/

Case Studies

Box can now throttle you before you hit your limit

Stani Mihov

Founder & CEO

·

TL;DR

Vendor: Box
Document: Fair Use Policy
Date detected: June 27, 2026
Key change: A new "Remedying Unfair Consumption" section lets Box notify your billing contact and throttle, rate limit, or temporarily suspend service when enterprise-wide API or AI usage exceeds or approaches your entitlement, held in place until the overage is remedied and/or billing is paid in full

Box's Fair Use Policy gained a new enforcement section and lost a paragraph that explained how platform usage is measured. Together they let Box restrict service for overage while telling customers less about how the underlying measurement works.

The change

On June 26, 2026, Box updated its Fair Use Policy. Venpo detected the change automatically as soon as the revised policy was posted.

The update did two things: it added a new enforcement section, and it removed a paragraph that described how platform usage is measured. The Fair Use Policy governs how every account can use the service, including API and AI consumption, so a change to what Box can do when usage runs high is exactly the kind of update that rarely reaches the team that approved the tool.

What changed

The June 26 revision made two customer-affecting changes:

  • A new Section 1(e), "Remedying Unfair Consumption," giving Box explicit rights to notify your billing contact about measured overage and to apply usage controls such as throttling, rate limiting, or temporary suspension when enterprise-wide resource usage exceeds or approaches your entitlement

  • The removal of the paragraph in Section 2 (Platform Use Limits) stating that Platform Resource usage was measured on a prior twelve-month average and that Platform Bandwidth was measured separately from user bandwidth

One adds an enforcement mechanism. The other removes the methodology that told customers how the underlying measurement worked.

The trigger is "approaches," not just "exceeds"

Box already returns a "429 Too Many Requests" error when API traffic crosses its limits, and its Box AI section already allows rate limiting. The new section is different in two ways.

First, the operative text says Box may apply controls if a customer "exceeds or approaches any Excess Usage limit." Enforcement is no longer tied only to going over; approaching the limit is enough to trigger it.

Second, the controls remain in place "until the overage is remedied and/or all billing issued by Box is paid in full." The throttle or suspension is linked to payment, so a billing dispute or a slow internal approval can keep the restriction active. The trigger covers enterprise-wide resources named explicitly as API Calls and AI Units, applied at the organization level and routed through your then-current billing contact. Box publishes the underlying API thresholds in its rate limit documentation.

Why this matters

A Fair Use Policy is part of the contract that governs day-to-day access to a vendor, and it changes with little notice and real operational consequence. This is the category of change covered in our analysis of the hidden risk of vendor legal changes, and it is why vendor contract monitoring belongs in the same tier as security review.

When an enforcement clause lets a vendor throttle or suspend service tied to billing, the operational risk stops being abstract. An automated integration or AI workflow that runs close to its allotment can be slowed or paused, and the team that approved Box at onboarding approved a different policy than the one in force today. The removed measurement paragraph compounds this, because the document now says less about how Box decides you are over the line.

Potential impact for SaaS companies

Companies that rely on Box for API integrations or AI features may want to review whether:

  • their integrations or AI workflows run close enough to entitlement to risk triggering controls

  • the billing contact on file is current and monitored, since Excess Usage notices route there

  • their Platform Resource consumption is still understood now that the twelve-month-average methodology is no longer stated in the policy, against the limits shown on the Box pricing page

  • their runbooks account for service continuing to be throttled until billing is paid in full

For teams that depend on Box inside production workflows, an unexpected throttle is an availability issue, not just a billing one. Tracking this kind of change across a full vendor portfolio is where continuous vendor risk monitoring becomes structural rather than periodic.

How Venpo detected it

Venpo continuously monitors vendor legal documents and detects changes as they happen. When Box posted its revised Fair Use Policy, Venpo immediately:

  • detected the new and removed clauses as soon as the document was published

  • isolated the new "Remedying Unfair Consumption" section and its operative language

  • flagged the enforcement expansion and the removed measurement methodology

  • rated each change and surfaced the customer-affecting impact

Instead of discovering a new throttle-and-suspend right during an incident or the next renewal review, teams understood the change on the day it took effect.

Business outcome

Companies that caught this change early were able to:

  • check whether any integration or AI workflow runs close to its entitlement

  • confirm the billing contact who would receive an Excess Usage notice

  • brief engineering and operations that throttling can persist until billing is settled

  • revisit Platform Resource assumptions now that the measurement paragraph is gone

Instead of reacting to a slowed or suspended service mid-month, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.

