ClickHouse CEO: give AI agents a spending limit
This article summarizes an episode of 20VC with Harry Stebbings’s video series featuring Aaron Katz, CEO of ClickHouse.

Aaron Katz, CEO of ClickHouse / Photo credit: 20VC with Harry Stebbings
Technology costs grow fast when AI agents can choose and buy their own software tools. Aaron Katz, CEO of ClickHouse, a database company, warns that companies must set strict spending rules before giving AI access to company budgets.
Managing these AI systems requires giving them digital identities, understanding the legal risks of different AI models, and checking if fast sales growth hides weak market positions.
Automated purchasing mandates strict identity controls
Putting these spending rules into practice requires treating non-human software users as financial entities.
Katz anticipates a shift in purchasing. He describes a future where “agents say, ‘We need to build an application and provision the underlying stack.'”
This shift dictates specific technical requirements:
- Assigning each AI agent a secure digital ID before it can buy services or access company data.
- Establishing spending limits to keep automated work within a budget.
- Maintaining fast responses to prevent bottlenecks during complex tasks.
A vendor becomes easier to approve when these permissions can be verified before an AI agent initiates a task.
Legal liability dictates corporate model selection
Moving beyond internal purchasing controls, businesses face external risks when selecting models that interact with customers, splitting adoption patterns along fault lines:
- Proprietary vendor safeguards: Developers secure contracts by taking legal responsibility for outputs and offering peace of mind.
- Open weight constraints: Open models win projects focused on cost and flexibility but struggle to guarantee legal accountability.
- Internal boundary lines: Companies use open models for internal code review but avoid using them to push production code into client environments.
Katz highlights this limitation by arguing that “enterprise customers want provisions and protections that open-weight models, especially those that come out of China, may not be able to provide around indemnification and output inference.”
High switching costs validate true revenue moats
Just as legal protections filter out risky models, evaluating a vendor’s financial durability filters out early adoption metrics.
Katz warns that “for any category that goes from zero to US$100 million in a year, I worry about the competitive moat they have to preserve that US$100 million.”
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




