Most businesses did not roll out AI through one big, carefully managed technology project. It happened gradually. Or sometimes not even from the business itself.
Someone started using ChatGPT to help write emails or summarize documents. Another department subscribed to another AI platform because it handled a specific task better. Developers began experimenting with AI coding tools. Microsoft Copilot showed up inside applications people were already using. Other employees found their own tools and started working them into everyday processes.
None of those decisions necessarily creates a problem on its own. In fact, a lot of that experimentation can be useful. Businesses want employees finding better ways to work, automate repetitive tasks, analyze information, and solve problems faster.
The challenge is that AI adoption can spread across an organization much faster than IT, finance, security, or leadership can keep track of it.
That is where AI sprawl starts to become a real business issue.
When organizations do not have a clear picture of which AI tools are being used, who is using them, what they cost, what information is being shared with them, or how they fit into the larger technology environment, it becomes difficult to make informed decisions about governance, security, spending, and long-term strategy.
That is also the focus of All In Technology’s September PizzaCast on AI sprawl, where we will be joined by Cloudbrink to talk about how businesses can get better visibility into AI use before trying to control it.
What Is AI Sprawl?
AI sprawl is the growth of AI tools, accounts, subscriptions, integrations, APIs, agents, and embedded features across an organization without enough centralized visibility or management.
For some businesses, that may mean employees using personal ChatGPT or Claude accounts for company work. For others, it may be several departments independently paying for different AI platforms that provide similar capabilities. AI may also be showing up inside existing SaaS platforms, development tools, browser extensions, productivity applications, automation systems, and other parts of the technology stack.
The difficult part is that there may not be one obvious place to look.
IT may have a list of approved applications. Finance may see another set of subscriptions and expenses. Employees may be using additional tools that never went through a formal procurement or technology review. By the time those different pieces are added together, the organization may have a much larger AI footprint than anyone realized.
That makes a basic question surprisingly difficult to answer:
How is AI actually being used across our business?
For many organizations, answering that question is becoming the first real step toward AI governance.
Why AI Sprawl Happens So Easily
Traditional business software usually creates some friction before it becomes part of the organization.
An enterprise application may need budgeting, procurement, licensing, a security review, implementation, integration, training, and IT support. Those steps naturally create visibility because several people or departments are involved before the technology ever reaches the user.
Many AI tools work very differently from what most companies are used to.
An employee can create an account in a few minutes. A department can purchase a subscription without treating it like a major technology investment. A developer can begin consuming an AI API. Employees can also gain access to new AI functionality through software the company already owns, sometimes without anyone thinking of it as a separate AI deployment.
Microsoft Copilot is a good example of how AI can become part of tools employees are already using every day. We have looked more closely at that in our guide to Microsoft Copilot for business and what IT leaders should prepare for.
That ease of adoption is part of what makes AI useful, but it also makes it much harder to manage through the same processes businesses have traditionally used for software.
Experimentation can quietly become part of the business
A new AI tool often starts as an experiment. Someone finds a faster way to analyze information, write code, create content, summarize meetings, or work with customer data, and over time that tool becomes part of how the person does their job.
The issue is not necessarily that the tool was introduced outside of IT. The bigger concern is when a workflow becomes important to the business while the technology supporting it remains largely invisible to the people responsible for security, continuity, compliance, or technology strategy.
If the person leaves, the account changes, the vendor changes its terms, or sensitive data is involved, the organization may suddenly discover that an important process was built on technology it never formally understood or managed.
AI spending does not always look like traditional IT spending
Cost is another area where AI sprawl can be difficult to see.
Some organizations have large enterprise AI agreements, but many others are accumulating AI costs through dozens of smaller purchases. Those may include individual subscriptions, departmental accounts, premium AI features within existing platforms, API or token usage, development tools, and services that simply appear on an employee expense report.
Each expense may be perfectly reasonable. The problem is understanding what they add up to across the organization and whether several teams are paying for overlapping capabilities.
This is why AI cost management is becoming part of the broader sprawl conversation. Before deciding whether the business is spending too much on AI, leadership needs to know where the spending is occurring, who owns it, how much the tools are actually being used, and what value they are creating.
Hidden AI Costs Are Not Always Easy to Spot
One department may be paying for one AI platform while another team has selected a competing service for nearly the same use case. Several employees may have individual subscriptions even though the organization already has access to a managed corporate platform. Developers may also be consuming AI services through APIs or token-based pricing that does not behave like a predictable monthly software license.
None of this automatically means the company should eliminate those tools. Different teams may have legitimate reasons for using different platforms.
