Editorial photograph of an enterprise finance and procurement team reviewing corporate card spend on AI tools
Benchmarking Research / Shadow AI

Shadow AI spend. The off books bill.

Shadow AI is the AI tooling employees buy on corporate cards and personal accounts to ship work this quarter. It does not show up in the EA. It shows up in the bill, the data risk, and the 2027 plan procurement is about to build.

Contact Us Benchmarking Practice
500+Enterprise clients
$2B+Under advisory
Industry Recognized
500+ Enterprise Clients
$2B+ Under Advisory
11 Vendor Practices
100% Buyer Side Independent

Shadow AI is the AI tooling employees buy on corporate cards or personal accounts to ship work this quarter. It does not show up in the EA. It does show up in the bill, in the data risk, and in the 2027 budget that procurement is about to build.

The report at a glance
~6%
Median share of software spend running through shadow AI in a large enterprise
2 to 4x
The gap between the formal AI line and the real card category in most estates
Cards
The real meter for AI spend, not the EA
Quarterly
Pace at which shadow AI grows once the first card subscription lands

Key takeaways

  • Shadow AI runs between 4 and 9 percent of total software spend in large enterprises today, often two to three times the line in the formal AI budget.
  • The corporate card category, not the EA, is the real meter for enterprise AI spend in 2026.
  • Four tool families dominate the off books bill: ChatGPT and Claude, AI coding tools like Cursor, AI search tools like Perplexity, and individual Copilot or Gemini seats.
  • The buyers are line managers and senior individual contributors with a card and a deadline, not rogue actors trying to dodge procurement.
  • Blanket bans push shadow AI deeper into personal accounts and remove the only oversight a contract would provide.
  • Data exposure on personal accounts is the larger risk and the harder one to undo, because contract terms never covered the activity.
  • The pattern that works is consolidate the few high value tools, contract by category, and budget AI as its own line sized from the card data.

About this report

This report is a directional benchmark, not a price list. It draws on three inputs.

  • Our advisory engagement file. Anonymized, aggregated ranges drawn from enterprise AI category sweeps, audits, and contract consolidations our team supported between 2024 and 2025.
  • Vendor public pricing. The published seat and consumption prices of the AI tools that dominate the off books bill, cited in line through the report.
  • A benchmarking panel. A rolling set of comparable enterprise estates used to separate the EA line from the corporate card category.

We report bands and directions, not precise discounts. Where a single number appears, treat it as the middle of a range, not a guarantee.

How big is shadow AI spend in the enterprise?

Bigger than the EA suggests, and bigger than the formal AI line in the IT plan. In our advisory file the off books AI bill typically ran between 4 and 9 percent of total enterprise software spend by mid 2025, often two to three times the line that finance had budgeted for AI.

The headline understates the issue, because it lumps small experiments with material recurring cost. Once a tool clears six months of card renewals, it is a budget line in everything but name. By that point the EA has no record of it.

The size in bands, not points

Small enterprises see a smaller absolute number but a similar share. Mid market estates often run a higher share, because they lack a centralized AI roadmap that absorbs the demand. The largest enterprises see the largest absolute bill, even when the share looks modest.

Treat any single number as the middle of a range. Estate by estate, the spread between the formal AI line and the card category ran from a low multiple to nearly ten times in the cases we audited.

  • Small enterprise, under 500 staff. Shadow AI tends to be a handful of card subscriptions per function, typically 3 to 5 percent of software spend.
  • Mid market, 500 to 5,000 staff. Shadow AI commonly runs 5 to 9 percent of software spend, driven by tool fragmentation across functions.
  • Large enterprise, 5,000 plus staff. Shadow AI tends to settle at 4 to 7 percent of software spend, but the absolute dollars are large.

The EA understates AI spend by design

The EA is a procurement instrument. It books what was negotiated, not what is being used. AI tooling that arrived after the last renewal sits outside it by construction, and most AI tools have arrived in the last 24 months.

This is why a finance leader who reads only the EA sees a small AI line. The bill is real. It is just sitting in a different ledger.

