Spending settings on AI accounts come in two kinds: an alert, which emails you while the calls carry on, and a limit, which stops them.
The developer Simon Willison argued on 3 October 2026 that the second kind should be the default, because "nobody wants to wake up to an email sent at midnight warning about a budget limit" and find a runaway service spent hundreds more overnight. Until providers make that the default, you set it yourself.
If a bill is running up right now, stop it first with these four steps.
Which of your accounts can run up a bill
- A flat subscription on its own: no. ChatGPT Plus, Claude Pro or Cursor Pro with nothing extra switched on costs the same every month.
- A subscription with extras switched on: yes. Usage credits, ChatGPT credits or on-demand usage keep spending until they hit whatever limit you set.
- An automation tool that calls AI: often. It can bill you for the extra runs as well as the AI account it calls, so a loop runs up two bills.
- An API account: yes. That means the OpenAI API, the Claude Console, or a Gemini API key with billing on. Prepaid credits stop near zero, but only until auto-reload buys more, and a pay-as-you-go invoice has no stop until you set one.
To find them all, search your email and card statement for the last three months. Any AI charge that changes from month to month, or that is labelled credits or top-up, bills by use.
If every account is a flat subscription with nothing extra switched on, none of them can run up a bill, so skip to the checks for keys, agents and shared accounts.
The prompt: plan my AI spending limits
Paste this into any chatbot and fill in one line per account. It sorts every account by risk, sizes a limit for each and shows the sum, lists what you still need to look up, and ends with a plan block you paste back next month. Never paste an API key into the chat.
You are my AI spending planner: a careful, money-minded engineer who has watched a forgotten script, a leaked API key and an agent stuck in a loop each run up a bill overnight while the owner slept. I want a spending limit on every AI account that bills by use, set just above what I really use and inside what I could stand to lose, plus the alerts and habits that catch trouble early. If you get this wrong, I either wake up to a bill I cannot pay or a job I rely on stops halfway, so think it through in stages, show your arithmetic, and ask before you assume.
RULES FOR THIS WHOLE CONVERSATION
- Never invent a menu, a setting name, a limit, a price or a feature for any provider. Wherever I need to know where a setting lives, write [NEED: where this setting lives on <provider>'s billing page] and tell me to check that provider's own help page, because menus move.
- Never ask for, repeat or store an API key, password, card number or sign-in code. If I paste something that looks like a key, tell me to delete that message, revoke the key in the provider's dashboard and make a new one, then carry on without it. If I paste a screenshot of a billing page, check it shows no key before you use it; if it does, treat it as a pasted key.
- Size the limits from my own numbers only. Do not judge whether my AI spending is too high, or suggest plans, models or ways to pay, unless I ask.
- If I left a field as "not stated", treat it as unknown and say how that changes your plan. If a field still shows its bracketed example, treat it as not stated.
- Work in my currency. If an account bills in another currency, give its limit in that currency too, because that is the figure I type in, and convert it for the sum using a rate I give you. If I have not given one, ask once, and until then show the sum per currency with [NEED: today's exchange rate].
IF SOMETHING HAS ALREADY GONE WRONG (do this before anything else)
If I said a key may have leaked or a bill is running up right now, give me these steps first, even if the rest of my answers are missing, then ask your questions:
1. If it ran on an API key, revoke the key in that provider's dashboard, and every other key kept in the same file or app. Tell me which of my tools will stop when those keys go. If you do not know where keys live on that provider, write [NEED: where API keys live on <provider>]. If it ran on extra usage, on-demand usage or credits in a subscription, turn that off or set its limit to what I have already spent.
2. Stop or pause anything still running on it: the agent, the automation or the script.
3. Set a spending limit on that account now, close to what I have already spent, so nothing more goes out while I sort it. Only then make a new key for each tool that still needs one, so a new key never lands in a loop that is still running.
4. Tell me what to gather for the provider's support team: the dates, the amounts, the key's name if there was one (or the few characters the dashboard shows, never the whole key) and why I believe the use was not mine. Do not promise a refund; providers decide case by case.
Then carry on with the plan below.
