Stackpack Blog

Shadow AI: How to Find Unauthorized AI Tools and Hidden Spend

Shadow AI isn't just a security problem. Unapproved AI tools, duplicate subscriptions and ghost licenses quietly inflate spend. Here's how to find them and bring AI adoption under control.


TL;DR: Shadow AI is AI software employees use without company approval or oversight. It creates both security risk and financial waste: unapproved tools can expose sensitive data, while duplicate subscriptions and unused licenses quietly increase software spend. The answer isn't to ban AI. It's to discover every AI tool in use, connect usage to spend, eliminate unnecessary subscriptions, and make the approved path faster than going around it.

What is shadow AI?

Shadow AI is the use of AI tools, applications, or services by employees without company approval or oversight.

It is essentially the AI-specific version of shadow IT – but AI makes the problem move much faster.

A traditional SaaS tool might go through procurement, security review, a contract, and an IT rollout before reaching employees. An AI tool can be adopted in minutes with a browser, an email address, or a personal credit card.

And employees aren't necessarily trying to circumvent their company. Often, they're simply trying to get their work done.

PagerDuty's 2026 Shadow AI Survey, conducted by Wakefield Research among 1,250 office professionals at companies with at least $500 million in annual revenue, found that 66% had used AI tools at work despite believing they were not permitted under company policy. Among workers who use AI for work, 89% said they first encountered the technology in their personal lives.

That creates a problem for more than just security teams.

If Finance doesn't know an AI tool exists, it can't manage the contract, subscription, renewal, or spend.

Why does shadow AI happen?

Shadow AI happens when employee demand moves faster than enterprise procurement and governance.

Employees discover a tool that makes them dramatically more productive. The company hasn't approved it yet – or doesn't have an easy process for approving it – so the employee uses it anyway.

PagerDuty found that 89% of employees who use AI at work first encountered the technology outside of work.

EY's 2025 Work Reimagined Survey found that 23% to 58% of employees bring personal AI tools to work, depending on sector, with some paying for their own subscriptions. EY surveyed 15,000 employees and 1,500 employers across 29 countries.

This creates a familiar cycle:

Employee discovers tool → starts using it → pays personally or submits an expense → team adopts it → company discovers it later

By the time Finance or IT finds out, there may already be multiple employees using the same tool – or multiple tools doing essentially the same thing.

What are the risks of shadow AI?

Shadow AI creates three overlapping problems: security, governance, and costs.

1. Security risk

Employees may put confidential information, customer data, financial information, or intellectual property into AI tools that haven't been reviewed by the company.

PagerDuty found that 34% of surveyed workers had entered customer data or information into public AI tools, while 31% had entered financial information or confidential company documents or strategies.

IBM's 2025 Cost of a Data Breach research found that one in five organizations studied experienced a breach linked to shadow AI. Organizations with high levels of shadow AI saw average breach costs approximately $670,000 higher than organizations with low or no shadow AI.

2. Governance risk

AI adoption is moving faster than governance.

ISACA's 2026 AI Pulse Poll found that 90% of respondents believe IT audit, security, governance and privacy employees are using AI in their organizations, but only 38% of organizations have a formal, comprehensive AI policy.

Gartner's 2025 research found that 69% of organizations surveyed either suspected or had evidence that employees were using prohibited public GenAI. Gartner also predicts that more than 40% of enterprises will experience security or compliance incidents linked to unauthorized shadow AI by 2030.

3. Financial risk

This is the part of shadow AI that often gets overlooked.

Every unapproved AI tool can also be an unmanaged expense.

A company may have:

  • Employees paying for AI subscriptions personally
  • Teams expensing duplicate AI tools
  • Multiple departments buying similar products
  • Unused enterprise seats
  • AI subscriptions nobody knows about
  • Contracts renewing without a usage review
  • Usage-based AI costs with no owner or budget
  • Enterprise tools sitting alongside cheaper alternatives

So shadow AI isn't just an IT problem.