SHARE OF OFF BOOKS AI CARD CATEGORY0%10%20%30%ChatGPT, personal or team~22 to 28% of card spend →Cursor and AI coding tools~14 to 20% of card spendClaude, personal or team~10 to 16% of card spendPerplexity and AI search~6 to 10% of card spendIndividual Copilot or Gemini~5 to 9% of card spendImage, audio, video AI tools~4 to 7% of card spendLong tail, 50 plus tools~12 to 18% of card spend, fragmented
Where the off books AI bill actually concentrates. Four tool families carry the majority of card spend across the estates we sampled in 2024 to 2025.

What tools dominate shadow AI today?

Four families show up in almost every audit. They are not obscure. They are the most used AI tools in the consumer market, layered onto enterprise card programs that procurement never sized for them.

General assistants on personal and team plans

ChatGPT and Claude lead the category. They land on personal accounts, on small team plans bought by a manager, and on individual Plus or Pro subscriptions paid by card. Each seat is small. The aggregate is meaningful.

Vendor terms on these plans are not the enterprise terms procurement would negotiate. The data handling on a personal ChatGPT account differs from an ChatGPT Enterprise contract, and the same applies to Anthropic for enterprise. The contract gap is the real exposure.

AI coding tools on developer cards

Cursor, GitHub Copilot for Business sold individually, and a small cluster of similar tools dominate the developer side of the shadow AI bill. Engineering leaders often buy them per team rather than through the EA because the seat price is below the approval threshold.

Public pricing is straightforward. Cursor pricing lists Pro and Business plans that any developer card can buy. The friction to procure is low, which is most of the reason these tools spread quickly.

Perplexity Pro and a handful of competitors show up across knowledge work functions. Marketing, strategy, and consulting style teams use them for daily research. They are usually billed monthly on individual cards.

The cost per seat is modest. The category becomes visible only when finance aggregates it across functions, which most card programs do not do by default.

Individual Copilot and Gemini seats

A surprising share of Microsoft Copilot and Google Gemini usage runs on individual or small team subscriptions bought outside the EA. These are often pilots that never got migrated, or seats added during a department initiative that finance never absorbed.

The enterprise contracts exist, the discounts are there to be won, and the seats are usually compatible with the SSO and data controls the EA already covers. What is missing is the migration.

  • General assistants. ChatGPT and Claude on personal, Plus, Pro, and small team plans.
  • AI coding. Cursor, individual Copilot for developers, and similar tools on developer cards.
  • AI search. Perplexity Pro and competitors across knowledge work functions.
  • Off EA Copilot and Gemini. Seats added by department initiatives and never migrated to the EA.
Share of software spend, low band, percentShare of software spend, high band, percentFormal AI line in IT budget2%6%Card category for AI tools5%18%All in AI spend, true picture7%24%
What finance budgets for AI against what the card category actually shows. The third bar is the picture procurement should plan against, and the one the EA alone cannot see.

Who is buying shadow AI, and on whose budget?

The buyers are line managers and senior individual contributors with a corporate card and a real productivity problem. They are not rogue actors. They are people trying to ship work inside the quarter.

Line managers with a card

A manager with a discretionary budget and a card can authorize a seat or a team plan in minutes. The seat sits below most card approval thresholds. The decision feels small at the time it is made.

Multiplied across a function, those small decisions become a category line item. By the time anyone aggregates them, the bill is a recurring cost the business already plans around.

Engineers and developer leads

AI coding tools are bought on developer or engineering cards faster than any other category. The productivity gain is visible per day, and the seat price sits comfortably below team budget thresholds.

The procurement gap here is not awareness. It is contract motion. Engineering moves faster than the EA cycle, and the tool is in production before procurement starts the negotiation.

Marketing, strategy, and operations

Knowledge work functions buy AI search and assistant seats on personal style accounts. The use case is daily research and drafting. The seat counts add up across teams, but each individual subscription looks small.

Whose budget the bill lands in

Most shadow AI is paid from departmental opex through corporate cards. Some lands as personal expense reports. A small share rides on a vendor invoice into accounts payable that no one mapped to AI.

None of these paths run through the EA. None of them carry the data terms a negotiated enterprise contract would include. That is the cost behind the cost.

Why does shadow AI grow faster than the EA?

