Somewhere between a quarter and a third of everything your company spends on AI tools never passes through anyone who could stop it. Gartner puts the figure at 25 to 35 percent of enterprise AI tool spending sitting entirely outside IT visibility, growing at roughly 40 percent a year. That is not a rounding error on a small line item. It is a structural blind spot on the fastest-growing category in most technology budgets, and finance teams are being asked to govern it without being allowed to see it.
Shadow AI has been discussed for two years now, almost always as a security story. The cost story is the one that gets finance in trouble, and it has barely started.
Security noticed shadow AI first. Finance is still catching up.
The security framing came fast because the risk was obvious. A 2025 TELUS Digital survey found that 68 percent of employees were reaching generative AI assistants through personal accounts rather than company-approved platforms, and 57 percent admitted to pasting confidential information into publicly available tools. IBM’s breach research gave that behavior a price: organizations with high levels of shadow AI averaged $4.74 million per breach, against $4.07 million for those with little or none. A $670,000 premium per incident is the kind of number that gets a CISO a budget line.
What that framing quietly assumes is that the damage shows up as a breach. Often it shows up as an invoice instead. When an employee expenses a Claude subscription, drops a team onto a Cursor plan, or wires up an OpenAI key against a corporate card, the security team may never notice because nothing leaked. Finance notices eventually, on the statement, months after the spend became a habit and long after the moment when a conversation could have redirected it. The same decentralization that makes shadow AI a data-governance headache makes it a budgeting headache, and the second problem is bigger for most companies than the first.
AI spend hides better than SaaS sprawl ever did
Anyone who has run a SaaS sprawl cleanup knows the drill: pull the expense reports, match charges to owners, kill the duplicates, consolidate the survivors. That playbook worked because SaaS, for all its mess, was legible. A subscription is a recurring charge for a named seat. You can count seats, audit logins, and see the renewal coming.
AI spend breaks every one of those assumptions. It is consumption-priced, so there is no seat to count and no stable monthly figure to reconcile; a quiet month and a runaway month look completely different on the statement. It rides on personal accounts and corporate cards more than on procurement contracts, so it never enters the vendor system that a SaaS spend management process is built to watch. And it is metered per token, which means the unit you are trying to govern is invisible to everyone except the person typing the prompt. A department can triple its usage in a quarter without a single new line appearing anywhere finance looks.
That is why the old discovery step does not transfer cleanly. The shadow IT tooling most companies already own was built to find unsanctioned SaaS apps by their login patterns and their recurring charges. It was not built to find a spike in token consumption on an API key that a developer created eight months ago and forgot to tell anyone about.
The overrun numbers point back to spend nobody logged
When you read the 2026 AI budget surveys, the reflex is to blame bad forecasting. That is only half the story. A WitnessAI report published in July 2026, based on 300 business executives, found that 68 percent of companies had overrun their AI budgets and 33 percent overran “mostly or always.” The same survey traced a specific cause: 30 percent said unmanaged AI usage directly caused cost overruns, and 27 percent had initiatives delayed or canceled because of it.
Read those two numbers together and the pattern is clear. A meaningful slice of the overruns is not the sanctioned project going over. It is the spend that was never in the plan because it was never in anyone’s field of view. You cannot forecast a line you cannot see, and you cannot cut one you never knew existed. This is the same AI budget overrun paradox that shows up even at mature FinOps shops: teams get better at optimizing the spend they track while the untracked spend grows underneath them.
The ROI picture makes the visibility gap more expensive. Only 9 percent of the WitnessAI respondents said more than three-quarters of their AI initiatives delivered a measurable financial return. CloudZero, in a separate survey, found 87 percent of finance leaders under pressure to connect AI spending to business outcomes within a year, and only 22 percent already doing it. You are being asked to prove the return on a category, and a third of the spend in that category is not even on the map.
How I’d treat it: discovery before governance
In 20-plus years running IT operations, and in fractional COO work since, the failure mode I have watched most often is a company answering a visibility problem with a policy. Someone writes an AI spending policy, circulates it, and considers the problem handled. Six months later the shadow spend is larger, because a policy governs the behavior you can observe and does nothing about the behavior you cannot.
Discovery has to come first, and for AI it has to be built differently than the SaaS version. Three moves do most of the work.
Start with the money trail you already control. Pull corporate card and expense data and search it for AI vendors by name, not by category, because these charges almost never file themselves under “software.” The known names (OpenAI, Anthropic, Google, Cursor, Perplexity, and the fast-moving long tail) are where the first surprises live.
Then go after the API keys, which is where the real spend hides. Consumption billing means a single forgotten key can outspend an entire team of seat-based subscriptions. Every provider exposes usage data through its console or API. Someone has to own the job of pulling it, because it does not surface on its own.
Finally, treat AI as its own spend category with a named owner, the way you would treat cloud. The reason cloud cost allocation works is that someone is accountable for tagging spend to the team that caused it. AI needs the same accountability before it needs a policy, because allocation is what turns an invisible aggregate into a set of decisions specific people can be asked about.
The tools are arriving, and they only see what you connect
The vendors have noticed the gap. On July 14, 2026, 1Password moved into AI cost management, adding AI Spend and Consumption Management to its SaaS Manager. It connects directly to vendor APIs, pulls daily token-level consumption for Anthropic, OpenAI, and Cursor, and normalizes it into one dashboard for IT and finance. It launched in public preview with broad availability promised for fall 2026. In August, MuleSoft shipped cost management for its Omni Gateway, pricing every request against the rate you actually pay and breaking spend down to the individual agent, which is the AI gateway pattern applied to the visibility problem rather than only to routing.
Both are genuinely useful, and both share the same limit worth stating plainly: a tool that connects to vendor APIs can only see the accounts and keys you connect it to. It gives you a clean dashboard for the spend you already knew about and does nothing for the personal-account subscription on someone’s expense report or the shadow key nobody registered. Tooling closes the gap for known vendors. It does not do your discovery for you. If you buy one of these before you have run the money-trail sweep, you will get a confident, well-designed dashboard that is quietly missing a third of the picture, which is arguably worse than no dashboard at all.
Visibility is the whole job right now
For most FinOps and finance teams, the instinct with AI is to jump straight to rate optimization: cheaper models, prompt caching, batch discounts, committed-use deals. All of that matters, and none of it matters yet if you cannot see a third of what you are spending. Optimizing the visible two-thirds while the invisible third compounds at 40 percent a year is motion, not progress.
The honest first question for the next few quarters is not “how do we make our AI spend cheaper.” It is “do we actually know what our AI spend is.” Until the answer is yes, every forecast is a guess, every allocation is incomplete, and every ROI conversation is being held over a number that is missing its fastest-growing part. Shadow AI stopped being only a security problem the moment it became the biggest thing finance cannot see. Getting it back into view is the work.