It's also a cost management problem.

What are ghost licenses?

A ghost license is a paid software license or seat that is no longer being actively used.

For example:

  • An employee leaves, but their AI seat remains active.
  • A team buys 50 licenses and only 28 people use them.
  • Marketing buys one AI writing tool while the company already pays for another.
  • An employee starts using a different AI product and stops using the tool their company provides.

Ghost licenses are the opposite side of the shadow AI problem:

Shadow AI = usage without a contract you control.

Ghost licenses = contracts without meaningful usage.

AI makes both problems worse because AI pricing is changing rapidly. Companies may be paying by seat, usage, credits, tokens, or a combination of the three.

That makes traditional software-license management increasingly inadequate for AI spend.

Shadow AI vs. Shadow IT vs. Ghost licenses

ComparisonShadow AIGhost licensesShadow IT
What it isAI tools used without approvalPaid software seats nobody usesAny unapproved software
Primary riskData exposure + unmanaged spendWasted spendSecurity + spend
Where it hidesPersonal accounts, cards, expenses, browsersLicense systems, invoices, renewalsExpenses, cards, departmental budgets
Typical ownerSecurity / IT / FinanceFinance / IT / ProcurementIT / Security
How to fix itDiscover, evaluate, approve or replaceReclaim, right-size, consolidateDiscover, govern, consolidate

How do you find unauthorized AI tools?

The most effective way to discover shadow AI is to combine financial, identity, usage, and employee data.

No single system will show you everything.

1. Follow the money

Start with:

  • Corporate card transactions
  • Expense reports
  • AP transactions
  • Vendor records
  • Employee reimbursements

Look for known AI vendors as well as small recurring software charges.

Personal purchases are particularly difficult to see, so don't assume your AP system contains the entire picture.

2. Check identity data

Review:

  • SSO applications
  • OAuth grants
  • Google Workspace integrations
  • Microsoft integrations
  • Corporate email domains
  • Browser or endpoint signals, where appropriate

An employee may not have a contract for an AI tool, but they may still have connected it to a corporate account.

3. Compare licenses with actual usage

For every centrally purchased AI tool, compare:

Paid seats vs. active users

If you're paying for 500 seats and only 310 people are using the product, you have 190 seats to investigate.

Don't automatically cancel them – understand whether they're reserved for upcoming hires, seasonal use, or legitimate low-frequency users.

4. Look for overlapping tools

Group AI products by function:

  • Writing
  • Coding
  • Meeting transcription
  • Research
  • Design
  • Sales
  • Customer support
  • Data analysis
  • Marketing
  • Productivity

You may discover that five departments are buying five AI tools that solve essentially the same problem.

5. Ask employees

Surveys are still useful because some shadow AI will never appear in corporate systems.

Ask: “What AI tools do you use for work, including tools you pay for yourself?”

Make disclosure easy and non-punitive.

The goal is discovery – not catching people breaking the rules.

6. Decide what to do with each tool

Every discovered tool should end up in one of a few buckets:

Approve → Consolidate → Replace → Retire → Investigate

The goal isn't to eliminate employee experimentation.

It's to bring useful experimentation into a system the company can manage.

How do you reduce shadow AI?

The best way to reduce shadow AI isn't to ban AI. It's to make the approved path easier than the workaround.

If an employee can sign up for a useful AI tool in 30 seconds but getting an approved tool takes six weeks, the company has created an incentive for shadow AI.

A better process is:

  1. Discover what employees are already using.
  2. Evaluate security, cost, overlap, and business value.
  3. Approve useful tools quickly.
  4. Consolidate redundant subscriptions.
  5. Monitor usage and spend.
  6. Review renewals before they happen.
  7. Measure whether AI spend is actually producing value.

This turns AI governance from a blocker into an operating system for adoption.

How should Finance manage AI spend?

This is where shadow AI becomes an Office of the CFO problem, not just an IT problem.