Because the EA was built to control sizable, planned commitments. Shadow AI runs on small, opportunistic ones. The friction the EA needs to function is exactly what makes a card subscription feel easier.

Friction at the wrong end

An EA cycle is months. A card subscription is minutes. When the productivity gain is felt today and the approval costs a quarter, the rational buyer pays the card.

This is not a failing of procurement. It is a structural mismatch between how AI tools come to market and how enterprise software is bought. The market moved. The instrument has not caught up yet.

Approval thresholds below seat price

Most AI tools price at a level that sits comfortably below the threshold at which a card needs procurement involvement. The category grows one seat at a time, beneath the radar that was designed to stop large purchases.

The fix is not a lower threshold. A lower threshold paralyzes the entire card program. The fix is a category sweep that aggregates the small purchases and brings the total under management.

The attach mechanic

Once a few people in a team use an AI tool, the rest follow. Attach behavior inside a team runs faster than any procurement cycle, because the productivity gain is visible in shared work product within a week.

This is why the shadow AI bill compounds quarter by quarter. The first seat anchors the team. The next seats arrive on the back of the first, on the same card program, with no fresh approval needed.

  • Friction. The EA cycle is months while the seat is minutes.
  • Thresholds. Seat prices sit below the card approval line by design.
  • Attach. Intra team adoption compounds faster than procurement can review.

Where bans go wrong, and what to do instead

Where the common advice on banning shadow AI is wrong

The standard procurement reaction is to ban shadow AI to control it. We disagree as a default. In the enterprises we have audited, blanket bans pushed shadow AI deeper into personal accounts and out of any governance, while the underlying productivity demand kept growing. The buyer side move is to consolidate the high value shadow tools into enterprise contracts with data controls, govern the rest with a clear acceptable use policy, and treat the corporate card category as the real meter rather than the EA. The ban removed the audit trail. It did not remove the spend.

Editorial photograph of a procurement and finance team auditing software expenses on corporate cards
Shadow AI does not show up in the EA. The real meter is the corporate card category, and the number is bigger than procurement expects.
Bigger
Than procurement sees
Cards
The real meter, not the EA
Quarterly
Where shadow AI grows

Source: Redress Compliance advisory engagement file, 2024 to 2025.

A blanket ban does not stop shadow AI. It removes the receipts. The off books bill keeps growing on personal accounts where the security team cannot see it and the contract never reaches.

How does shadow AI create data exposure beyond cost?

The data risk is the larger story, and the harder one to put back together later. Cost can be repriced at the next renewal. A leak that traveled into a model cannot be recalled.

Prompts on personal accounts

Personal account terms differ from enterprise terms in ways that matter for confidential work. Vendor enterprise contracts often exclude prompts from training and add audit rights. Personal account terms generally do not.

An employee pasting an internal document into a personal ChatGPT account is doing useful work. They are also placing that document on a vendor account that was never reviewed by security and carries no enterprise data handling commitments.

Code and source data

AI coding tools require source access to be useful. On a personal subscription, that means proprietary code sitting on a vendor account no security team has signed off. Even where vendors offer enterprise tiers with stronger controls, the personal tier is what got bought first.

The retrofit is consolidation, not a ban. Move developers from personal subscriptions to an enterprise contract with the data controls security needs, and the productivity is preserved while the exposure is closed.

Records and audit obligations

Regulated industries carry record retention and audit obligations that shadow AI quietly breaks. A regulator does not care that the seat was bought on a card. The obligation sits with the enterprise.

For financial services, life sciences, and the public sector, this is the part of shadow AI that has to be closed first, ahead of the cost discussion. The compliance exposure compounds faster than the bill.

  • Personal account prompts. Sit on terms the enterprise never accepted.
  • Proprietary code. Ends up on vendor accounts no security review has covered.
  • Records and audit. Obligations the enterprise still owns, with no governance trail.

How do finance and procurement bring shadow AI back into the budget?

By doing it as a category, not as a tool list. The pattern that works in our advisory file is consolidate, contract, and govern, with finance reading the card data as the true demand signal.

Sweep the cards first

The fastest path to the off books bill is a category sweep of the corporate card data. A short list of vendor name patterns and merchant categories surfaces 80 percent of the bill in a single afternoon.

