Guides / shadow ai spend

Finding the AI spend that never reached your AI budget

Shadow AI spend is money leaving the company on tools nobody registered, usually through personal subscriptions and expense claims rather than the API budget everyone watches. It's a procurement problem before it's a cost one. Culpa, a local-first LLM cost, margin, and forecast ledger, prices the traffic you do control so the gap is visible.

Why this happens

Everyone watching AI cost watches the API bill, and the API bill is the part that went through a process. The rest arrives as individual subscriptions on personal cards, browser extensions, tools bundled into products you already buy, and trials that quietly converted. Each one is small enough to clear an expense policy without a conversation, which is precisely why it accumulates. This differs from untagged internal spend in a way that matters for the fix. Untagged spend is your own traffic missing a label, and the answer is instrumentation. Shadow spend is traffic you never knew existed, often not through your infrastructure at all, and no amount of instrumentation on your own systems will find it. The exposure is rarely the money. It's that work is being done, and data sent, through tools nobody has reviewed, and the first time anyone counts is usually during a security questionnaire rather than a budget review.

What this usually looks like

  • AI appears in expense claims and not in the AI budget.
  • Nobody can list the AI tools in use across the company.
  • Teams have their own subscriptions and nobody consolidated them.
  • A tool was discovered during a security review rather than a budget one.
  • Your API spend looks well controlled and total AI spend has never been totalled.

Free, no card, no account

Run the free Cost Leak Scan

It shows your most expensive conversation before you install anything.

Run the free Cost Leak ScanStart 14-day trial

Mistakes that cost the most

MistakeWhy it hurtsDo instead
Equating AI spend with the API bill.The API bill is the part that went through a process, which is why it's the visible part.Total AI spend across expenses, subscriptions and the API before calling it controlled.
Treating this as an instrumentation problem.The traffic often never touches your infrastructure, so tagging your own calls won't find it.Search expense data and card statements, which is where this spend actually appears.
Banning tools before offering a sanctioned path.The need was real, so the usage moves further out of sight rather than stopping.Provide an approved option first, then consolidate onto it.
Counting only the money.The larger exposure is unreviewed data handling, and that doesn't show up in a total.Treat discovery as a review question, and use the cost figure to get attention for it.

Run this check tonight

  1. Search last quarter's expense data for the names of the ten largest AI vendors.
  2. Ask each team lead which AI tools their team uses, and compare to your vendor list.
  3. Total personal subscriptions and set that beside your API spend.
  4. Check which of those tools has been through a data-handling review.

What a modest amount of shadow usage totals

Illustrative example

A modelled 40 staff each holding a personal AI subscription at $20 a month, expensed individually rather than procured centrally. Every figure here is modelled, and deliberately conservative: it assumes one subscription each and no team tools, no bundled add-ons and no API keys held outside the main account.

40 people x $20 a month = $800.00 a month
over a year: $800.00 x 12 = $9,600.00
none of it appears in the AI budget, because none of it was procured as AI
at a negotiated team rate the same coverage would typically cost less, and would be reviewable

Ten thousand dollars a year is small enough that no single claim triggers anything and large enough to matter once. The number is worth producing mainly because it gets the conversation started, and the conversation is about data handling rather than about the money.

Every number, with its confidence and source

FigureWhat it meansConfidenceSource
$9,600.00 a yearmodelled annual cost of 40 personal AI subscriptions expensed individuallycalculatedA modelled 40 staff each holding one $20 monthly personal subscription: 40 x $20 = $800.00 a month, and $800.00 x 12 = $9,600.00 a year. Every input is modelled and deliberately conservative, assuming one subscription each with no team tools, bundled add-ons or externally held API keys.

What a generic answer can’t know

This is a category Culpa genuinely can't see, and saying so plainly is more useful than implying otherwise. Culpa prices calls that go through your own infrastructure. A colleague using a personal subscription in a browser never touches it, and no cost tool built on your traffic will ever find that spend. What Culpa does is remove the other explanation: when your own API spend is fully attributed down to the feature and customer, the difference between that figure and what the company actually spends on AI stops being ambiguous. Discovery still comes from expense data and asking people. Having a complete, defensible number for the traffic you do control is what makes the gap obvious rather than arguable.

Questions founders ask next

What counts as shadow AI spend?

Any AI tool in use that nobody registered: personal subscriptions on expenses, browser extensions, trials that converted, and features bundled into products you already buy. The defining trait is that it never went through procurement, so it never reached the AI budget.

How much is it usually?

Smaller than people fear and larger than nothing. A modelled 40 staff on $20 personal subscriptions is $800.00 a month and $9,600.00 a year. The reason to total it lies elsewhere than the money.

Can a cost tool find shadow AI?

Not if the traffic never touches your infrastructure, which is usually the case. Cost tooling prices calls it can see. Discovery comes from expense data, card statements and asking team leads what they use.

Should we just ban unapproved tools?

Banning without providing a sanctioned alternative tends to move usage further out of sight, because the need that created it doesn't go away. Offering an approved option first and consolidating onto it gets both the visibility and the saving.

On your infrastructure

Culpa runs on your infrastructure. Your prompts and responses never leave it. Culpa counts calls to run your plan, and it fails open, so if it ever breaks your app keeps running.


How Culpa works

Find the culprit. Not just the total.

Your dashboard shows what you spent. It stops short of who spent it. Culpa shows the conversation, the user and the feature behind it.

Your prompts stay local.

Culpa runs on your own infrastructure. What you send to a model reaches us at no point.

Every dollar has a name.

Follow any charge to the conversation, the user, the feature and the customer behind it.

See the bill before it lands.

Cost your next feature before you ship it. You get the likely bill and the worst case, at best, median, p90 and p99.

Three steps to your first answer.

1

Change one base URL.

Or drop in the Python or TypeScript library.

2

Find your most expensive conversation.

In the first session, not the first week.

3

Cost your next feature before you ship it.

Base URLhttp://localhost:4545/v1Your traffic keeps flowing if Culpa ever stops.

Why the bill went up

Example dashboard

Calls traced

418,209

across 3 projects

Spend this week

$378.41

+ $182 vs last week

Failed calls

312

74% retried, and you paid for all of them

+ $182 this week traced to one culprit

Spend over 14 days

$0$20$40$60$8024262830020406
user_384report_generatorconv_91fprompt_v1894,220 tokens3 retries$6.81

Most expensive users

user_384$38.42
user_119$21.07
user_562$14.90
user_204$8.30
user_871$5.10

Next week forecast

Best$180
Median$240
p90$310
p99$395

Graded against reality. Accuracy shown as results land.

Keep reading


Sources: Anthropic pricing. Last reviewed 2026-08-05, rates effective 2026-07-02. Plain text version.