TL
The short answer

Shadow AI spend is GenAI consumption that runs outside any governed budget: a developer's personal API key billed to a corporate card, model calls buried inside a SaaS subscription, inference jobs spun up in an unmonitored project, or a notebook calling a hosted model with no tagging. It is the fastest growing line in many cloud estates because AI access is trivially easy to start and rarely attributed to a cost center. You surface it by triangulating three sources: the cloud billing data filtered to AI services, the identity and access logs that show who created AI resources, and the network egress to model endpoints. Anything that shows cost or traffic but has no owner tag is shadow spend, and the fix is attribution before restriction.

Here is where shadow AI hides, the discovery steps that find it, and how to bring it under governance without blocking the teams using it.

Why does AI spend escape normal controls?

Traditional cloud governance assumes resources are provisioned through known channels and tagged on creation. AI breaks that assumption in three ways. First, access is often a single API key, which can be created and used without standing up any tagged infrastructure. Second, much AI consumption is embedded in SaaS products, so the cost appears as a software subscription rather than cloud usage. Third, the unit of spend, a token or a GPU hour, is small and frequent, so individual charges stay below the thresholds that trigger review while the aggregate grows quickly. The result is spend that is real, growing, and invisible to the monthly cloud review.

Where does shadow AI actually hide?

  • Unattributed API keys. Model API usage on AWS, Azure, GCP, and OCI billed to an account with no cost allocation tags pointing at a team or product.
  • SaaS add ons. AI features inside existing SaaS tools, charged on the software line and never counted as AI spend. The State of FinOps 2026 shows scope expanding precisely to capture SaaS and AI together.
  • Notebooks and dev environments. Data science notebooks calling hosted models, often running on long lived instances that stay up between experiments.
  • Orphaned capacity. Provisioned throughput or GPU capacity reservations bought for a pilot and never released after it ended.

How do you discover it?

  1. Filter billing to AI services. Pull the cloud billing data, the Cost and Usage Report on AWS and its equivalents on Azure, GCP, and OCI, and isolate model, inference, and GPU line items. Anything without an owner tag is a candidate.
  2. Walk the identity trail. Use access logs to see who created AI resources and which keys are active, then map each to a team. Active keys with no named owner are the priority.
  3. Inspect egress. Network traffic to model endpoints reveals consumption that billing alone misses, especially calls to externally hosted models.
  4. Reconcile SaaS. Review software subscriptions for embedded AI features and bring that spend into the same view as cloud AI cost.

How do you govern it without blocking teams?

The goal is attribution, not prohibition. Once every AI charge has an owner, apply the same controls you use elsewhere: a tagging policy that AI resources must carry, a small number of approved access paths so new usage is governed by default, budgets and anomaly alerts per team, and a review cadence that treats AI as its own line. Token costs, GPU capacity, provisioned throughput, and capacity reservations each need their own governance because they behave differently. Restricting access before you understand usage simply pushes teams further into the shadow; making the governed path the easy path is what brings spend into the light and keeps it there.

A worked example

Worked example

A scaling fintech believed its AI spend was a single governed inference service. Filtering billing to AI line items and walking the identity trail told a different story: roughly a third of total AI cost ran through unattributed API keys and data science notebooks left running between experiments, plus an embedded AI feature charged on a SaaS subscription that no one counted as AI. We tagged every active key to a team, shut down idle notebook instances, released a capacity reservation bought for a pilot that had ended, and pulled the SaaS AI cost into the same monthly view. Attribution alone cut the unmanaged portion sharply and gave the finance team a single AI number it could forecast. The recovered spend supported the wider program that left the company materially lighter on cloud cost. Figures are verified against billing data and anonymised.

Frequently asked questions

What is shadow AI spend?
GenAI consumption that runs outside any governed budget, such as personal API keys, model calls embedded in SaaS products, notebooks calling hosted models, and orphaned GPU or throughput reservations. It is real and growing but invisible to the standard cloud review.
How do you find shadow AI spend?
Triangulate three sources: cloud billing data filtered to AI services, identity and access logs showing who created AI resources, and network egress to model endpoints. Anything with cost or traffic but no owner tag is shadow spend.
How do you control it without blocking teams?
Start with attribution, not prohibition. Tag every AI charge to an owner, make the governed access path the easy one, set per team budgets and anomaly alerts, and review AI as its own line covering tokens, GPU hours, provisioned throughput, and reservations.

Talk this through with us

We help enterprises surface and govern shadow AI spend across AWS, Azure, GCP, and OCI, tying every token and GPU hour to an owner without slowing the teams that use it. We take zero provider commissions and answer only to you. Our guarantee: we reduce your cloud spend or we reimburse our service fee, on either a Fixed Fee scoped up front or a no risk Gainshare basis. Book a strategy call to scope it for your estate, and follow more analysis in The Cloud Spend Navigator.

Independent · buyer-side

Put a defensible number on your cloud spend.

No provider in the room, no published price list. Tell us your footprint and we will scope the savings against your billing data — we reduce your cloud spend or we reimburse our service fee.

Buyer-side intelligence, monthly.

The Cloud Spend Navigator: what changed in cloud pricing, commitments, and FinOps — no vendor spin.