The output is not a witch hunt. It is a category map that finance and procurement can read together and use as the input for the contract round.

Consolidate the few that matter

Three or four enterprise contracts usually cover the bulk of the bill. One general assistant vendor, one AI coding contract, one AI search contract, and one negotiated Copilot or Gemini line typically close most of the exposure.

Consolidation has to keep at least one credible alternative alive in each category. Without an alternative, the next renewal is priced against a buyer with no leverage, which is the standard advice the contrarian section warned about.

Govern the rest with a policy and a budgeted line

The long tail of tools that does not warrant a contract still needs governance. A short acceptable use policy and a budgeted central AI line give finance a place to plan the spend and security a place to set the rules.

The policy should be one page. It should name the approved categories, the prohibited uses, the data classes that may not leave the enterprise account, and the path to request a new tool. Anything longer will not be read.

The pattern in one line

Consolidate the high value tools, contract by category, govern the rest with a policy, and budget AI as its own line sized from the card data. Repeat at every renewal cycle and at every quarterly card review.

  • Sweep. The corporate card data to map the actual off books bill.
  • Consolidate. The high value categories into a small number of enterprise contracts with data controls.
  • Govern. The long tail with a one page acceptable use policy.
  • Budget. AI as a separate line sized from the card data, not from the request queue.

How does shadow AI vary by sector and company size?

Sector and size shape the off books bill more than the headline number suggests. Regulated industries carry more compliance risk per dollar. Mid market estates carry more fragmentation. Large enterprises carry larger absolute dollars on smaller percentages.

Financial services

Financial services sees the highest compliance exposure from shadow AI, because record retention and customer data handling rules apply equally on the card and in the EA. The bill is usually moderate. The risk is high.

Life sciences and healthcare

Life sciences carries similar exposure on patient and research data, with additional pressure from regulators reviewing AI used in clinical workflows. The category sweep here usually surfaces less spend and more risk to close.

Technology and digital native firms

Technology firms carry the largest absolute card category for AI tools, with developer tools and general assistants both heavy. The compliance risk is lower for most use cases, but the cost story is larger.

Public sector

Public sector estates often have the lowest absolute spend and the strictest rules. The shadow AI conversation in these estates is usually about closing personal account use entirely, not about contract consolidation.

A practical map of the off books AI category

Below is the comparison table we use with finance leaders to size the off books bill against the formal AI budget. Treat each row as a typical band, not a per estate number.

Shadow AI category map: formal AI line against the card category

CategoryTypical formal lineTypical card categoryMultiplier, card over formalDominant buyer
General assistants, ChatGPT, ClaudeSingle EA pilot, often under 0.5%1 to 3% of software spend3 to 6xLine managers
AI coding, Cursor, individual CopilotOften zero in the EA0.5 to 2% of software spendEffectively infiniteEngineering leads
AI search, Perplexity, similarRarely a formal line0.3 to 1% of software spend5 to 10xKnowledge workers
Individual Copilot or Gemini seatsInside the EA, but undersized0.5 to 1.5% of software spend2 to 4xDepartment pilots
Image, audio, video AI toolsRarely contracted0.2 to 0.7% of software spend5 to 8xCreative and marketing
Long tail, 50 plus toolsEffectively zero1 to 3% of software spendEffectively infiniteMixed across functions

What does the shadow AI pattern say about the 2027 AI budget?

Up materially, with the planning input coming from card data rather than the request queue. Procurement teams that size 2027 AI from formal asks will understate by the same multiplier the off books bill shows today.

The base case

The base case is that the four dominant tool families remain dominant. Pricing will rise modestly on the general assistants, faster on the AI coding tools, and the AI add ons embedded in the EA will keep attaching seats.

For most enterprises this means an AI line that runs at 6 to 10 percent of software spend by mid 2027, depending on how much of the card category gets consolidated into negotiated contracts.

The attach risk

The faster moving risk is in attach. Once a department lights up an AI add on, the seat count expands inside the next two quarters. A 2027 plan needs an attach assumption, not a fixed seat count.

Gartner has flagged AI spend as the fastest growing line in IT, and our card data is consistent with that view. Gartner IT and AI spend commentary shows the same direction at the market level that we see inside individual estates.

