← All guides

Guide

How to find and govern shadow AI

Shadow AI is any AI tool your teams pay for or sign into without IT approval. Spendassay finds it by reading SSO and OAuth grants plus corporate-card spend, then prices each finding by proof level. Your own admins govern it using the step-by-step instructions Spendassay generates. The audit is read-only and metadata-only.

What is shadow AI, and why does it cost you money?

Shadow AI is any AI tool employees buy or sign into outside your approved stack. It shows up as ChatGPT, Cursor, or Claude subscriptions on personal cards and OAuth grants no admin approved. The cost is duplicate seats, unmanaged data access, and spend no one has priced against its use.

Most shadow AI is not malicious. An engineer expenses a Cursor seat, a team buys ChatGPT Team, and finance never maps the charge to a tool. The spend is real; the visibility is not.

The problem is measurement. Card statements show a vendor and a dollar amount. They do not show who uses the tool, whether the seat is active, or whether a sanctioned tool already covers the same job. That gap is what an audit closes.

How does Spendassay detect shadow AI?

Spendassay cross-references two signals: identity grants from SSO and OAuth (Okta, Google Workspace, GitHub), and corporate-card spend (Ramp, CSV import). When a tool appears in one and not your approved list, it becomes a priced finding. The audit reads metadata only, never source code, prompts, or message content.

OAuth and SSO grants reveal which AI apps employees have connected to corporate identity. Card and expense data reveal what is being paid for. A tool present in either, but absent from your sanctioned inventory, is flagged as shadow AI.

Every finding carries a proof level so you know how solid it is: Counted (from direct usage or spend data), Compared (against similar teams), or Estimated (from assumptions). Each finding also exposes the formula behind its dollar figure.

How do you govern shadow AI once you find it?

Governance is a decision per finding: consolidate onto an approved tool, reclaim idle seats, or formally sanction the tool. Spendassay produces a set of step-by-step instructions for each path with the exact steps and affected users. Your admins execute the step-by-step instructions in the vendor console; Spendassay tracks the recovery.

The audit does not write to, route, or throttle any vendor system. It finds the waste, sets the recoverable target, and gives your admins step-by-step instructions to act in their own tools. Routing and throttling are Control, a separate opt-in plan (private beta) that runs on your own provider keys.

For renewals, Spendassay builds a negotiation package. When a shadow tool is genuinely useful, the right move is often to sanction and consolidate it, not kill it. The audit gives you the dollar case either way.

What does an approved AI inventory look like afterward?

After the first pass you have a single list of every AI tool in use, who is on it, what it costs, and whether it is sanctioned. New shadow AI surfaces automatically as fresh grants and charges appear, so the inventory stays current instead of going stale after one cleanup.

The audit treats findings at the team level, never as individual league tables. You govern by team and tool, not by naming employees.

Because detection runs on live SSO and card data, the next unsanctioned Cursor seat or ChatGPT charge shows up as a new finding. Governance becomes a standing process, not a one-time project.

Step by step

  1. 1

    Connect a spend source

    Connect Ramp or upload a corporate-card CSV. This gives the audit the vendor charges that reveal paid AI tools no one has mapped. You can start with CSV import alone, with zero live integrations.

  2. 2

    Connect an identity and usage source

    Connect Okta, Google Workspace, or GitHub for SSO and OAuth grants, and connect OpenAI or Anthropic for token usage. These signals show which AI apps employees have linked to corporate identity and how much they are used.

  3. 3

    Review the shadow AI findings

    Open the findings list. Each shadow AI finding names the tool, the affected team, the dollar amount, and its proof level (counted, compared, or estimated). Expand any finding to see the formula behind the number.

  4. 4

    Decide the path per finding

    For each finding choose to consolidate onto an approved tool, reclaim idle or duplicate seats, or formally sanction the tool. The audit sets the recoverable dollar target so the decision is grounded in spend, not opinion.

  5. 5

    Act on the step-by-step instructions

    Spendassay generates a set of step-by-step instructions with the exact admin-console steps and the affected users. Your own admins execute it in the vendor system. The audit does not write to or throttle any vendor account.

  6. 6

    Track the recovery

    As sources re-sync, Spendassay confirms closed findings and banks them into a Recovered statement. New shadow AI surfaces automatically as fresh grants and charges appear, keeping the inventory current.

Common questions

Does Spendassay read employee prompts or messages to find shadow AI?

No. The audit is read-only and metadata-only. It reads SSO and OAuth grants and card spend to detect tools, but never reads source code, prompts, or message content. Detection works from access and billing signals alone.

Can Spendassay block or shut down a shadow AI tool for me?

No. Spendassay's audit never writes to, routes, or throttles vendor systems. It finds and prices the shadow AI and produces a set of step-by-step instructions. Your own admins execute any change in the vendor console.

Do I need every connector before I can find shadow AI?

No. CSV import works with zero live integrations. Card spend alone surfaces paid shadow tools; adding SSO or OAuth sources like Okta or Google Workspace improves detection of tools connected to corporate identity.

How much shadow AI spend can I expect to recover?

Spendassay is built to surface 10 to 15 percent of seat and subscription spend as recoverable within 30 days. Shadow AI, idle seats, and tool overlap are common sources. Every finding shows its dollar figure and proof level.

Run the audit on your own AI spend

Connect read-only sources and get a CFO-credible AI cost report. Free to start, about 10 minutes to connect.

Practical, evidence-first notes on AI spend. A couple a month. No spam, unsubscribe anytime.