The point is that businesses should be able to make those decisions intentionally rather than discovering them months later on a spreadsheet of expenses.
Once organizations have better visibility, they can begin asking more useful questions:
- Are multiple teams paying separately for similar capabilities?
- Could some individual subscriptions be consolidated into managed corporate accounts?
- Are employees purchasing tools the company already provides?
- Which platforms are actually being used enough to justify their cost?
- Are API and token expenses connected to defined business use cases?
- Are there AI services that nobody clearly owns?
Those questions sit somewhere between IT, finance, operations, and security, which is one reason AI sprawl is not just an IT department problem.
Why Visibility Should Come Before Blocking AI
When businesses first discover unmanaged AI usage, it can be tempting to respond by restricting access.
There are situations where controls are absolutely appropriate, particularly when sensitive information, regulatory requirements, or unacceptable security risks are involved. But a blanket “block everything we did not approve” strategy can create its own problems if employees are using those tools because they solve legitimate business needs.
It can also push AI usage further into the shadows.
A better starting point is understanding the environment. Businesses need enough visibility to know which tools are being used, who is using them, what business processes depend on them, what data is involved, and where costs or duplicated capabilities are developing.
Once that picture is clearer, the organization can make much better decisions about what should be approved, what needs additional oversight, where consolidation makes sense, and which tools genuinely create too much risk.
That visibility-first approach is also why Cloudbrink and its Veraify AI governance platform fit naturally into this conversation. Veraify is designed to provide visibility across different forms of AI usage and then apply governance and policy controls across users, devices, applications, developer tools, and AI agents.
The goal is not simply to find AI activity so it can be blocked. It is to give organizations enough context to decide what should be allowed, what deserves additional oversight, and what should change.
Five Practical Steps for Bringing AI Sprawl Under Control
There is no reason for a business to try to build the perfect AI governance program overnight. The technology is changing too quickly for that approach to work very well anyway.
A more practical strategy is to begin with the environment you actually have today and work forward from there.
1. Find out what people are actually using
Start with discovery first.
Do not assume the official software inventory tells the whole story. Look at the AI applications, individual accounts, APIs, browser tools, development platforms, embedded AI features, and other services people are actually using to get work done.
This is often where organizations discover the difference between their approved AI environment and their real AI environment.
That difference is important. Policies built around an incomplete picture will only go so far.
2. Understand why each tool is being used
Once you have a better inventory, the next question should not immediately be, “How do we get rid of this?”
Ask why people are using it.
A team may have selected a different AI platform because it supports a workflow the approved corporate tool does not handle well. A developer may need an AI service with a specific capability. Another employee may simply be paying for something the company already provides because nobody told them it was available.
Understanding the business purpose behind the technology makes it much easier to separate productive adoption from unnecessary sprawl.
3. Understand what data is involved
AI governance and data governance are increasingly difficult to separate.
Organizations should understand what information employees are entering into AI platforms, which files are being uploaded, what systems AI services can access, and whether sensitive customer, financial, proprietary, regulated, or internal information is involved.
This is also where AI management starts connecting back to broader cybersecurity practices such as identity, access management, device security, data protection, and Zero Trust security.
The goal is not to assume every AI interaction creates a serious security event. It is to understand where meaningful risk exists so controls can be applied where they are actually needed.
For organizations building a more formal governance model, the NIST AI Risk Management Framework is also a useful reference. It is designed to help organizations incorporate trustworthiness and risk considerations into how AI systems are designed, deployed, used, and evaluated, rather than treating AI risk as a one-time review.
NIST also publishes a specific Generative AI Profile for the AI Risk Management Framework for organizations working through risks associated with generative AI and large language models.
4. Look for opportunities to simplify and consolidate
Once usage, purpose, and cost become more visible, businesses can begin making better decisions about the AI stack itself.
Some individual accounts may make more sense under a managed corporate platform. Several overlapping tools may be consolidated. Certain use cases may need specialized platforms while others can be standardized.
For organizations already investing heavily in Microsoft, this may also be the point where Microsoft Copilot and the broader Microsoft AI environment become part of the larger conversation. The right approach will depend on the company’s existing technology environment, workflows, security requirements, and what employees are actually trying to accomplish.
There is no universal answer that says every organization should standardize on one AI platform.
The important part is that those choices are deliberate.
5. Build governance around how people actually work
Once the organization understands its real AI environment, policies become much easier to create.