The prep

The prep work is the category sweep done now, not at budget time. A finance team that runs the sweep in the second quarter of 2026 has a real number to plan against. A team that runs it in November is reacting, not planning.

  • Plan a band. 6 to 10 percent of software spend on AI by mid 2027.
  • Assume attach. Not a fixed seat count, especially on Copilot and Gemini.
  • Run the sweep early. The card data is the real planning input.

What should a buyer do next?

  1. Run a category sweep of the corporate card data for AI vendor name patterns and merchant categories before the next quarter close.
  2. Cross check the card list against expense reports and SSO logs to capture seats that were purchased outside the card program.
  3. Aggregate the sweep into four to six categories. Size each category as a band, not a point, and compare it to the formal AI line in the IT budget.
  4. Identify the two or three categories where consolidation into an enterprise contract closes the largest share of the bill and the largest share of the data risk.
  5. Negotiate the consolidation contracts with data controls, audit rights, and a separate term and cap for any AI add on.
  6. Issue a one page acceptable use policy that covers the long tail, names the approved categories, and sets a path to request a new tool.
  7. Add a dedicated AI line to the software plan, sized from the card data rather than the request queue, and review it at every quarterly card cycle.
  8. Engage independent benchmarking and renewal advisory before signing the consolidation contracts, not after the first quote arrives.

What do real shadow AI category sweeps look like in practice?

Three anonymized patterns from the engagement file show how the sweep plays out in different estates. The figures are bands. Details are generalized to protect confidentiality.

A financial services firm with no formal AI line

A large financial services buyer ran the card sweep against a 2025 quarter and found AI vendor spend roughly four times the formal AI line in the IT budget. The largest single category was AI coding tools across the engineering function.

The remediation was an enterprise contract with the dominant AI coding vendor, data clauses signed by the security team, and a parallel review of two personal account general assistant tools that handled customer data. The formal AI line in the next budget cycle absorbed the consolidation.

A technology firm with a large but legitimate AI bill

A technology firm found that its off books AI bill, while large in absolute terms, sat within the boundaries the security team was already comfortable with for the tools in use. The exception was a long tail of newer vendors no one had reviewed.

The fix was a one page acceptable use policy that distinguished the approved tools from the long tail, plus an SSO requirement on the approved set. The category total barely moved. The risk dropped sharply.

A public sector estate that needed to close personal accounts entirely

A public sector estate found a small but unacceptable use of personal account AI tools for handling case data. The card spend was minor. The compliance exposure was material.

The response was to consolidate to one enterprise contract with the strictest data clauses in the market, run a brief training session on the new tool, and block personal account access at the network layer. The total spend rose. The exposure closed.

Common mistakes finance and procurement make on shadow AI

The same mistakes appear in most sweeps we run. None of them are obvious in advance. All of them are easy to fix once they are named.

Treating the request queue as the demand signal

The most common mistake is sizing the AI budget from the formal request queue. The queue captures what was asked through the right channel. The card data captures what is actually being used, which is a larger and more honest number.

A budget built from the queue will understate. A budget built from the card data will be defensible at the next finance review.

Buying one tool to rule them all

The second common mistake is signing a single AI contract on the theory that one vendor will cover every use case. In practice, different teams need different tools, and the single contract approach leaves the unserved teams to buy on the side.

Three or four category contracts almost always close more of the bill than one tool ever can. The category contract approach matches how the business actually uses AI.

Reaching for the ban first

The third common mistake is the ban that the contrarian section above warned against. A ban that lacks an alternative pushes use to personal accounts and removes the only audit trail finance had.

The pattern that works is consolidate first and ban only what cannot be consolidated. The reverse order produces more spend, more risk, and a worse 2027 budget input.

  • Mistake. Sizing the AI budget from the formal request queue rather than the card data.
  • Mistake. Signing a single AI contract on the theory it will cover every use case.
  • Mistake. Reaching for a ban before a consolidation plan is in place.

What signals predict that shadow AI is already large in your estate?

A handful of operational signals reliably flag estates where shadow AI is already a material line. They show up in the data finance and IT already collect, not in a separate audit.