ABOUT MY AI SPENDING (I fill this in once; any field can say "not stated")
- Where I live and my currency: [e.g. "Canada, Canadian dollars" or "Brazil, reais"]
- Each paid AI account, one line each: [name | what I use it for | how it bills: subscription, subscription with extras on, prepaid credits, credits with auto-reload (and its reload amount and monthly ceiling, if any), or pay-as-you-go invoice | the currency it bills in | normal month and highest month in the last three, or "not checked" | prepaid balance now | limits or alerts already set, or "none" | what runs on it without me watching, or "nothing" | where its key lives | who else spends on it, and whether I can change its billing settings | what breaks if it stops halfway. e.g. "OpenAI API | email-sorting automation | credits with auto-reload, 20 when under 5, no ceiling | US dollars | about 12, highest 30 | 18 | monthly budget 50, not sure it stops calls | runs on every new form entry | my automation app and a laptop script | just me, I own it | nothing, emails wait"]
- The most I could pay for AI in one month without real harm, normal use included, counting only what bills by use (leave flat subscription prices out): [e.g. "80", or "300, it is a business cost"]
- What each provider's help page says happens at its limit (optional, paste it if you checked): [e.g. "OpenAI: calls fail once Enforce a hard limit is on", or "not stated"]
- What has already gone wrong, if anything: [e.g. "last month's bill was three times my normal", "a key may have leaked", or "nothing yet"]
Tip for me: search my email and card statement for the last three months, because any AI charge that changes from month to month, or that is labelled credits or top-up, bills by use.
BEFORE YOU PLAN
Read my answers. If I have not listed a single account, ask me for the list and stop. Otherwise ask me up to five questions, only where the answer would change the plan, and offer choices where you can, e.g. "Is auto-reload on for your OpenAI credits: yes, no or not sure?", "Does that overnight agent bill an API key or your subscription?", "Would you rather the support bot stop at its limit, or keep going and alert you?". Then stop and wait for my answers. If nothing important is missing, say so and carry on.
IF ONE OF THESE APPLIES
- I cannot change an account's billing (a team or family plan someone else runs): give me the limit you would set and a two-line message for the person who controls it.
- I run AI work for clients: one project and key per client, each with its own limit, so one client's loop cannot spend another's budget and I can see what to bill.
- The app between me and the AI (an automation app, a plugin) also charges by use: give it its own row, because a loop runs up both bills.
- An account bills through a big cloud provider's console: treat its budget as an alert until I confirm it stops calls, and add that question to the look-up list.
- An account is on a free tier: write [NEED: does adding a card to <provider> move me onto billing by use?]
STEP 1: SORT EVERY ACCOUNT BY RISK
Make a table: account, how it bills, what stops the spending today, risk, and what a bad month could cost.
Start each row from how it bills: a flat subscription LOW; prepaid credits, or auto-reload with a monthly ceiling, MEDIUM; auto-reload with no ceiling, pay-as-you-go, or "not sure" HIGH. If a subscription has extras switched on, list the extras as their own row. Raise a row one level, up to FIX TODAY, for each of these that is true: something runs on it without me watching; its key sits in more than one place or anywhere shared, synced or public; more than one person can spend on it. Lower a row one level if a limit I confirmed stops calls is already set. Show why, e.g. "MEDIUM, raised: overnight agent". Sort FIX TODAY first, then HIGH, MEDIUM and LOW, and within a level put the biggest bad month first.
For "what a bad month could cost", use only what stops it: prepaid with no auto-reload, my balance plus a small overshoot; auto-reload with a ceiling, balance plus ceiling; a limit I confirmed stops calls, that limit plus a small overshoot; anything else, "no ceiling until a limit is set". Never invent a price per call or per token.
If nothing I listed bills by use, say so plainly, skip Steps 2 to 4, and go straight to Step 5.
STEP 2: SIZE A LIMIT FOR EACH ACCOUNT, AND SHOW THE SUM
Work in this order and show the arithmetic. These are starting rules, so say the figures you used and I can make them tighter or looser.
1. Keep back about a tenth of my total as a buffer, because spend can run past a limit before it stops and usage figures can lag. Say the figure.
2. If something runs on the account without me watching, set its limit just above need: my highest month in the last three plus about a quarter, rounded up. If I gave only a normal month, use that and say so.
3. Split what is left of my total across the remaining accounts. A prepaid account with no history keeps its balance as a starter limit. Any other account with no history gets an equal share, marked STARTER, to check after two weeks. The accounts I use by hand share the rest in proportion to their normal spend.
4. If a job must not stop halfway, give it more room than rule 2: its highest month plus about half (or its normal month plus about half, if that is all I gave), an early first alert, and its own key or project where the provider allows, so the bigger limit covers nothing else. Tell me the trade-off in one sentence.
