Epic's AI Tokenomics Problem Is Also a Security Problem

AI Industry Watch

At Epic's 2026 Users Group Meeting in Verona, several health system CIOs reached for the same word to describe what's happening to their AI budgets: tokenomics. It's not a term from healthcare finance. It comes from the cryptocurrency world, where it describes the economic mechanics of a token-based system — how tokens are created, consumed, and priced. The fact that healthcare CIOs are borrowing it to describe their Epic AI bills says something about how fast the landscape has shifted.

The problem isn't token costs in the abstract. Health systems have been managing token-based pricing across their broader AI vendor stack for a while now, largely through access tiering and governance controls. What's different with Epic is that the token spend is now embedded inside the EHR that every clinician and biller touches every day — and the pricing model is, by CIO accounts, uniquely hard to isolate, forecast, or govern the way you can with a standalone AI tool.

What's Actually Happening at Epic

Epic's AI suite — which now includes Agent Factory (approximately 120 adaptable AI features), the clinical AI scribe Art, the patient-facing assistant Emmie, and the revenue cycle copilot Penny — runs on a hybrid pricing model. Some features carry a flat fee. Others are consumption-based, billed per token. Amy Trainor, CIO of Ochsner Health, put the range plainly: a given feature "could be $10. It could be $10,000, depending on what the usage and the price model looks like." Epic has begun building per-feature cost dashboards, but those tools aren't fully deployed yet. For now, the visibility gap between what's being consumed and what's being billed is real and acknowledged by Epic itself.

Adding to the complexity, Epic's Cogito Cloud analytics platform has effectively become mandatory infrastructure — Mass General Brigham's Eric Podradchik noted it's being positioned "much like Cosmos was before," meaning health systems are absorbing the cost whether or not they actively chose it. The infrastructure layer and the AI feature layer are now financially entangled in ways that traditional IT budgeting doesn't accommodate.

Where InfoSec and FinOps Converge

Most of the UGM tokenomics coverage has focused on the CFO and CIO budget problem. That framing is accurate but incomplete. The questions that emerge from a hybrid, per-feature, consumption-based pricing model embedded in your primary clinical system are not just financial — they're access control and audit trail questions. That's InfoSec territory.

Access Controls at the Feature Level

When AI features inside Epic carry variable costs based on consumption, the question of who can enable or use which features becomes a financial control problem as much as a security one. In a traditional EHR environment, role-based access controls govern what users can see and do. In an Agent Factory environment, where a single authorized clinician or workflow can spin up an AI agent that consumes tokens continuously, RBAC alone isn't sufficient.

Health systems need to extend their access control models to include AI feature authorization — not just "can this user access the tool" but "is this tool authorized for this role, this department, and this spend tier." Baptist Health's Aaron Miri put it directly: "Who's paying the piper on the back end, paying for the tokens? We've got to work through that sausage-making." That calculation requires knowing not just who ran the agent, but what it consumed and on whose authorization.

The FinOps Foundation's 2026 Tokenomics framework flags exactly this gap: token invoices represent one of nine cost buckets in a full AI cost model, and without attribution at the workload level, finance can see the bill but can't trace it back to a decision, a workflow, or a role.

The Audit Trail Gap

An audit trail problem follows directly from the access control gap. If a health system can't attribute token consumption to specific users, workflows, or authorizations, they can't answer the basic audit questions that healthcare compliance requires: Who accessed this capability? When? Under what authorization? What did it produce?

This isn't hypothetical. Sha Edathumparampil, CDIO of Baptist Health South Florida, noted that Epic's pricing varies by which frontier model underlies a given feature — and that those models change. When the underlying model changes, prompt behavior changes, token consumption shifts, and outputs may differ. From an audit trail perspective, you now have a moving target: the same authorized workflow, run by the same authorized user, can produce different outputs and different costs depending on which model Epic is running underneath it on a given day.

The WVU Medicine model for Agent Factory governance — recurring flow reviews every six to twelve months, with token usage as a tracked metric, and mandatory prompt re-engineering whenever the underlying model changes — represents the current state of the art. It's a reasonable framework, but it presupposes that you have the visibility to run it. Right now, most health systems don't.

The On-Prem GPU Hedge and Its Own Risk Surface

Baptist Health's Miri flagged one coping strategy that's gaining traction: running AI models on-premise to avoid per-token fees from Epic's cloud. The logic is sound — if you own the inference infrastructure, you escape the consumption billing model. But this trades one risk surface for another.

On-prem GPU deployments introduce model governance questions that cloud-hosted Epic AI doesn't: What version of the model is running? Who controls updates? How are prompts and outputs logged? What's the patch cadence? For healthcare security teams, a locally-hosted frontier model is an entirely different threat model than a vendor-managed cloud API, and the access control and audit requirements are substantially more complex to implement.

What This Means for Healthcare Security Teams

The tokenomics conversation at UGM 2026 is a signal that AI governance in healthcare is entering a second phase. The first phase was about whether to adopt AI tools and how to assess them. The second phase is about what happens when those tools are embedded in your core clinical infrastructure, generating continuous consumption costs that cross the boundary between security, compliance, and finance.

Access Control Reviews Need to Include AI Features

If your health system is running Epic's AI suite, your next access control review cycle should include an inventory of which Agent Factory features are enabled, which roles can invoke them, and whether there's a defined authorization path for adding new features. The default posture — "IT enabled it, so it's authorized" — doesn't hold when each feature carries variable cost and variable data exposure. Enablement and authorization are separate questions.

Token Consumption Belongs in Your Audit Log

If you're building or updating an AI governance framework, token consumption data should be treated as an audit artifact, not just a billing input. Who ran which agent, when, against which data, and what it cost are all questions your compliance and security teams may need to answer. Start the conversation now about what data Epic's cost dashboards will expose when they're fully deployed, and whether that data needs to flow into your SIEM or audit trail systems.

FinOps Is Now an InfoSec Stakeholder

The FinOps Foundation's 2026 State of FinOps data shows that 98% of organizations now actively manage AI spend — up from 31% two years ago. The discipline is maturing fast, but it's maturing primarily in finance and IT operations, not in security. The shadow AI problem that security teams have been managing — unsanctioned tools, ungoverned data flows — has a direct analog in shadow token spend: authorized users running authorized tools in ways that generate unauthorized costs and ungoverned data access patterns.

Healthcare security teams that haven't already established a working relationship with their FinOps function should treat the Epic tokenomics problem as the forcing function to do so.

The Bigger Picture

Epic's UGM 2026 made its ambitions explicit: the company wants to move from being the system of record to being the system of intelligence and the operating layer beneath the health system itself. Agent Factory's approximately 120 adaptable AI features are the mechanism for that ambition. The tokenomics problem isn't a bug in that strategy — it's a feature. Consumption-based pricing ties health system revenue to Epic's AI adoption in ways that flat licensing never did.

For security practitioners, the takeaway is structural: when your primary clinical platform becomes the AI runtime layer, the access control, audit, and governance questions that apply to your AI stack now apply to your EHR. Those aren't separate conversations anymore.

The health systems that will manage this well aren't the ones that solve the budget problem first. They're the ones that build the access control and audit infrastructure before the token bills start arriving — before, as Trainor put it, there's anything left to refund.


This is an AI Industry Watch post. For related coverage, see The IBM AI Security Trilemma and Big Tech's Hidden AI Debt Pyramid.

Key Links