Most shadow AI conversations stop at security: an employee uses an unapproved model, sensitive information enters the wrong system, or IT cannot see which tools touch company data.
Those risks are real. I think the way we frame them can hide another, quieter problem.
The charge renews.
A $20 or $40 individual plan becomes a team workspace. A company card replaces a personal card. More seats are added. What started as an experiment becomes a normal software commitment without ever getting a clear owner, review date, or replacement test.
Short answer
Treat shadow AI as a software-lifecycle problem as well as a security problem. Start with the charge. Identify the workflow, assign an owner, record the renewal and notice dates, and make one keep, cut, review, or consolidate call.
The goal is not to punish experimentation. It is to stop experiments from renewing indefinitely by default.
Expense reports are becoming part of software procurement
Zylo's 2026 SaaS Management Index reports that expense-based SaaS spend increased 267% year over year in its dataset and that ChatGPT became the most-expensed application. It also reports AI-native application spend up 108% overall.[1]
Spendesk found that 70% of AI purchases in its 2025 European dataset were subscriptions, compared with 43% in early 2023. Its study covered more than 2,500 companies using Spendesk across France, the UK, Germany, and Spain.[2]
The numbers come from different customer populations, so they should not be blended into one benchmark. The operating point is still clear: many AI purchases are recurring costs, and recurring costs need an owner and a renewal decision.
Why the tool list misses them
Shadow AI can enter through several paths:
- an employee expense or reimbursement;
- a corporate card owned by a department;
- a free workspace that later converts to paid;
- an API account billed separately from the team's normal software;
- an AI add-on inside a product already under contract;
- a usage-credit purchase that does not look like a normal seat license.
No single system necessarily sees all six.
Finance sees the charge. IT sees approved applications. Security sees access and data risk. The team sees the workflow. Procurement sees the contract only if the purchase reached procurement.
That is why I would start with one simple record that connects the tool, the bill, the owner, the workflow, and the renewal.
The four-step cleanup loop
1. Discover the recurring charge
Review card and expense exports, accounts-payable vendors, reimbursement records, and known team workspaces. Search by both product and merchant name. Keep API and usage-credit accounts separate from seat subscriptions until you confirm they are the same billing relationship.
2. Assign the operational owner
The purchaser is not always the owner. Ask who can answer: what job the tool performs; who depends on it; what data it handles; whether another paid tool can replace it; what would break if it disappeared.
If nobody can answer, owner missing is the finding. It is not proof the tool should be cut.
3. Record the decision window
Capture the renewal date and any cancellation notice deadline. Monthly tools can usually be revisited quickly. Annual plans may require a decision weeks or months before the renewal charge.
The due date belongs to the notice deadline, not the day after the invoice arrives.
4. Make one explicit call
Keep when the tool has a clear job, owner, evidence, and acceptable cost.
Cut when there is no defensible use and cancellation is safe.
Review when usage, cost, ownership, contract, or security evidence is missing.
Consolidate when another paid product can cover the workflow but a migration or replacement choice still has to be made.
Do not count the monthly charge as captured savings until the outcome is completed and confirmed.
Security and spend should share the same record
Flexera's 2026 State of ITAM survey found that only 31% of respondents reported accurate visibility into AI software. It also found 84% identified tracking or adopting AI applications as a top challenge and 59% reported increased wasted AI spend.[3]
A security inventory and a spend inventory answer different questions, but they should point to the same tool record.
Security needs to know what data enters the system and whether use is approved. Finance needs to know the cost and renewal exposure. The operating team needs to know whether the workflow is valuable. The decision is safer when those facts can be reviewed together.
Do not solve shadow AI by freezing experimentation
A blanket ban can push useful work back onto personal accounts and make visibility worse. I would rather use a lightweight intake and cleanup loop:
- small experiments can start quickly;
- every paid tool gets an owner;
- material usage or cost triggers a deeper review;
- renewals require evidence;
- overlapping tools get a consolidation decision;
- completed outcomes are recorded.
This keeps experimentation possible without letting every experiment become a permanent line item.
Where AlignCube fits
I built AlignCube so the first decision list does not require vendor logins. Paste the known tools, costs, owners, and notes. The browser-only preview can show the shape of the stack locally; the free AI-scored audit adds keep, cut, review, and consolidate reasoning.
The result is not an automatic cancellation order. It is a record of what deserves review, who owns the next move, and what evidence is still missing.
Start with the subscriptions you can see. The missing owners and unknown costs are part of the answer.
Sources and methodology
Sources checked through 2026-07-19. Figures are attributed to each vendor's own dataset or survey and should not be blended into a single benchmark.
- Zylo, 2026 SaaS Management Index announcement (January 29, 2026). Dataset described as more than 40 million SaaS licenses and $75 billion in spend under management. https://zylo.com/news/2026-saas-management-index
- Spendesk, State of AI Spend announcement (February 19, 2026). Study describes more than 2,500 European companies using Spendesk and EUR 33.8 million in 2025 AI-tool purchases. https://www.spendesk.com/press/ai-state-of-spend-report/
- Flexera, 2026 State of ITAM report announcement (June 24, 2026) and AI cost-optimization overview (June 2026). https://www.flexera.com/about-us/press-center/flexera-2026-state-of-itam-report-reveals-only-31-percent-organizations-have-visibility-into-ai-as-spend-surges
Researched with AI assistance; every figure is sourced, and Collin Jones reviews and stands behind each note before it publishes.
See a source or correction we should review? Email [email protected].