Corporate card spikes in software categories

The first signal is a quarterly rise in the software merchant category on the corporate card program, with no matching rise in EA spend. The card category usually breaks out the increase before procurement notices it.

A second pass on the card data, filtered to AI vendor names, almost always confirms the picture. The first list reveals the category. The second list names the tools.

Expense report patterns

Repeat individual expense reports for the same vendor name, often under twenty dollars per month, are the second signal. They appear most in functions that ship to deadlines, like engineering, marketing, and sales.

The pattern is rarely one big claim. It is many small claims that an expense system was never tuned to flag. Aggregated across a quarter, they read as a recurring cost.

SSO and identity provider logs

SSO logs show the same picture from a different angle. AI vendor domains that appear in sign in events but never in the EA inventory are off books seats by definition.

This is the cleanest source for engineering tools, because developers log in to AI coding tools daily. The SSO log catches what the card data missed when the seat was bought on a personal email.

  • Cards. Quarter on quarter software category rises without matching EA growth.
  • Expense reports. Repeat sub twenty dollar claims for the same vendor across many people.
  • SSO logs. Vendor sign ins that never appear in the EA inventory.

What does a credible enterprise contract for an AI tool actually need?

The good news is that the contract template is short. The clauses that matter on an AI tool are the ones that close the data and cost questions the personal account never answered.

Data handling and training carveouts

The first clause excludes prompts and outputs from model training by default. Enterprise tiers from the major vendors include this. The personal tier usually does not, which is why the migration matters.

The second clause names the data classes the enterprise may submit, the storage region, and the retention period. Where regulation applies, this clause closes the audit question in advance instead of leaving it open until a breach.

Audit rights and SOC reporting

A right to inspect the vendor's SOC reports and a documented audit path are now table stakes on any AI contract a regulated enterprise signs. Without them, the security review has to be repeated from scratch every year.

For non regulated estates, the same clauses still pay off at renewal, because they shift the burden of proof from the buyer to the vendor when something does need to be reviewed.

Term, cap, and exit on the AI add on

The last set of clauses is the cost discipline. A separate term and a flat percentage cap on the AI add on, with an exit right that does not penalize the buyer for stepping back, keeps the premium bounded.

Bundling the AI add on into the base license removes this discipline. Even when the base renewal is friendly, an uncapped AI line will compound past the base inside two cycles.

  • Data handling. No training on prompts by default; named regions and retention.
  • Audit rights. SOC reports and a documented audit path.
  • AI add on term. Separate term, flat cap, and clean exit, not bundled into the base.

Who should own the shadow AI conversation inside the enterprise?

Ownership decides whether the category gets sized accurately or argued about. Finance, procurement, and security each see a different slice of the bill, and none of them sees all of it alone.

Finance owns the meter

Finance is the only function that holds the card data, the expense reports, and the AP feed. That makes finance the owner of the sizing exercise. The deliverable is the dollar number behind the category, not a policy.

This is also where the planning input lives. The 2027 AI line in the software budget belongs in finance, sized from the data finance already controls.

Procurement owns the contracts

Procurement turns the finance number into a contract round. The category map becomes a list of two or three enterprise contracts to negotiate, with the data and cost clauses described above.

This is also where the consolidation conversation lives. A procurement team that runs the round annually keeps the off books bill bounded for the next twelve months.

Security owns the rules

Security writes the one page acceptable use policy and signs off on the contract data clauses. Security does not need to own the cost number. It does need a veto on tools that fail the data review.

The three way ownership works when each function leads its own slice and meets monthly to reconcile. It fails when one function tries to own all three, which is the usual reason a ban is reached for in the first place.

  • Finance. Owns the sizing, the card data, and the budget line.
  • Procurement. Owns the consolidation contracts and the renewal round.
  • Security. Owns the data review, the acceptable use policy, and the veto on failing tools.

What this report deliberately does not measure

A benchmark is only useful if its limits are stated. This report is a directional read on the size and shape of the off books AI category. Several things sit outside it on purpose.

One time cost and pilots

The category sweep counts recurring card subscriptions. It does not size one time AI consulting, vendor proof of concepts, or short pilots paid as a single expense claim. Those are real costs but they are not the recurring exposure.