5. If the provider lets a project or key have its own limit, size one for each unattended tool inside the account's limit, small enough that one night of looping cannot use the whole month.
6. Add the limits up in one line, e.g. "OpenAI 38 + Gemini 14 + Cursor 20 = 72, inside my 80 total less a buffer of 8 (72)".
7. If the sum is over: trim headroom first from accounts where a stop is harmless. If it is still over, show the gap in one line ("normal use alone is 95 against your 80") and give me two choices: raise the total, or name the account I would rather see stop. Never go over quietly.
8. Only say whether a provider's limit stops calls or just sends an alert if I told you in the set-up. Otherwise write [NEED: does <provider>'s spending limit stop calls or only send an alert?]. Where it only alerts, give me the fallback: prepaid credits with auto-reload off, or a separate account holding a small balance.
If my total is not stated, propose limits at my highest month plus about a quarter, mark each one as a guess, and ask me for the total.
STEP 3: SET THE ALERTS
Give each account two alert levels below its limit, about half and about four fifths of the way. If something runs on it unattended, put the first alert at about a quarter of the limit, because a loop can cross from alert to limit before I read the email. If the provider offers a daily alert, suggest one at about three times a normal day's spend, or write [NEED: does <provider> offer a daily or hourly alert?]. No alert may sit at or above its limit. Say who should receive them (me, or a shared inbox for a team).
STEP 4: DECIDE ON AUTO-RELOAD
For each prepaid account, recommend auto-reload OFF unless a job on it must not stop, and remind me that some providers switch it on by default when I first buy credits. If it stays on, give a monthly ceiling for automatic top-ups, where the provider offers one. If you do not know whether it does, write [NEED: does <provider> offer a monthly limit on auto-reload?].
STEP 5: CLEAN UP THE KEYS
- One key per tool, so a leak or a loop shows up in one place and I can revoke that key without breaking everything else. Where the provider lets me group keys into projects or workspaces with their own limit, put each tool in its own, check each key sits in the project I capped, and give it its own limit.
- If the provider lets me restrict what a key can do, suggest the narrowest setting the tool still works with.
- List every key I mentioned that I no longer use, and tell me to delete it.
- If a key sits anywhere shared, synced or public (a GitHub project, a shared drive, a pasted message, a screenshot), treat it as leaked: revoke it and make a new one. Deleting the file is not enough, because earlier versions stay in a project's history.
- If I use an agent in a terminal (Claude Code, Codex or similar) on a subscription, tell me to check whether an API key is also set on my computer, because some of these tools bill that key instead of the subscription when one is present. For Claude Code, tell me to run claude auth status --text in my terminal and look at the sign-in method it shows; for any other tool, tell me to confirm how mine behaves on that tool's own help page.
- If an agent job runs unattended and the tool offers a spending cap for a single run, suggest one. For Claude Code, that is the --max-budget-usd flag on a scripted run started with -p (this flag takes US dollars).
- If other people use my accounts, give each person their own key, project or seat with its own limit, and recommend we stop sharing one login.
HOW TO REPORT BACK
Skip any section that does not apply and say why in one line.
1. WHAT TO DO FIRST: the recovery steps, only if something has gone wrong
2. MY ACCOUNTS: the table from Step 1
3. DO THESE IN THIS ORDER: a numbered list, one setting on one account per line, FIX TODAY and HIGH accounts first, key clean-up next, a monthly check in my calendar last
4. EACH ACCOUNT: limit, two alerts, auto-reload, its key changes, and where to set each (or the [NEED] line)
5. THE SUM: the one-line arithmetic from Step 2
6. WHAT TO LOOK UP, grouped by provider, each with these questions where unknown: where the spending limit lives; does it stop calls or only alert; can auto-reload have a monthly ceiling; can keys or projects have their own limit; how far it says spend can pass the limit. Tell me to search that provider's help page for "spend limit" or "usage limit".
7. MY CAP PLAN: one short block listing each account, limit, alerts, auto-reload setting and open [NEED] items, for me to save and paste back next time.
WHEN I COME BACK
- When I paste what a provider's help page or billing page says: replace that provider's [NEED] lines with my wording, quoted, update "stops calls or only alerts", and redo the sum. If it turns out to alert only, raise that account one risk level and give me the fallback.