Key takeaway

A Fair Use Policy update can change what a vendor is allowed to do to your service overnight, and the only way to know it happened is to be watching the document when it changes. Box's June 26 revision added a section that lets it notify your billing contact and throttle, rate limit, or temporarily suspend service when enterprise-wide API or AI usage exceeds or approaches your entitlement, held in place until the overage is remedied and/or billing is paid in full. Venpo detected it automatically as the revised policy went live. A closer look at why scheduled reviews keep missing this kind of change is in our comparison of manual vs automated vendor monitoring.

The change

On June 26, 2026, Box updated its Fair Use Policy. Venpo detected the change automatically as soon as the revised policy was posted.

The update did two things: it added a new enforcement section, and it removed a paragraph that described how platform usage is measured. The Fair Use Policy governs how every account can use the service, including API and AI consumption, so a change to what Box can do when usage runs high is exactly the kind of update that rarely reaches the team that approved the tool.

What changed

The June 26 revision made two customer-affecting changes:

  • A new Section 1(e), "Remedying Unfair Consumption," giving Box explicit rights to notify your billing contact about measured overage and to apply usage controls such as throttling, rate limiting, or temporary suspension when enterprise-wide resource usage exceeds or approaches your entitlement

  • The removal of the paragraph in Section 2 (Platform Use Limits) stating that Platform Resource usage was measured on a prior twelve-month average and that Platform Bandwidth was measured separately from user bandwidth

One adds an enforcement mechanism. The other removes the methodology that told customers how the underlying measurement worked.

The trigger is "approaches," not just "exceeds"

Box already returns a "429 Too Many Requests" error when API traffic crosses its limits, and its Box AI section already allows rate limiting. The new section is different in two ways.

First, the operative text says Box may apply controls if a customer "exceeds or approaches any Excess Usage limit." Enforcement is no longer tied only to going over; approaching the limit is enough to trigger it.

Second, the controls remain in place "until the overage is remedied and/or all billing issued by Box is paid in full." The throttle or suspension is linked to payment, so a billing dispute or a slow internal approval can keep the restriction active. The trigger covers enterprise-wide resources named explicitly as API Calls and AI Units, applied at the organization level and routed through your then-current billing contact. Box publishes the underlying API thresholds in its rate limit documentation.

Why this matters

A Fair Use Policy is part of the contract that governs day-to-day access to a vendor, and it changes with little notice and real operational consequence. This is the category of change covered in our analysis of the hidden risk of vendor legal changes, and it is why vendor contract monitoring belongs in the same tier as security review.

When an enforcement clause lets a vendor throttle or suspend service tied to billing, the operational risk stops being abstract. An automated integration or AI workflow that runs close to its allotment can be slowed or paused, and the team that approved Box at onboarding approved a different policy than the one in force today. The removed measurement paragraph compounds this, because the document now says less about how Box decides you are over the line.

Potential impact for SaaS companies

Companies that rely on Box for API integrations or AI features may want to review whether:

  • their integrations or AI workflows run close enough to entitlement to risk triggering controls

  • the billing contact on file is current and monitored, since Excess Usage notices route there

  • their Platform Resource consumption is still understood now that the twelve-month-average methodology is no longer stated in the policy, against the limits shown on the Box pricing page

  • their runbooks account for service continuing to be throttled until billing is paid in full

For teams that depend on Box inside production workflows, an unexpected throttle is an availability issue, not just a billing one. Tracking this kind of change across a full vendor portfolio is where continuous vendor risk monitoring becomes structural rather than periodic.

How Venpo detected it

Venpo continuously monitors vendor legal documents and detects changes as they happen. When Box posted its revised Fair Use Policy, Venpo immediately:

  • detected the new and removed clauses as soon as the document was published

  • isolated the new "Remedying Unfair Consumption" section and its operative language

  • flagged the enforcement expansion and the removed measurement methodology

  • rated each change and surfaced the customer-affecting impact

Instead of discovering a new throttle-and-suspend right during an incident or the next renewal review, teams understood the change on the day it took effect.

Business outcome

Companies that caught this change early were able to:

  • check whether any integration or AI workflow runs close to its entitlement

  • confirm the billing contact who would receive an Excess Usage notice

  • brief engineering and operations that throttling can persist until billing is settled

  • revisit Platform Resource assumptions now that the measurement paragraph is gone

Instead of reacting to a slowed or suspended service mid-month, they adapted on their own schedule. This is the difference between operating with current information and operating on assumptions from the last review cycle.

Key takeaway

A Fair Use Policy update can change what a vendor is allowed to do to your service overnight, and the only way to know it happened is to be watching the document when it changes. Box's June 26 revision added a section that lets it notify your billing contact and throttle, rate limit, or temporarily suspend service when enterprise-wide API or AI usage exceeds or approaches your entitlement, held in place until the overage is remedied and/or billing is paid in full. Venpo detected it automatically as the revised policy went live. A closer look at why scheduled reviews keep missing this kind of change is in our comparison of manual vs automated vendor monitoring.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago