Insights · Shadow IT & shadow AI

From SaaS sprawl to shadow AI: what enters unseen

Too many scattered subscriptions is an old problem. What is new: employees pasting company data into AI tools nobody approved, and AI features quietly appearing in software you already owned.

Published 30 June 2026 · Reading time ± 6 minutes · Practice article

There is a reason shadow IT was never solved: it is not an incident but a structural consequence of how software is bought today. Business units buy directly, the corporate card is faster than the procurement process, and the vendor does not ask whether IT knows. What changed this year is the stake: it is no longer only about duplicate licences, but about company data disappearing into third-party models.

The numbers behind the gut feeling

Verizon measures annually how breaches occur. Its 2026 Data Breach Investigations Report contains the most telling series available right now: the share of employees using unapproved AI tools rose from 15% to 45% in a single year, and that usage is now the third most common way data leaks unintentionally. Independently, a survey of two thousand employees at organisations with more than five hundred staff confirms the picture: 49% used AI tools without employer approval and 51% connected such a tool to work systems without involving IT.

The same edition contains the figure that hits vendor management: 48% of all breaches involved a third party. Two editions earlier that was 15%, then 30%. A tripling in two years. Anyone still treating vendor risk as an annual questionnaire is not managing the largest category.

The size of the portfolio

The underlying problem is scale. Zylo, which measures customer SaaS spend, reports an average of 305 applications per organisation in 2026, with a median of 240; large enterprises add 21 per month on average. Research by BetterCloud among more than five hundred IT and security professionals shows only 56% of those applications carry formal IT approval — roughly 44% run without it. One in five organisations discovered new unsanctioned SaaS and AI tools in the past year, and 18% found data leaks coming directly from AI tools or chatbots.

The centre of gravity of spend also left IT long ago. On the same data, business units control 81% of SaaS spend while IT directly manages 15%. That explains why control from a single department does not work.

Why your login system will not find it

Most organisations hunt for shadow IT through their identity provider: which applications use single sign-on? Useful, but precisely the channel the new generation of tools bypasses. The strongest growth is in spend running through expenses and corporate cards — up 267% year on year, with ChatGPT now the most expensed application. A tool someone pays for personally and uses with a private account never appears in your SSO reporting.

Effective discovery therefore draws on at least four sources at once: login data for what officially runs, expense and accounts payable data for what is on the card, network or browser telemetry for what is being called, and the contract register for what was signed. Only when those four sit side by side does a complete picture emerge — and it usually contains an unpleasant surprise.

Meanwhile the cost side is rising

Sprawl is not only a risk problem. In 2026, 79% of IT leaders faced a price increase at renewal, and 78% saw unexpected charges from consumption-based or AI pricing models, up from 66.5% the year before. For 61%, that forced projects to be cut. The Vertice SaaS inflation index, based on the spend they manage, reached 16.4% in June 2026 against general inflation of 4.2% — roughly four times higher. That is a vendor source rather than a statistical agency, but the direction is broadly corroborated.

Visibility is weakest exactly where growth is fastest: only 31% of organisations have visibility into AI software spend and only 29% measure its value, while 59% report that waste on AI spend has increased.

What does work

Four things, in this order. Discover from multiple sources as described above, and repeat it — this is a rhythm, not a project. Give every application an owner in the business, because that is where 81% of the money sits; an owner without budget is not an owner. Build a renewal calendar: an average organisation processes some 211 renewals a year, roughly one per working day, and the cancellation deadline in practice falls thirty to ninety days before expiry — miss that date and you are no longer negotiating. And put AI explicitly on the quarterly agenda: not just how many accounts, but what consumption, with which data, under which terms.

For the AI part this is not purely a cost story. What staff paste into uncontrolled tools — research data, personnel records, financial figures — is exactly what you must be able to account for under the GDPR and the AI Act. Our approach is on the AI governance page.

Want to know what is running in your organisation?

We combine your login data, expense records and contracts into one overview of every SaaS and AI tool — including the ones nobody requested.