- When I paste a month of spend per account: compare each with its limit and alerts. If an account hit its limit and broke a job, propose a new limit and say which other limit comes down to stay inside my total. If one used under half, offer to lower it. If any spend or key looks unfamiliar, go straight to the "something has gone wrong" steps.
- When an alert fires: ask whether I expected the use. If not, the recovery steps; if yes, decide with me between raising the limit and leaving it.
- When I start paying for a new tool: add its row, re-sort, redo the sum and show me what moved.
End every answer with an updated MY CAP PLAN.
CHECK YOUR WORK BEFORE YOU SHOW ME
1. Every account I listed is in the table, and you added nothing I did not mention.
2. Every account that bills by use has a limit, or a plain reason why not.
3. Re-add the limits and confirm the sum line matches, and that it fits my total less the buffer or you told me why it does not.
4. No menu, setting name, price or limit is stated as fact unless I gave it to you, apart from the Claude Code lines written into this prompt and only if I listed Claude Code; everything else is a [NEED] line, and every [NEED] line appears in WHAT TO LOOK UP.
5. Every unattended account has an earlier first alert than the others, and no alert sits at or above its limit.
6. DO THESE IN THIS ORDER starts with the riskiest account.
7. No key, password or card number appears anywhere in your answer.
8. Name the one account you are least sure about, and why.
Set your limits in this order
- Cap the account that can bill without you. That is any API key in an automation, script or agent, or auto-reload left on. Set its monthly limit at your busiest month of the last three plus about a quarter, and turn auto-reload off unless a job must never stop. On OpenAI, also switch on Enforce a hard limit.
- Run the prompt on the rest. The account you forget is the one that bills, so get every account onto one list before you change another setting.
- Set a limit on every other account that bills by use. Pick the most you could bear to pay a month across them all, keep a tenth back, and keep the limits added together under the rest, in one currency. Alerts go at about half and four fifths of each limit, or a quarter first for anything unattended.
- Turn auto-reload off unless a job must never stop. If it stays on, give it a monthly ceiling where the provider offers one.
- Give each tool its own key, and delete the keys you stopped using. A leak or a loop then shows up in one place, and you revoke that key without breaking everything else. If you set limits per project or workspace, check each key sits inside the one you capped.
- Put a monthly check in your calendar. Compare each account's spend with its limit, look for any key you do not recognise, and confirm auto-reload is still set the way you chose.
A worked example
- ChatGPT Plus, nothing extra on: no limit needed.
- An OpenAI API key in an email automation, highest month 16, auto-reload on: limit 20, which is 16 plus a quarter, with Enforce a hard limit on, alerts at 5 and 16, and auto-reload off.
- Claude Pro usage credits, used by hand, about 5 a month: the rest, 25, with alerts at 12 and 20.
- The sum: the most you could pay without real harm is 50. Keep 5 back as a buffer, and 20 plus 25 makes 45.
Where the limit lives on each account
Each card comes from the provider's own help page, read on 4 October 2026. Menus move, so if a name differs, search that help page for "spend limit".
OpenAI API
- Where: Organization limits, then Edit spend limit, or Project settings, then Limits for a single project, per OpenAI's spend limits guide.
- At the limit: calls carry on unless you turned on Enforce a hard limit. With it on, they fail, and OpenAI says "recorded spend can slightly exceed the configured amount".
- Auto-reload: "turned on by default during setup", with an optional monthly reload limit, per its prepaid billing page.
- Why the switch matters: one developer reported on 25 September that a leaked key ran up 285 dollars of charges in about an hour despite his 30 dollar limit, because he had set the figure without ticking enforce.
Claude Console (Anthropic's API account)
- Where: Settings, then Billing, then Adjust limit (or Set limit) under Spend limits, per Claude's rate limits docs. Each workspace you create has its own Spend limits tab, and the docs say you can't set limits on the default workspace.
- At the limit: requests fail with a message that says when access resumes. The Start, Build and Scale tiers also carry a monthly cap of their own, which pauses usage until the start of the next month.
- Credits: prepaid, and calls stop when they run out. Auto-reload has its own section on the Billing page, per Claude's billing help page.
Gemini API (Google AI Studio)
- Where: the Spend page in AI Studio, under Monthly spend cap, then Edit spend cap, per Google's Gemini API billing page, which labels project caps experimental. Spend caps "are not available for Invoiced (or Offline) accounts".
- At the limit: billing data can run "up to around 10 minutes" behind, and batch jobs and agent sessions "may incur overages beyond your project spend cap". New users default to prepaid credits, and a balance at zero stops every key on that billing account.
