Between 20 and 40 percent of AI tools in use had never passed procurement or security review
AI adoption has outrun control in most enterprises, and the gap is not a policy failure. Tools arrived through expense claims and free tiers rather than through procurement, so there was no gate for them to fail.
Prepared by Redress Compliance · August 16, 2026 · GenAI advisory. 25 to 35 enterprise AI tool reviews, 2024 to 2025.
Executive summary
20 to 40 percent of AI tools in use had never passed procurement or security review. They did not fail a gate. They arrived through routes that had no gate, which is why a policy alone does not fix it.
Agreements were signed without confirming whether prompts train the vendor model. That is the decisive contract clause, and confirmation belongs in the agreement rather than on a documentation page the vendor can revise.
Three or four overlapping assistants were licensed across departments with no central owner, which is where AI budgets leak without any single purchase looking unreasonable.
Regulation is catching up through the NIST framework and the EU AI Act, so the registry that solves the spend problem is the same artefact the compliance question will require.
Three exposures, and what each one costs
Governance lagged adoption by a wide margin across the reviews, and it did so in three distinct ways that need different fixes.
| Exposure | What it looks like | What it costs |
|---|---|---|
| Shadow AI | Tools in use that never passed procurement or security review | Unknown data exposure and unbudgeted spend |
| Data terms | Agreements signed without confirming training use | A position that cannot be reversed once data has flowed |
| Overlap | Three or four assistants doing similar work in different departments | Budget leak with no single purchase looking unreasonable |
| No owner | Nobody accountable for the estate as a whole | All three of the above, permanently |
Shadow AI is not a compliance failure by the people using it. These tools arrived through expense claims, free tiers, and browser extensions, which are routes that never had a procurement gate to pass. Treating the result as non compliance misdiagnoses it and produces a policy nobody can follow. The fix is to create a gate that is light enough to use and then to make it the only route, rather than to enforce a gate that never existed against people who had no way to find it.
The registry solves the spend problem and the regulator asks for it anyway
Enterprise AI governance is usually framed as a risk exercise, which makes it compete for attention with every other risk exercise and lose. The reviews we ran suggest a more useful framing: the artefact that fixes the spend problem is the same artefact the regulatory question will require, so it can be justified on cost and delivered once. That artefact is a registry, with one owner, listing every AI tool in use, what it does, what data it touches, and what its contract says about training.
Start with the spend case because it is immediate. Three or four overlapping assistants licensed across departments was the norm rather than the exception, and no individual purchase looked unreasonable at the point it was made. A marketing team buying a writing assistant, a support team buying a summarisation tool, and an engineering team buying a coding assistant are each solving a real problem within budget. The waste is only visible from above, and nobody was looking from above because no one owned the estate. That is a leak a registry closes on its own, before any negotiation.
The data question is the one that cannot be fixed retrospectively. Agreements were signed without confirming whether prompts train the vendor model, and once data has flowed under those terms the position cannot be reversed by renegotiating them. Confirmation belongs in the agreement rather than on a documentation page, because documentation pages are revised unilaterally and an assurance you cannot produce later is not an assurance. This is the single clause worth holding a purchase over.
Then the regulatory overlay, which is arriving through the NIST framework and the EU AI Act and which asks broadly the same question: what AI is in use, who owns it, what does it touch. An organisation with a registry answers that in an afternoon. An organisation without one begins a discovery exercise under a deadline, which is the expensive version of the same work. Build the gate light and make it mandatory, because a heavy gate gets routed around and reproduces the shadow estate it was meant to prevent. The procurement framework sits in the AI procurement framework, and the wider library in the GenAI practice.
- Every risky clause flagged with the verbatim quote and page anchor
- Overlapping tools surfaced across departments, with consolidation costed
- Paste ready replacement language and an evidence trail for the response
What the gate and the registry need to hold
- One named owner for the AI estate, because every other control depends on somebody being able to see the whole of it.
- A registry entry per tool recording purpose, data touched, contract position on training, and the department that owns it.
