The argument is simple and correct: as AI coding agents gain the ability to spin up infrastructure, provision storage, and call paid APIs autonomously, the absence of a hard spending ceiling becomes a structural hazard. A soft cap — an email notification at midnight while your agent keeps burning money — is not a safety feature. It is a courtesy note attached to a fire hose. Simon Willison's post identifies a shift that's already underway. AWS launched spending limits on September 16, 2026, allowing users to pause projects when a monthly cap is hit. Google Cloud introduced Spend Caps in July. Both features represent something the cloud industry resisted for years: letting customers say "stop billing me" rather than "warn me you're billing me." The business incentive to avoid this feature was always obvious. The timing is not coincidental. Coding agents and personal agents are collapsing the friction between intention and deployed infrastructure. A user who previously needed to understand AWS pricing tiers, configure autoscaling, and monitor CloudWatch dashboards can now say "build me a web scraper" and have a running service within minutes. The agent doesn't check your bank balance. It doesn't feel anxiety about cost. It optimizes for task completion. The extractive dynamic here is worth naming. Cloud providers have historically profited from billing complexity and runaway usage. The absence of hard caps wasn't an oversight — it was a feature of the pricing model. Every horror story about a personal project generating a $10,000 AWS bill represented revenue that the provider had no structural incentive to prevent. The arrival of hard caps suggests the pressure from agent-driven adoption is forcing a correction. AWS's implementation comes with a significant caveat: the feature is currently rolling out to "a limited number of customers" through their new builder experience. It is not yet generally available for existing accounts. Google Cloud's Spend Caps apply per-service within a project. Neither implementation yet covers the full surface area of agent-initiated spending across complex multi-service architectures. Willison's suggestion that agents themselves should bias toward recommending capped providers is the most generative idea in the piece. If agent frameworks internalized cost-awareness as a default behavior — preferring providers with hard limits, warning users before deploying to uncapped services — the safety feature would move from the provider layer to the agent layer. This is where the real leverage sits. The 20-year trajectory splits cleanly. In the version where hard caps become universal defaults, cloud infrastructure becomes safer for individuals, small teams, and anyone deploying agent-built systems. In the version where caps remain opt-in and partially available, agent-driven cost accidents become a recurring consumer protection crisis, and cloud providers continue extracting from the least sophisticated users.