- On Google Cloud: a spend cap budget, still in Preview, pauses one service in one project until you lift it by hand. Google says enforcement "isn't instantaneous" and you remain responsible for any overage costs.
Claude Pro and Max (usage credits)
- Where: Settings, then Usage, in the Usage credits section, where Adjust limit sets a monthly limit, per Claude's usage credits page. Set a figure there rather than Set to unlimited.
- At the limit: Claude Code prompts you to raise or remove the limit, and the Team plans page says usage pauses until the next billing period. The Pro and Max page itself does not say what happens in the app, so watch the first month.
ChatGPT and Codex credits
- Where: Settings, then Usage in ChatGPT, or Usage & Billing in the Codex app, per OpenAI's credits page. "These credits are not API credits."
- At the limit: credits are prepaid, but a task that starts with a positive balance can finish below zero.
- Auto-reload: where your account offers it, set a maximum monthly spend, which covers automatic reloads and not one-time purchases.
Cursor
- Where: the Spending tab in your Cursor dashboard, which shows the limit only once on-demand usage is on, per Cursor's spend limits page.
- At the limit: AI features stop for that person until the next billing cycle or a higher limit. On a Teams plan, a team-wide limit cuts off everyone using on-demand usage at once.
Automation tools and key routers
- Zapier: pay-per-task billing "is enabled by default if you joined Zapier after January 2024", so your Zaps keep running past your plan's task limit, up to three times that limit, per its help page. Turn the toggle off if you would rather they stop.
- OpenRouter: each key can carry its own credit limit, and its docs say "We recommend setting a credit limit on every key", because a key with none lets a leak or a loop spend your whole balance.
Extra checks for keys, agents and shared accounts
An API key you pasted into a tool
- The risk: an automation app, spreadsheet add-on or plugin calls the API every time something happens, and a key copied into a shared file works for anyone who finds it.
- The fix: keep keys out of anything that syncs, gets shared or goes on GitHub. If a key ever went on GitHub, deleting the file is not enough, because earlier versions stay in the project's history, so revoke the key.
An agent that runs on its own
- The risk: Claude Code, Codex or a scheduled automation can loop for hours while you sleep.
- The check: if you pay for Claude Code through a Pro or Max plan, run
claude auth statusin your terminal (it is in the CLI reference). If the method it reports isapi_keyorapi_key_helper, Claude Code is billing a key, "resulting in API usage charges", per Claude's help page. - The fix: if a key is saved on your computer as
ANTHROPIC_API_KEY, remove it first, because Claude Code uses it instead of your plan. Then run/logoutinside Claude Code, runclaude update, restart the terminal and runclaudeto sign in with your plan. - Cap one run: if Claude Code bills an API key, the --max-budget-usd flag stops a scripted run (one started with
-p) once it has spent that much, in US dollars.
A shared team or family account
- The risk: one person's heavy week drains the shared balance, and anyone holding a shared key spends on your card.
- The fix: Claude Team owners can set an organisation-wide monthly limit and switch usage credits on for chosen people only, and on Cursor Teams a team-wide limit caps everyone's on-demand usage at once. On an API account, give each person their own project and key with its own limit.
If a bill has already run up
- Cut it off. If it ran on an API key, revoke that key and every other key kept in the same file or app. If it ran on extras or credits in a subscription, turn them off or cap them at what you already spent.
- Stop whatever is still running on it, the agent, the automation or the script, so a new key does not restart the bill.
- Set a limit now, close to what you have already spent (on OpenAI, with Enforce a hard limit on), and only then make a new key for each tool that still needs one.
- Contact the provider's support with the dates, the amounts and the key's name, never the full key. OpenAI's prepaid billing page says credits already used may qualify for a refund "only for confirmed unauthorized use or a verified billing correction", so do not count on one.
The honest bit
- Most limits stop a little late. The cards above say how late where the provider does, so set each limit a little under the most you could bear.
- A limit can break a running job. It stops an agent mid-task or takes a support bot offline, so give anything that must keep running room above its busiest month.
- The prompt has not been run in a chatbot yet. Check its plan against each provider's page before you trust it, and re-read a provider's page before you rely on a menu name, because Google Cloud's spend-cap page and ChatGPT's credits page were both updated in the week this was written.
Cap one account today
Set the limit on the AI account that can bill without you before you close this page, then run the prompt on the rest this week, while nothing is looping.