Finance needs to know:

  • What AI tools are we paying for?
  • Which employees or teams use them?
  • How much are we spending?
  • Which tools overlap?
  • Which subscriptions aren't being used?
  • When do contracts renew?
  • Where is AI spend increasing fastest?
  • Which costs are fixed vs. usage-based?
  • Who owns each AI budget?
  • Is the spend producing measurable value?

Traditional SaaS management answers some of these questions.

AI requires going further because the cost can change with usage.

A company might have a $20,000 annual contract with an AI vendor and also incur another $30,000 in usage-based charges. Or it may have hundreds of employees purchasing AI tools independently.

That means AI spend management increasingly needs to connect contracts, payments, usage, budgets, and outcomes.

How Stackpack helps manage shadow AI spend

Most shadow AI solutions focus primarily on security and visibility: identifying which AI tools employees are using.

That's important – but it's only the first step.

Stackpack connects AI discovery to software cost management, so Finance can move from:

“What AI tools are people using?”

to:

“What are we paying for, what are we actually using, and what should we do about it?”

With Stackpack, teams can:

  • Discover: Identify AI vendors and subscriptions across spend and usage data.
  • Evaluate: Surface duplicate tools, unused licenses, and opportunities to consolidate.
  • Approve: Give employees a faster path to request and approve new software.
  • Manage: Track contracts, budgets, renewals, and vendor spend in one place.
  • Optimize: Right-size licenses and negotiate before renewal.
  • Measure: Connect AI spending to utilization and ROI.

The goal isn't to stop employees from using AI.

It's to make AI adoption visible, governed, and economically accountable.

See what your company is actually spending on AI → Book a demo

Frequently Asked Questions

What is shadow AI?

Shadow AI is the use of AI tools, applications, or services by employees without company approval or oversight. It can create security, compliance, and financial risks because organizations may not know what tools employees are using or what they're paying for.

What is an example of shadow AI?

An employee using a personal ChatGPT, Claude, or other AI account to analyze confidential company information without their company's approval is an example of shadow AI. Another example is an employee purchasing an AI software subscription on a personal or corporate card without going through the company's software procurement process.

What is the difference between shadow AI and shadow IT?

Shadow IT refers to any unauthorized technology or software. Shadow AI is the subset involving AI tools. Shadow AI can introduce additional risks because employees may submit sensitive information to external AI models and because AI pricing and usage can be difficult to track.

What is a ghost license?

A ghost license is a paid software license or seat that is no longer being actively used. Common examples include licenses belonging to former employees, unused seats purchased ahead of adoption, and duplicate software subscriptions.

How do you find unauthorized AI tools?

Combine corporate card and expense data, AP transactions, SSO and OAuth data, software-license usage, and employee surveys. No single source captures every unauthorized AI tool.

How do you manage shadow AI?

The most effective approach is to discover unauthorized tools, evaluate their security and business value, consolidate redundant software, right-size licenses, and create a fast approval process for new AI tools. Banning AI entirely can drive usage further underground.

Is shadow AI always bad?

No. Shadow AI often indicates that employees have found useful ways to apply AI to their work. The problem is that the organization may not have visibility into the tools, data being shared, costs, or business value.

How much does shadow AI cost?

The cost varies significantly by company. Direct costs can include duplicate subscriptions, unused licenses, employee reimbursements, and unmanaged usage-based charges. There can also be security and compliance costs. IBM's 2025 research found that organizations with high levels of shadow AI experienced average breach costs approximately $670,000 higher than organizations with low or no shadow AI.

Sources

  1. PagerDuty, 2026 Shadow AI Survey (June 2026)
  2. EY, 2025 Work Reimagined Survey (November 2025)
  3. IBM, Cost of a Data Breach Report 2025 (July 2025)
  4. ISACA, 2026 AI Pulse Poll (May 2026)
  5. Gartner, Gartner Identifies Critical GenAI Blind Spots That CIOs Must Urgently Address (November 2025)