O
OOMeta
← Back to Insights

September 2026 · 5 min read

400 agent seats at $14:
governed cost goes public

400 agent seats at $14: governed cost goes public

Key Definitions

Control-included cost The per-seat price of an agent that already includes the control stack — data residency, session isolation, identity propagation, and token budgets. MRH Trowe’s ~$14/seat/month in month one is a control-included figure; agent quotes without these items underquote by design.

Session isolation AgentCore runtime isolates each agent session at the compute and filesystem level, so one session cannot read another’s data — a compliance precondition for letting employees self-serve AI on client data.

On-behalf-of (OBO) identity The user’s identity flows through every layer of the call (LibreChat, API gateway, Lambda, agent) and cannot be set from the chat box — an agent can only reach the signed-in employee’s own calendar and transcripts.

If an agent cost quote has no governance in it, you are not comparing prices — you are comparing different products. MRH Trowe, a German commercial and industrial insurance broker, put roughly 400 seats of self-service AI agents into production in their first month at about $14 per seat — a rare published hard figure for agents in a regulated vertical. Our judgment: $14/seat is the control-included price; the value of the number is not the price tag, it is that someone finally published the governed unit cost. This piece unpacks what the figure includes and gives regulated buyers a transferable minimum set. Source: AWS ML blog, company- and vendor-reported, no third-party audit.

1. A rare hard number: what $14 per seat buys

Roughly 400 employees reached this scale in the first month of production; ~$14/seat/month covers infrastructure and tokens. Board member Leonid Karlinsky states the vision plainly: “every question should be first answered by AI before any human intervention, and repetitive processes should be automated by those who did them in the past.” Cost transparency comes from consumption-based billing: AgentCore runtime bills on active CPU and memory per second, and I/O wait is not charged — relevant because agentic workloads typically spend 30–70% of their time waiting on model responses, tool calls, or database queries.

Under evidence discipline: this is company-reported data published through a vendor channel (AWS), with no third-party audit. Read it as a floor and an architecture reference for governed agents, not as a market benchmark. What transfers is the minimum control set and the first-agent choice, not the specific figures.

2. The four control levers of a regulated agent program

1. Data residency

Agents, models, and data all run in the AWS Europe (Frankfurt) region, keeping client and meeting data in Germany.

2. Session isolation

AgentCore isolates each agent session at the compute and filesystem level, so one session cannot read another’s data.

3. Identity end-to-end

Entra ID sign-in, with the user’s identity passed server-side through an on-behalf-of flow that cannot be set from the chat box — an agent reaches only that employee’s own calendar and transcripts.

4. Token budgets

LibreChat’s built-in token budget system avoids unexpected costs, on top of per-seat cost transparency.

Add the foundation — private connectivity (transit gateway plus zero trust) keeps employee traffic off the public internet. These five controls are the “governance minimum set” for regulated verticals, and each maps to a question a compliance review will actually ask.

3. Self-service and central governance are not opposites

The core tension is stated in the official narrative: employees should be able to build and use agents themselves, without deep technical skills, while everything stays inside a secure, centrally governed, compliance-ready environment. MRH Trowe’s answer is not policy — it is architecture. One managed platform (LibreChat + Strands + AgentCore) replaces fragmented shadow AI; the LibreChat admin panel governs which endpoints and models each user can reach via ACLs; employees are encouraged to explore, but exploration happens inside governance boundaries.

For digital-transformation leads, this is the answer to why banning shadow AI fails: prohibition does not stop adoption, it pushes it out of sight. Replacing it with a governed self-service floor is how you get both adoption and control.

4. Our judgment: the control-included price is the real price

Any agent cost figure that leaves out residency, isolation, identity, and budgets is a different product priced a different way. The $14/seat is “what it actually costs to let one employee run a governed agent” — comparing governed delivery against a feature is the only apples-to-apples comparison.

Our position: write the control stack into the cost model on day one, not as an afterthought. Cost transparency is a governance property, not a FinOps follow-up — you cannot govern an agent program whose cost you cannot account for, and you cannot fund one that never priced the controls. This is also our own practice: governance is part of the quote, not a discount line.

5. The transferable template

The first agent is deliberately low-risk and high-frequency: Teams meeting minutes, not claims processing. A one-line request becomes a structured protocol. The step proves that “self-service plus governance boundary” works in real employee hands while barely touching high-risk actions.

The adoption mechanics transfer too: cross-team use-case workshops build a power-user group; adoption data identifies power users whose workflows get promoted; and the board member’s line — “if you and your colleague do something twice, create an agent” — is a usable rule of thumb. The scale path: 10–15 domain-expert agents maintained by subject-matter experts by end of 2026, plus ~40% infrastructure cost reduction via right-sizing and scheduled scaling.

6. Action and the question left for buyers

Action: put the control stack in the cost model before the pilot; choose a low-risk, high-frequency first agent; instrument cost per seat and per use case from day one. The question left for buyers: what does one governed agent seat cost in your organization — including residency, isolation, identity, and budgets? If you do not know, you have not priced the product you are actually deploying.

OOMeta AI

OOMeta’s position and practice: the control stack belongs in the cost model from day one — cost transparency is a governance property, not a FinOps afterthought. MRH Trowe’s $14/seat is a public floor for control-included cost: company-reported, no third-party audit; what transfers is the minimum control set and the first-agent choice.

Book a diagnostic call

References: AWS ML Blog, How MRH Trowe enabled secure self-service AI agents in financial services (company- and vendor-reported, no third-party audit) https://aws.amazon.com/blogs/machine-learning/how-mrh-trowe-enabled-secure-self-service-ai-agents-in-financial-services/ | MRH Trowe, company site https://www.mrh-trowe.com/en/

FAQ

Is the $14 per seat figure real?+

Company-reported via AWS’s blog: ~$14/seat/month in the first production month for ~400 seats, covering infrastructure and tokens. It is vendor-published case data, not an audited benchmark — read it as a floor for governed agents, not a market average.

What is included in the $14?+

Infrastructure and token cost for the governed stack — data residency in Frankfurt, private connectivity, per-session isolation, Entra ID identity end-to-end, and LibreChat token budgets. Organizational change (workshops, power users) is not in the number.

Why does a regulated broker let employees build their own agents?+

Because self-service happens inside a centrally governed platform: one managed environment replaces fragmented shadow tools, with ACLs per endpoint and model, session isolation, and token budgets. Self-service and central governance are reconciled by architecture, not by policy.

What was the first production agent?+

A Teams meeting agent — ask in German for a recent meeting with a participant; the agent finds it on the employee’s own calendar, retrieves the transcript, and drafts structured minutes with action items. Identity cannot be set from the chat box.

What is the roadmap?+

A Data and AI Community of Practice aims for 10–15 domain-expert agents maintained by subject-matter experts by end of 2026, plus a path to cut infrastructure cost ~40% via right-sizing and scheduled scaling.

What should I copy?+

The governance minimum set — residency, session isolation, identity end-to-end, token budgets — plus the first-agent choice (low-risk, high-frequency meeting minutes) and the adoption mechanics (use-case workshops, power-user promotion).