the three spreadsheet versions is correct.
3. The integration tier you didn't know existed
Your helpdesk has an API. It's on the enterprise plan. This is a per-seat licence increase discovered in week three, and it's occasionally larger than a chunk of the build itself. Check the API tier of every system in scope *before* the build is approved — it takes an afternoon and it's the single highest-yield hour of diligence available.
4. Security and compliance review
A new system touching customer data needs a review, and reviews take calendar time even when they pass. In regulated environments — healthcare, finance — budget weeks, not days, and budget the *internal* effort of assembling evidence, not just the reviewer's time.
The mitigation is to start it in parallel with the build rather than after. Teams that sequence it last routinely finish engineering on time and ship two months late.
5. Change management
The cost of people actually using the thing. Training, documentation, the productivity dip while a team learns a new process, and the political work of persuading people whose jobs change. This is why 91% of mid-market firms use generative AI but only 25% have it integrated into core operations (RSM, 2025) — the gap is adoption, not capability.
6. The parallel-run period
You will not switch off the manual process on day one, nor should you. For some weeks you run both: the agent handles cases and humans check them. That's a real, temporary cost increase — you're paying for the system and the old process simultaneously — and it belongs in the model as a defined period rather than appearing as an unpleasant surprise in month four.
7. Operating it forever
The one that isn't hidden so much as deferred. Monitoring, eval regressions, drift management, and model migrations don't stop, and an unoperated system decays quietly. Managed, that's $3,000–$20,000 a month depending on how many systems you run. Staffed internally, it's a fraction of an engineer indefinitely. It is never zero.
The whole picture
| Cost | Who pays it | When it surfaces |
|---|---|---|
| Your team's time | You | Throughout |
| Data cleanup | Usually you | Week 2–4 |
| Integration licence tiers | You | Week 3, painfully |
| Security and compliance review | You | Late, unless started early |
| Change management | You | At rollout |
| Parallel run | You | Weeks 8–16 |
| Operations | Either | Forever, from go-live |
A workable rule of thumb: add 30–50% to the vendor's number to get the true first-year cost of the change. That isn't a criticism of the quote — the quote is for the software. This is the cost of the business absorbing it.
What to do about it
Price them, don't discover them. Before approving anything, ask your own team four questions: *how many hours of ours does this consume, what state is the data actually in, what API tier does each system need, and who runs it after launch?* Four answers turns most of this list from a surprise into a line item.
Then build the total into the business case rather than the vendor's figure alone, so the ROI arithmetic is honest — a project that pays back on the quote and not on the true cost is a project that will disappoint someone in month nine. What a mid-market AI budget should look like puts the whole first-year number together, and our prices are published so at least the vendor half of it needs no discovery.