- A light but mandatory review gate, light enough that people use it and mandatory enough that it is the only route. A heavy gate reproduces the shadow estate.
- Training use confirmed in the agreement, not on a documentation page, since documentation is revised unilaterally and cannot be produced as evidence later.
- An overlap review across departments, because three or four assistants doing similar work is normal and invisible from inside any one of them.
- Expense and free tier routes closed, since those are how the unreviewed tools arrived rather than any deliberate circumvention.
What the AI governance reviews showed, 2024 to 2025
Across roughly 25 to 35 enterprise AI tool reviews, governance lagged adoption by a wide margin:
Tools in use that had never passed procurement or security review, having arrived through routes with no gate to pass.
Overlapping assistants licensed across departments with no central owner, where no single purchase looked unreasonable.
Agreements were signed without confirming whether prompts trained the vendor model, which is the one exposure that cannot be corrected after the fact because the data has already flowed.
Regulation is catching up through the NIST framework and the EU AI Act. The registry that closes the spend leak is the same artefact those frameworks ask for, which is why the governance case can be made on cost and delivered once.
Watch the briefing · 4:33From Licenses to Subscriptions to AI Consumption: The Third Repricing of SoftwareWhy AI spend behaves unlike the two software pricing eras that preceded it.
Your first five moves
- Name one owner for the AI estate, because every control below depends on somebody being able to see all of it.
- Discover what is actually in use, through expense data, network telemetry, and browser extension inventory rather than by asking.
- Build the registry: purpose, data touched, contract position on training, owning department, for every tool found.
- Confirm training use in writing for each agreement, and treat an unconfirmed position as a reason to hold the purchase.
- Run an overlap review and consolidate, then put a light mandatory gate in front of new tools. The GenAI practice builds the registry with you.
Frequently asked questions
How much shadow AI is normal?
Between 20 and 40 percent of tools in use had never passed procurement or security review across the estates reviewed. They did not fail a gate; they arrived through expense claims, free tiers, and browser extensions, which are routes that had no gate.
Is shadow AI a compliance failure by staff?
Generally no, and treating it that way misdiagnoses the problem. People solving a work problem through a free tier were not circumventing a control, because no control existed on that route. The fix is creating a usable gate, not enforcing an absent one.
What is the decisive contract clause?
Whether your prompts train the vendor model. Confirm the exclusion in writing in the agreement rather than relying on a documentation page, because documentation is revised unilaterally and an assurance you cannot produce later is not an assurance.
Why can the data question not be fixed later?
Because once data has flowed under permissive terms, renegotiating those terms does not recall it. It is the one exposure on this list that is genuinely irreversible, which is why it is worth holding a purchase over.
Where do AI budgets actually leak?
Into overlap. Three or four assistants doing similar work were licensed across departments with no central owner, and no individual purchase looked unreasonable at the point it was made. The waste is only visible from above.
What should a registry record?
Purpose, data touched, the contract position on training, and the owning department, for every tool in use. That is enough to close the spend leak and to answer the regulatory question without a second exercise.
How heavy should the review gate be?
Light enough that people use it and mandatory enough that it is the only route. A heavy gate gets routed around, which reproduces exactly the shadow estate it was introduced to prevent.
Does regulation change the case?
It reinforces it. The NIST framework and the EU AI Act ask broadly what AI is in use, who owns it, and what it touches. An organisation with a registry answers in an afternoon; one without begins a discovery exercise under a deadline.
How do we find the tools nobody declared?
Through expense data, network telemetry, and browser extension inventory rather than by asking. Asking surfaces the tools people know are tools; it misses the ones that arrived as a feature inside something else.
What is the first move?
Naming one owner for the AI estate. Every other control on the list, discovery, registry, gate, overlap review, depends on somebody having visibility of the whole thing and the authority to act on it.
After the Signature
Part 6 of the Negotiating Anthropic series. With consumption pricing the money is won after signing, not at it. Routing, caching, batching, monitoring and the true up discipline that decides what the term actually costs.