Revenue from AI products

The report measures cost on the buyer side, not revenue on the vendor side. A vendor revenue figure can grow even where a given enterprise holds spend flat, and the reverse is also true.

Currency and regional mix

Pricing varies by region, currency, and product mix. A global estate will see effects this report does not localize. Read the bands as direction and adjust for your own region before planning.

  • Excluded. One time consulting, vendor proof of concepts, and short pilots paid as a single expense.
  • Not measured. Vendor revenue from AI products.
  • Not localized. Currency, region, and product mix.

Frequently asked questions

What is shadow AI in an enterprise?

Shadow AI is any AI tool an employee uses for work that procurement and IT did not approve, did not contract, and cannot see in the EA. It usually arrives on a personal account, a free plan, or a corporate card subscription a manager bought directly. The point is not the tool. It is the absence of oversight.

How big is shadow AI spend in a large enterprise?

In our 2024 to 2025 advisory file, shadow AI ran 4 to 9 percent of total software spend in a large enterprise. That is often two to three times the formal AI line. On a billion dollar IT budget, the gap reaches tens of millions of dollars sitting outside contract.

Which AI tools dominate shadow AI today?

Four families show up in almost every shadow AI audit. ChatGPT and Claude on personal or team plans, Cursor and similar AI coding tools on individual developer cards, Perplexity and similar AI search tools, and individual Microsoft Copilot or Google Gemini subscriptions bought outside the EA. Together they cover most of the off books AI bill.

Who buys shadow AI inside the enterprise?

The buyers are almost always line managers and senior individual contributors with a corporate card and a real productivity problem. They are not trying to evade procurement. They are trying to ship work this quarter. The buyer pattern is consistent across functions, with engineering, marketing, and sales the heaviest users.

How does shadow AI grow on corporate cards?

Shadow AI grows quarter by quarter, because most AI tools price per seat per month at a level that sits below the threshold a card needs procurement to approve. Each seat is small. The aggregate is large. By the time finance pulls the category, the bill is already a recurring cost.

Should we ban shadow AI to bring it under control?

We disagree with a default ban. In the estates we audited, blanket bans pushed the highest value tools into personal accounts and out of any governance. Productivity demand kept growing. The better move is to consolidate the few tools that matter into enterprise contracts with data controls.

What are the data risks of shadow AI beyond cost?

The data risk is larger than the cost risk and harder to undo. Personal account prompts can leak into model training, customer data can cross a boundary the contract never blessed, and sensitive code or financials sit on a vendor account no security team has reviewed. The breach you do not see is the breach you cannot answer for.

How do finance and procurement find shadow AI spend?

The fastest path is a category sweep of the corporate card data. A short list of vendor name patterns and merchant categories surfaces 80 percent of the bill in a single afternoon. The second pass cross checks expense reports and an SSO log for the same vendors. Together they map the off books estate.

How do we bring shadow AI back into the budget?

The pattern that works is consolidate, contract, and govern. Consolidate the high value tools into one or two enterprise contracts with data controls. Contract the rest by category, not by tool. Govern usage with a short acceptable use policy and a budgeted central AI line that gives finance a place to plan the spend.

How should we budget for AI in 2027 given what shadow AI shows?

Treat AI as its own line in the software plan, separate from the base EA, and size it from the corporate card data, not from the request queue. The card data shows what the business is already paying for. That is a more honest planning input than the formal AI roadmap, because it reflects revealed demand.

Shadow AI Spend Report 2026

Get the full category map and the corporate card sweep checklist.

The vendor name patterns to search for, the four category consolidation framework, the data control checklist for AI contracts, and the one page acceptable use policy template.

Used across more than five hundred enterprise engagements. Independent. Buyer side. Built for finance and procurement leaders sizing the 2027 AI budget.

No spam. We will only email you about this request. Privacy.
Run the software spend health check against your AI exposure in under five minutes.
Open the Tool →
Off Books
Bigger Than EA
Cards
The Real Meter
500+
Enterprise Clients
$2B+
Under Advisory
100%
Buyer Side

The EA tells you what procurement bought. The corporate card tells you what the business is actually using. In 2026, the gap between those two is the AI category.

Morten Andersen
Co Founder, Redress Compliance