⌘ K
Partner with us
Insights
All insightsResourcesAboutTalk to usPartner with us

Shadow AI Has a Price Tag Now, and Finance Just Found It

Explore the hidden cost of shadow AI, from duplicate tools and unmanaged subscriptions to security exposure, compliance risk, and wasted finance spend.

By Editorial Team

6 min read

Shadow AI Has a Price Tag Now, and Finance Just Found It
AI & DATA

Nobody budgeted for the AI tools employees are actually using. Finance is starting to find the bill anyway — in expense reports, corporate card statements, and the cleanup invoice that shows up after something goes wrong.


The AI governance conversation at most companies still runs through IT: which models are approved, which data can touch them, who signs off on a new tool. It is a sensible conversation, and it is looking at the wrong ledger.

The actual spend on unapproved AI tools is not sitting in a system IT controls. It is sitting in expense reports, personal corporate-card charges under the approval threshold, and departmental software budgets that nobody in security ever reviews. Finance finds it the way finance finds most things nobody wanted found — by accident, during a routine reconciliation, months after the fact.

The discovery problem is now a majority-case problem

Gartner's most recent survey of 302 cybersecurity leaders found that 69 percent of organizations suspect or have direct evidence of employees using prohibited public generative AI tools. Engineering teams lead adoption at 79 percent. Only about a third of that usage runs through an approved enterprise account — the rest is a personal login, a free tier, or a browser extension that nobody in IT provisioned and nobody in finance coded correctly.

A separate industry survey, the 2026 Cost of Insider Risks Global Report, found that 65 percent of organizations discovered employees using unapproved AI tools with organizational data within the past twelve months, and identified shadow AI as the leading driver of negligent insider incidents — incidents that now average $19.5 million a year per organization across the broader insider-risk category. IBM's own data on breaches tied to unsanctioned AI use puts the average cost of one at roughly $4.2 million.

None of this is a security team failing to do its job. It is a security team doing exactly the job it was given, on exactly the systems it was told to watch — while the actual spend and the actual risk accumulate one level down, in accounts payable.

Where it actually shows up, and why each place misses most of it

Ask a CFO where shadow AI spend would surface and the honest answer is: nowhere reliably. It is scattered across systems that were never built to categorize it, each catching a different slice and missing the rest.

Visual 1 — Where shadow AI spend actually surfaces, and what each system misses

Where it hides

What gets caught

What gets missed

Corporate card statements

Recurring charges above the reconciliation threshold

Charges under the threshold, or billed to a personal card and expensed as "software"

SaaS spend management tools

Known vendors with recognizable line items

New or rebranded AI products the tool has no category for yet

IT asset inventories

Tools provisioned through SSO or an approved vendor list

Free-tier and browser-based tools that never touch provisioning

Security data-loss monitoring

Traffic to a known list of AI domains

Traffic through a personal device, a mobile app, or an unlisted domain

How to read it: Each system is doing its job. None of them was built to answer the specific question "what AI tools are we actually paying for and feeding data to," which is why the honest answer to that question, at most companies, is still "we don't fully know."

The subscription is the cheapest part

The instinct is to treat this as a procurement problem — consolidate the logins, cut the duplicate subscriptions, done. That undercounts the exposure by a wide margin.

Among organizations whose employees use AI chatbots for work, the same Cost of Insider Risks research found that 36 percent route customer and client data through them, 33 percent route IT credentials and access requests, 31 percent route employee personal and HR data, and 30 percent route financial data — into tools that were never risk-assessed, never covered by a data processing agreement, and in most cases never told anyone existed. Only 28 percent of organizations have deployed AI-specific data-loss prevention, and just 26 percent report having already experienced a sensitive data exposure through an AI tool in the past year.

The subscription fee is the part with a clean invoice. The data exposure, the compliance gap, and the breach-response bill are the parts that show up later, in a different budget, traced back to a decision nobody remembers approving because nobody approved it.

What to check this quarter

  1. Pull twelve months of corporate card data and search for AI-adjacent vendor names — not just the obvious ones. New entrants rebrand faster than finance categorization keeps up.

  2. Ask department heads directly what AI tools their teams use day to day, separate from what's been formally procured. The gap between the two answers is the actual exposure.

  3. Check whether any AI tool in regular use has a signed data processing agreement. If finance can't produce one on request, treat that as the finding, not as an oversight to quietly fix.

  4. Decide, explicitly, whether unsanctioned AI use is being treated as a policy violation or as a demand signal. The 21-point drop in outright AI bans over the past year suggests most companies have already made this decision without saying so out loud.

What this changes

Treating shadow AI purely as an IT governance question keeps the response inside a team that cannot see the spend and cannot see the data flows that matter most — the ones running through expense reports and personal accounts rather than the corporate network. Finance has visibility IT does not; IT has risk context finance does not. Neither has the whole picture alone, which is exactly the condition that let this go unmeasured for as long as it has.

The companies ahead of this are not the ones with the strictest ban. They are the ones that ran the card-statement search, found the number, and decided — with an actual figure in front of them instead of a policy in the abstract — whether to fund the tools people are already using or fund the controls to stop them. Either answer is defensible. Not knowing which one you've chosen is not.


Sources and method. A BusinessInfomatics original. Insider-risk cost and shadow AI discovery figures ($19.5 million average annual insider risk cost; 65 percent of organizations discovering unapproved AI tool use within 12 months; data-category exposure rates of 36/33/31/30 percent; 28 percent AI-specific DLP deployment; 26 percent reporting sensitive data exposure via an AI tool) from the 2026 Cost of Insider Risks Global Report, as summarized by Kiteworks. Gartner survey figures (69 percent suspected/evidenced prohibited GenAI use across 302 cybersecurity leaders; 79 percent engineering adoption; roughly one-third of usage through approved accounts) and the average $4.2 million cost of a shadow-AI-linked breach per IBM Security, and the 28-to-7-percent decline in outright AI bans, as compiled by Second Talent. Figures are dated where stated and are not independently re-verified beyond the cited compilations.