← All posts

June 6, 2026 · 7 min read · Waste and recovery

Finding shadow AI spend on the company card

Shadow AI means AI tools bought on personal cards, outside of purchasing. It is a spend and renewal problem before it is a security problem. The data-leak framing is real, but it has crowded out the framing that actually gets a budget line approved.

By Spendassay Research

The fastest way to find shadow AI spend is not a network scan or a new cloud security tool. It is four queries you can run this week: the text on your corporate card transactions, expense-report line items, your sign-in logs, and the vendor list your bill-paying system already keeps. Those four will show most of it in an afternoon.

The largest line you find probably will not be a tool nobody approved. It will be an approved one, bought at full price by eleven separate people, each of whom put $20 a month on a card rather than wait three weeks for sign-off.

That difference matters, because it changes who funds the fix. A security finding goes to a review board and waits in line behind other risk items. A spend finding arrives with a dollar figure and a renewal date attached, and gets approved this quarter. Both are worth doing. Only one pays for itself right away.

Why it piles up

Three mechanics, none of which involve anyone behaving badly.

Waiting costs more than buying. An AI tool costs $20. Getting it bought costs weeks of calendar time and somebody's goodwill. For one engineer with a deadline, the card is the smart choice, because waiting costs more than it saves. If your expense policy works and your vendor sign-off is slow, you are quietly paying people to buy their own tools.

Free plans that turn paid, quietly. Someone signs up on a free plan. Nobody has to sign off, because there is nothing to sign off on. Six weeks later they hit a rate limit and upgrade with a card. The tool arrived free and became paid without ever crossing a desk. There is no moment in that sequence where a control would have fired.

Retail prices, multiplied. Tools sold by the seat — one paid license per person — bill at full list price when people buy them one at a time. Cursor Pro is $20. GitHub Copilot Pro is $10. Claude Pro is $20. Buy those one at a time on twelve different cards and you have paid the worst price the vendor offers, twelve times over, with no combined usage data and no bargaining position. Vendr's marketplace data on Cursor shows 15–25% off list through an annual commitment, and 25–40% when you combine several terms. None of that is open to a person expensing a monthly bill.

Zylo's 2026 SaaS Management Index puts a number on how normal this has become. ChatGPT is now the most-expensed application. Not the most-bought — the most-*expensed*, meaning it reaches finance as an expense claim rather than as a purchase. The same report finds AI-native app spend up 108% year over year, and 78% of IT leaders hit with unexpected AI or consumption charges.

Where to look, in order of effort

Most teams are starting from close to zero here. Flexera's 2026 research has 59% reporting increased wasted spend on AI software year over year, and only 31% claiming accurate visibility into it. That is vendor research that does not fully publish its method, but it points the same way as everything else on the subject.

Card and expense transactions. Start here, because the data is already yours. Pull twelve months of card transactions and filter on known AI vendor names. You are looking for small repeating amounts — $10, $20, $39, $60 — charged each month against several card holders.

The vendor-name problem. This is where most first attempts fail. The same vendor bills under several strings: a raw merchant name, a name carrying the card processor's prefix, and a legal entity name on the invoice. Now add resellers and marketplaces. AWS Marketplace, Google Cloud Marketplace, or a payment company that bills on the vendor's behalf, like Paddle or FastSpring. One vendor can show up four ways in the same export, and none of the four match each other. Until you collapse them into one standard name, with a table of the aliases, your spend-by-vendor report is fiction and your estimate of what merging saves is wrong in a direction you cannot guess. Do that job once, when the data first comes in, and reuse it everywhere.

Sign-in logs. Okta, Google Workspace and Entra all record which apps people signed into with their work account. This catches two things card data misses completely: tools still on a free plan, with real use and no transactions, and tools someone paid for personally and never expensed. It also gives you a headcount per tool, which is what you need to size a shared plan. What it does not give you is depth of use. A sign-in record tells you someone logged in once, not that they use it daily.

Expense-report line items. Free-text notes on expense claims. Search tool names, "AI", "subscription", "API". This is the only place personal-card purchases show up, and it is the slowest source, because the text has no structure. Do it last, but do it.

The most expensive shadow AI is rarely the tool nobody approved. It's the tool everybody approved, bought twelve separate times at list price.

What to do with each finding

Every hit lands in one of three buckets. Decide the bucket before you decide the fix.

Consolidate. You already hold a contract with this vendor, and these are the same seats bought one at a time. Cancel the personal plans, add those people to the contract you signed, and book the price difference. This is the bankable bucket. The saving is the gap between list price and your contracted rate, and you get it at the next billing cycle rather than the next renewal. It is often the largest bucket in dollars, too.

Sanction and centralize. Real use, real need, no contract. Move billing onto a single contract, put the app behind single sign-on, give it an owner and a line in your books, and set a review date. The combined usage data you now hold is what you take into the talks. Seat counts you can show, and use you can prove, are what move a vendor off list price, and building the renewal case from evidence is a very different conversation from simply asking for a discount.

Shut it off. One or two users, shallow use, and something you already pay for does the same job. Cancel it. But check that overlap against how much the other tool is really used, not against its license list. A tool can look pointless next to a product whose seats nobody touches. An idle seat is a paid seat nobody has used lately, and idle seats often cost more than the shadow tool you were about to cancel.

The third bucket gets the most attention in meetings and returns the least money. Budget your time to match.

Count it once

Shadow spend is unusually easy to double-count, because the same person often shows up twice: on the seat list for an approved tool, and on a card charge for the same vendor. Add both and you report a saving twice. Your total goes up without anyone lying.

Three rules fix it. Remove duplicates by person and by standard vendor name before you total anything. When you move retail seats onto a shared plan, book the *price difference*, not the full seat cost, because those seats still exist and simply cost less. And never report the same dollar as both "shadow spend removed" and "seat spend reduced." We count each dollar once: a dollar you get back sits in one bucket, no matter how many reports could lay claim to it.

The security part, kept short

The risk is real. Company data goes into a third-party tool. Often there is no contract covering how that data is handled, no limit on how long it is kept, and no way to know whether prompts are used for training. Tools nobody approved multiply that risk. This work should happen.

It should just happen in parallel, on its own clock, with its own owner. Not as a gate on the consolidation that pays for itself in one billing cycle. Putting the spend work behind a security review is how shadow AI stays unfixed for another two quarters.

For what it is worth on our side: Spendassay's sign-in links read metadata only — counts, dates and names, never the contents. That means who signed in to which app, and when. Never email content, never file content, never message bodies. Everything is read-only. The security posture is written up in full, including what those links cannot see.

The honest caveats

This method has known blind spots. Card text misses annual plans bought before the months you pulled, personal-card purchases nobody ever expensed, and AI tools bundled inside a bigger platform invoice. Sign-in logs prove a login, not depth of use or cost. Zylo's and Flexera's numbers come from vendor research that does not fully publish its method, so treat them as direction, not as your baseline. "Most-expensed app" describes the set of firms that expense software, which may not look like yours. And every saving from merging is an estimate until the new rate is signed. Report it as a range with the assumed discount stated, not as money already in the bank.

Find your recoverable AI spend

Connect a card feed and your sign-in system and you will see each AI vendor in the firm, under one name each, with repeat purchases flagged against the plans you already hold. The snapshot is free, read-only, and does not need a card.

`Start free` → /login?src=blog_shadow-ai-spend-on-the-company-card

Find your recoverable AI spend

Spendassay turns this from an afternoon of spreadsheets into a live, proof-level audit with the recovery attached.

Practical, evidence-first notes on AI spend. A couple a month. No spam, unsubscribe anytime.