A Norwegian startup has been landed with a 17,600 dollar bill for running Claude inside Microsoft Foundry, believing its Azure credits covered it. They didn't. And when it asked for the charges to be waived, Microsoft sent it to Anthropic and Anthropic sent it straight back. The Register has the story.
What happened
Vegalabs AS received 25,060 dollars in Azure credits through Microsoft's startup programme. In August it deployed Claude in Foundry for its analysis workloads, assuming that balance would pay for it.
It didn't: the sponsorship rules exclude Anthropic models bought via Azure Marketplace. While the sponsorship portal kept showing available credit, Marketplace charges were piling up elsewhere. Microsoft attempted to take 16,500 dollars from the card on file, and the invoiced total reached 17,600 dollars before tax. The card issuer declined it as suspected fraud. The company deleted the deployment within an hour of noticing, and on 8 September 21,168 dollars of unused credit expired.
Vegalabs admits two things: it didn't read the credit exclusions and it didn't set a budget alert. It disputes neither the usage nor the written rule. What it does say is that the deployment interface never made clear this was billed separately.
And that's where it turns ugly. Microsoft replied, in communications the outlet has seen, that Marketplace purchases run through a separate billing pipeline tied to the third-party publisher, that Azure support cannot waive or refund those charges, and that if Anthropic approves it, Anthropic can initiate the refund through Microsoft. Anthropic's support said the opposite: that Microsoft needs no authorisation from them to issue a refund. Of the seven support replies it got, four were AI-generated — including both from Anthropic — and they described the account as a student sponsorship, which it wasn't. Microsoft had nothing further to add when asked on 6 October; Anthropic didn't respond. This isn't a first, either: back in March there was a similar case with third-party model charges falling outside sponsored credit.
Why it matters
The real issue isn't Claude or Azure: it's that one console shows two separate sets of books and only one of them has a visible meter. The balance you can see isn't the balance that counts.
If you're about to put a third-party model inside someone else's cloud, five things I'd change today:
- Keep cloud consumption and Marketplace purchases separate in your head. A third-party model offered inside a cloud is usually a purchase from that publisher with the cloud acting as a till. Different invoice, different support, different rules.
- The budget alert goes in before the first deployment, not after the first scare. And not against the credit portal: against the subscription's actual cost management, which is where Marketplace charges surface.
- A card on file means credit stops being a ceiling. Almost nobody internalises this. On a credit-only sponsored subscription, the deployment won't even start. With a card saved, it starts and it charges. Your sponsorship goes from being a limit to being a floor.
- Before you sign anything, ask who can issue the credit note. Not who invoices you: who has the refund button. If the answer takes more than one sentence, you already know where you'll end up.
- Review your service list with its biller next to it. One column on the architecture sheet: service, who bills it, which balance pays it. Twenty minutes.
What doesn't change
Let's be fair to the other side, because this story can be told worse than it is.
The rule was documented. Microsoft's own Claude deployment guide says credit-only sponsored subscriptions aren't supported and that an account with a card on file gets charged to that card. Vegalabs doesn't dispute it. Nor does it dispute the usage: that spend came from its own workload, not from a metering error. 17,600 dollars with real consumption behind it isn't a mistaken invoice, it's an invoice.
And for now the money hasn't left: the bank declined the charge. This isn't the tale of a company ruined by a cloud, it's the tale of a company that didn't read an exclusion and now can't find anyone on the other end to sort it out. Two different things, and the second one is the serious one.
Our take
I think this is a design failure, not a small-print failure. The place to fix it costs one line of interface: a warning on the deploy button itself saying this model doesn't draw on your sponsored credit and will be billed separately. At that exact moment Microsoft already knows the subscription is sponsored and that the model goes through Marketplace. It has both facts and doesn't join them up. Burying that in a documentation page when you have it right there on screen is choosing to let the user find out late.
The automated support replies bother me more, and this will only grow. Four out of seven generated by AI, and misclassifying the account type on top. Look: first-line support is exactly where a model shines, because 90% of tickets are things already written down somewhere. The problem is that nobody contacts support for the 90%. They contact support for the exception. And a model trained to repeat what's already documented, faced with an exception, can do precisely one thing: send you elsewhere with impeccable grammar. That's not support, it's a redirector.
We've also seen this before. It's the old reseller gap: whoever bills you isn't whoever provides the service, and the refund lives right in between. We saw it with resold domains and hosting fifteen years ago and we're about to see it multiplied, because model marketplaces are building exactly the same commercial architecture. The more third-party publishers inside a single console, the more tickets that bounce.
What I'd do with a startup that's just been handed credits: get the card out of sponsored subscriptions, set an alert at 10% of the balance, and have a ten-minute conversation about what credit pays for and what it doesn't. Deeply boring, and it saves you weeks exactly like this one.
When someone asks us to put a model inside a business process, the first question isn't which model: it's who issues the invoice and who has the authority to cancel it. On AI projects running in someone else's cloud, that answer is worth more than the benchmark.
Any questions, tell me and we'll look at it.
Best, Vicente.
