The AWS bill grew, the rate card did not, and five places explain it
AWS bills keep growing in 2026 and the rate card explains almost none of it: the overspend hides in five places, over committed Savings Plans, idle and oversized resources, untagged spend, egress, and on demand workloads at scale, each with a measurable signature on the bill and a defined recovery move. None appears as a new line, they all flow through the same per service meters, which is why the bill climbs without a rate change to point at and why the lever sits inside the buyer organization.
Prepared by Redress Compliance · August 8, 2026 · AWS advisory. Based on 40 to 60 AWS estates benchmarked 2024 to 2025.
Executive summary
The commitment tax leads: 15 to 35 percent of commits above realized usage. Committed Savings Plan and Reserved Instance capacity ran 15 to 35 percent above realized eligible usage on a steady state, with the gap paid every hour at full rate: the structural signature is usage below the commit line.
Hours paid whether anything ran on them, and an effective rate on the workload that did run ending above what a smaller, well sized commit would have produced.
Commits size to baseline, never to headroom, because the headroom is the tax.
Untagged spend blocks everything else, at 25 to 45 percent of the bill.
Cost that cannot be attributed to an owner cannot be optimized, because nobody is accountable for it, and untagged spend ranged from 25 to 45 percent of the bill at first read, making cost allocation directional at best and blocking any line by line attack: the fix is process before tooling.
A tagging policy with a small number of mandatory dimensions enforced at the account or service control policy level. Tagging is the lever, not the goal, the hook every other optimization pulls on.
Egress is the most underbudgeted line, moving bills 4 to 9 percent.
Cross availability zone, cross region, and internet egress price small per gigabyte and large at terabyte scale.
And together they moved monthly bills by 4 to 9 percent in environments where data movement had not been engineered as a first class cost line: buyers underbudget it because it appears in no commitment vehicle and no EDP discount sheet in compute's shape.
Architecture makes most of the difference, a workload crossing regions on every call carrying a line the single region version would not, and the honest unit is dollars per million calls.
The idle tail and the uncommitted scale round out the five.
Idle EC2, attached EBS volumes nobody uses, and RDS sized for peaks that no longer arrive ran 10 to 20 percent of the run rate, rarely heroic per resource and heroic in aggregate across thousands of resources and years nobody looked.
On demand workloads at scale without commitment coverage ran 8 to 18 percent of compute, and marketplace sprawl 3 to 7 percent of the bill. The recovery work is operational rather than procurement, a regular review loop against a baseline.
And disciplined buyers recovered a material share at the next reconciliation.
The five categories, sized on the bill
| Category | Typical share | The recovery move |
|---|---|---|
| Over committed plans | 15 to 35 percent of the commit | Resize to measured baseline, never headroom |
| Idle and oversized resources | 10 to 20 percent of the run rate | The regular review loop against a baseline |
| Untagged spend | 25 to 45 percent of the bill at first read | Mandatory tag dimensions enforced by policy |
| Egress | 4 to 9 percent of the bill | Architecture as a cost decision, dollars per million calls |
| On demand at scale and marketplace sprawl | 8 to 18 percent of compute, 3 to 7 of the bill | Commitment coverage and subscription inventory |
The rate card alibi fails, and that is the good news.
Public list rates barely moved while bills grew, because commit sizing, sprawl, and egress patterns drifted faster than budgets: nothing here requires a negotiation with AWS, the categories all flow through meters that have run for years, and the lever sits entirely inside the buyer organization.
The bill that grew without a rate change recovers without a rate change, at the next reconciliation, through operational discipline rather than procurement leverage.
The commitment tax, mechanically
- The signature: realized eligible usage below the commit line, with the hours under it paid at the commitment rate whether anything ran.
- The effective rate inversion: the workload that did run ends up costing more per hour than a smaller, well sized commit would have charged.
- The sizing rule: commits sized to the measured steady state baseline, with growth bought as it arrives rather than prepaid as a forecast.
- The cadence: the commit position reviewed against realized usage quarterly, because the drift compounds silently between reconciliations.
- The EDP layer above: the enterprise discount program's own commitment mechanics, where the same over sizing logic applies at the agreement level.
The AWS EDP negotiation brief
The commitment sizing method, the discount band mechanics, and the agreement terms that survive a usage miss.
Get the white paper →The recovery program, operational not procurement
The sequence runs visibility first: the tagging policy enforced so cost has owners, the idle sweep against a baseline so retired workloads stop billing, the commit resize to measured usage so the tax stops accruing, the egress architecture review pricing data movement in dollars per million calls.
And the on demand coverage decision for whatever scale remains.
Every move is internal, none needs AWS at the table, and the reconciliation calendar is the enforcement mechanism.
The commitment layer above connects to the negotiated agreements, the EDP mechanics in the EDP pillar family, the egress economics in the egress negotiation guide, the private pricing structures in the Savings Plans analysis.
And the cross cloud pattern family this report belongs to in the overpayment patterns report.
- Percentile standing for your exact deal size and industry, from real closed transactions
- Scenario simulation before the call: test alternative terms and see the financial impact of each
- A negotiation playbook, talking points, and a two page executive brief on day one
What we saw across AWS estates, 2024 to 2025
Across roughly 40 to 60 AWS estates our team benchmarked between 2024 and 2025, the run rate climbed faster than the underlying workload growth, and the rate card barely moved:
Committed capacity above realized eligible usage, paid every hour at full rate.
Untagged spend at first read, blocking cost allocation and every downstream move.
The report's structural point is that cloud overspend differs from software overspend in kind: there are no seats to reclaim and no audit to defend, only commitments to resize, meters to govern.
And architecture to price, which makes the recovery an operations program with a quarterly cadence rather than a renewal event with a calendar.
The five categories compound in the same estate, the untagged spend hiding the idle resources that the oversized commit was covering while the egress ran unmeasured underneath, and the tagging policy that seems administrative is the move that makes every other number visible enough to attack.
Your first five moves
- Enforce the tagging policy first, the lever that unlocks every other move against the 25 to 45 percent blind spot.
- Resize commits to measured baseline, never headroom, where 15 to 35 percent paid hourly for nothing.
- Run the idle sweep on a quarterly loop, the 10 to 20 percent that compounds while nobody looks.
- Price egress in dollars per million calls, and make data movement an architecture decision.
- Cover the on demand scale and inventory the marketplace, the last 8 to 18 and 3 to 7 percent. The cost optimization practice runs the program with you.
Frequently asked questions
Where do enterprises overspend on AWS?
Five places with measurable signatures: over committed Savings Plans and Reserved Instances at 15 to 35 percent above realized usage, idle and oversized resources at 10 to 20 percent of the run rate, untagged spend at 25 to 45 percent of the bill, egress at 4 to 9 percent.
And on demand workloads at scale at 8 to 18 percent of compute, with marketplace sprawl adding 3 to 7.
The rate card explains almost none of the growth.
What is the AWS commitment tax?
The gap between committed and realized usage: Savings Plan and Reserved Instance capacity sized to growth that did not arrive is paid every hour regardless of use, and the effective rate on the workload that did run ends higher than a smaller, well sized commit would have produced.
The rule is sizing to the measured steady state baseline and buying growth as it arrives.
Why does untagged AWS spend matter so much?
Because cost without an owner cannot be optimized: untagged spend ran 25 to 45 percent of bills at first read, making allocation directional and blocking every line by line recovery move.
The fix is process before tooling, a small set of mandatory tag dimensions enforced at the account or service control policy level, and tagging is the lever rather than the goal, the hook everything else pulls on.
How much does AWS egress really cost?
More than any budget planned: cross availability zone, cross region, and internet egress together moved monthly bills by 4 to 9 percent where data movement was never engineered as a cost line, priced small per gigabyte and large at terabyte scale.
It appears in no commitment vehicle, so the discipline is architectural, the honest unit is dollars per million calls, and the workload that crosses regions on every call is a design decision wearing a bill.
Is AWS cost recovery a negotiation with AWS?
No, and that is the point: the five categories all flow through standard meters, the recovery moves, resizing commits, sweeping idle resources, enforcing tags, re architecting egress, and covering on demand scale, are all internal.
And disciplined buyers recovered a material share of the bill at the next reconciliation without AWS at the table.
The work is operational, on a quarterly cadence, not procurement.
How do you stop AWS overspend from returning?
With cadence: the quarterly commit review against realized usage, the idle sweep against a baseline, the tag enforcement that keeps owners attached to cost, and egress priced at design time rather than discovered on the bill.
The categories compound in the same estate when unwatched, and the reconciliation calendar is the enforcement mechanism that keeps the five signatures from rebuilding.
Negotiating AWS 3: The Discount Stack
Reserved Instances, then Savings Plans, then your negotiated rate, multiplied not added. Savings Plan bundling, marketplace as shortfall insurance rather than saving, and the effective rate that turns a 15 percent headline into 11.