Instead of starting with a long list of restrictions that may or may not reflect actual behavior, businesses can develop practical guidelines around areas such as approved tools, business use, sensitive information, personal versus corporate accounts, access, procurement, AI agents, APIs, monitoring, and ongoing review.
Those policies should also continue evolving. AI usage six months from now may look very different from what it looks like today.
That same principle applies well beyond AI. In cybersecurity, finding a gap is only useful if the organization has a process for prioritizing it, addressing it, and continuing to monitor the environment. Our discussion of moving from cybersecurity risk assessment to remediation goes deeper into that ongoing assessment-and-improvement approach.
The goal is not to write one AI policy and consider the job finished. It is to create a process that allows the organization to continue learning what is happening and adjusting as the technology changes.
AI Sprawl Is Also a Cybersecurity Issue
The cost and technology-management sides of AI sprawl are easier to see, but there is an obvious security component as well.
Employees may enter information into AI applications, upload files, authorize integrations, connect tools to business systems, or use personal accounts for company work. Developers may be working with AI coding assistants and APIs. Organizations are also beginning to use more AI agents that can take actions and interact with systems rather than simply returning text in a browser window.
That does not mean every new AI tool should immediately be treated as a security threat.
It does mean the organization should understand what is happening.
At All In Technology, we have been talking quite a bit about the growing role of AI in cybersecurity itself. AI can help security teams analyze activity faster, identify patterns, automate certain tasks, and respond more effectively. At the same time, businesses need to consider how their own employees and systems are adopting AI and whether that adoption is introducing new areas they cannot currently see.
We explored that other side of the conversation in our recent look at the role of AI in cybersecurity defenses.
Those two conversations are increasingly connected. Good security decisions depend on visibility, and AI is no different.
Questions Business and IT Leaders Should Be Asking
One useful way to start an AI sprawl conversation internally is to forget about building the perfect policy for a moment and see how many basic questions the organization can answer today.
Do we know which AI tools our employees are currently using?
Are personal AI accounts being used for company work?
Do we know what AI subscriptions are being purchased across departments and employee expenses?
Are multiple teams paying for tools with similar capabilities?
Do employees understand what company information should or should not be shared with AI platforms?
Which AI tools can access business applications or company data?
Do we have a process for evaluating new AI services before they become part of an important workflow?
Could we explain our current AI environment to leadership today without relying on guesses?
If several of those are difficult to answer, the organization may not need a more restrictive AI policy yet.
It may need better visibility.
Join Us for the September AIT PizzaCast
We will be digging further into this topic during our September PizzaCast, AI Sprawl: How to Regain Visibility, Control, and Cost Management.
All In Technology will be joined by Raul Amezcua, Senior Solution Architect at Cloudbrink, for a practical conversation about how organizations can identify unmanaged AI usage, uncover hidden costs and duplication, and begin putting more structure around AI adoption without immediately shutting tools down.
Thursday, September 17, 2026
11:30 AM MT / 12:30 PM CT
Live on Microsoft Teams
Qualified attendees who register by noon MT on September 15 can also receive complimentary pizza for the session.
Register for the September PizzaCast here
You will find previous events at the button below.
Frequently Asked Questions About AI Sprawl
What is AI sprawl?
AI sprawl is the growth of AI tools, accounts, applications, APIs, integrations, and services across an organization without enough centralized visibility or management. As that environment grows, it can become harder for businesses to understand usage, cost, security exposure, and governance needs.
Is AI sprawl the same as Shadow AI?
They overlap, but they are not exactly the same. Shadow AI generally refers to AI tools or usage that happens outside approved IT processes. AI sprawl can include Shadow AI, but it can also include approved technologies when the total number of platforms, accounts, subscriptions, and integrations becomes difficult to manage effectively.
Should businesses block unapproved AI tools?
Not automatically. Some tools may need to be restricted because of sensitive information, security concerns, or compliance requirements. However, businesses generally make better decisions when they first understand what employees are using and why. Visibility allows organizations to distinguish productive use from unnecessary cost or unacceptable risk.
How can AI sprawl increase technology costs?
AI expenses can build up through individual subscriptions, department-level purchases, premium AI features, APIs, token consumption, and overlapping platforms. Once businesses can see actual usage and spending more clearly, they may find opportunities to consolidate accounts, eliminate duplication, or negotiate more appropriate enterprise licensing.
How often should businesses review AI usage?
AI adoption is changing too quickly for a one-time inventory to be enough. Organizations should treat AI visibility and governance as an ongoing technology-management process, periodically reviewing which tools are in use, what they cost, what business purposes they support, what data they access, and whether existing policies still reflect how employees actually work.