In general, you can't assume people won't deep-link your content, and that includes embedding.Technically, no, you can't with current protocols. However, this has been regarded as bad manners ("hot linking", "bandwidth theft", etc.) since forever.
Taking steps to protect against or take advantage of traffic spikes is the responsibility of a content provider.
The trouble is, with the increasing concentration of attention on the web in the hands of a few high profile traffic aggregators and social networking sites, this kind of argument holds less credibility than it used to. It's all very well saying if you put something on-line then you're responsible for supporting it, but the reality is that someone else suddenly diverting large amounts of traffic to your site is statistically indistinguishable from a denial of service attack.
If it's qualified traffic and being directed to somewhere you welcome the extra visitors, you might appreciate it. If it's unqualified traffic and overloading your servers at your and/or your normal visitors' expense, you probably won't appreciate it. If it's not even being directed to your normal site but instead deliberately freeloading on your servers and bandwidth via hot-linking, I think you're at least well into a grey area in terms of both ethics and legality.