Composite — end of Q2 close. Three expense categories that never used to matter are suddenly material: personal Pro seats reimbursed as “software,” cloud token overages booked under “misc cloud,” and a mid-tower GPU that somehow landed on a cost center meant for monitors. Nobody called it a strategy. It just accumulated — the same way shadow IT always does — until the P&L made it impossible to ignore.

Shadow AI spend is no longer a culture story. It is a controls story. Boards that funded “AI transformation” decks in 2024–2025 are now asking a sharper question: which of these dollars bought durable capability, and which bought convenience with no owner?

Where the money actually hides

The first bucket is seat sprawl. Knowledge workers bought ChatGPT, Claude, Cursor, Midjourney, and a rotating cast of “AI copilots” on personal cards, then expense-reported them as SaaS. Individually trivial. At a thousand employees, it is a seven-figure leak with zero SSO, zero data-handling agreement, and zero offboarding.

Personal cards and checkout counter — ayraix.com view of seat sprawl reimbursed as SaaS
Seat sprawl looks trivial per card — at a thousand employees it is a seven-figure leak with zero SSO.

The second bucket is API and agent overages. A promising pilot wires an agent to a frontier model, then a busy week of retries, tool loops, and verbose traces burns the monthly budget in three days. Finance sees a cloud spike. Engineering sees “we were iterating.” Neither side has a unit cost per successful task.

Analytics dashboard with spend charts — ayraix.com framing of cloud token overages
Finance sees a cloud spike; engineering sees “we were iterating” — neither has cost per successful task.

The third bucket is hardware that escaped the AI budget. Local LLMs are rational for privacy and predictable cost — especially for SAP-adjacent shops that refuse to send client data to a public endpoint. But a quiet GPU purchase without a refresh plan, power budget, or model-ownership story is just CapEx theater. Local AI without ops is another form of shadow spend.

GPU hardware close-up — ayraix.com take on CapEx that escaped the AI budget
A quiet GPU without refresh, power, or ownership plans is CapEx theater — local AI without ops is still shadow spend.

Why CFOs woke up in mid-2026

Two pressures landed at once. First, interest rates and slower deal cycles made “experimental” line items radioactive. Second, security and legal started asking the same audit questions about AI vendors that they ask about any SaaS: DPA, retention, subprocessors, and who can delete a customer prompt. When legal cannot answer, finance stops reimbursing.

Enterprises with mature SAP landscapes feel this sooner. Any tool that can touch master data, pricing, or change documents gets escalated out of “innovation sandbox” language and into change-control language. That is healthy — and it is why shadow AI spend surfaces first in regulated or ERP-heavy environments.

What still gets funded

Not everything freezes. Spend that survives usually has three traits: a named owner, a measurable task (not a vibe), and a path to either centralize (SSO + billing) or deliberately keep local (air-gapped RAG, on-prem agents with eval gates). Pilots that cannot name a kill criterion die first. Pilots that can show cost per completed ticket, per drafted change, or per support deflection keep a pulse.

The winners are boring on purpose: shared model gateways with quotas, approved tool catalogs (including MCP servers you actually trust), and eval suites that fail closed. The losers keep buying seats because a director saw a demo.

What to watch

What to watch: the first wave of companies that publish internal “AI unit economics” — cost per successful agent task — next to their cloud bills. That metric will decide which shadow spend becomes a product line and which becomes a policy violation.