# Finding the AI spend that never reached your AI budget > Forty staff on personal AI subscriptions is $9,600 a year that never appears in the AI budget, and it leaves through expenses instead. URL: https://getculpa.com/shadow-ai-spend Last reviewed: 2026-08-05 Rates effective: 2026-07-02 ## Answer Shadow AI spend is money leaving the company on tools nobody registered, usually through personal subscriptions and expense claims rather than the API budget everyone watches. It's a procurement problem before it's a cost one. Culpa, a local-first LLM cost, margin, and forecast ledger, prices the traffic you do control so the gap is visible. ## Why this happens Everyone watching AI cost watches the API bill, and the API bill is the part that went through a process. The rest arrives as individual subscriptions on personal cards, browser extensions, tools bundled into products you already buy, and trials that quietly converted. Each one is small enough to clear an expense policy without a conversation, which is precisely why it accumulates. This differs from untagged internal spend in a way that matters for the fix. Untagged spend is your own traffic missing a label, and the answer is instrumentation. Shadow spend is traffic you never knew existed, often not through your infrastructure at all, and no amount of instrumentation on your own systems will find it. The exposure is rarely the money. It's that work is being done, and data sent, through tools nobody has reviewed, and the first time anyone counts is usually during a security questionnaire rather than a budget review. ## What this usually looks like - AI appears in expense claims and not in the AI budget. - Nobody can list the AI tools in use across the company. - Teams have their own subscriptions and nobody consolidated them. - A tool was discovered during a security review rather than a budget one. - Your API spend looks well controlled and total AI spend has never been totalled. ## Common mistakes - Equating AI spend with the API bill. Why it hurts: The API bill is the part that went through a process, which is why it's the visible part. Do instead: Total AI spend across expenses, subscriptions and the API before calling it controlled. - Treating this as an instrumentation problem. Why it hurts: The traffic often never touches your infrastructure, so tagging your own calls won't find it. Do instead: Search expense data and card statements, which is where this spend actually appears. - Banning tools before offering a sanctioned path. Why it hurts: The need was real, so the usage moves further out of sight rather than stopping. Do instead: Provide an approved option first, then consolidate onto it. - Counting only the money. Why it hurts: The larger exposure is unreviewed data handling, and that doesn't show up in a total. Do instead: Treat discovery as a review question, and use the cost figure to get attention for it. ## Self-check - Search last quarter's expense data for the names of the ten largest AI vendors. - Ask each team lead which AI tools their team uses, and compare to your vendor list. - Total personal subscriptions and set that beside your API spend. - Check which of those tools has been through a data-handling review. ## What a modest amount of shadow usage totals (illustrative) A modelled 40 staff each holding a personal AI subscription at $20 a month, expensed individually rather than procured centrally. Every figure here is modelled, and deliberately conservative: it assumes one subscription each and no team tools, no bundled add-ons and no API keys held outside the main account. 40 people x $20 a month = $800.00 a month over a year: $800.00 x 12 = $9,600.00 none of it appears in the AI budget, because none of it was procured as AI at a negotiated team rate the same coverage would typically cost less, and would be reviewable Ten thousand dollars a year is small enough that no single claim triggers anything and large enough to matter once. The number is worth producing mainly because it gets the conversation started, and the conversation is about data handling rather than about the money. ## Cost figures Every figure carries its confidence and its source. No figure on this page is provider-reported. - $9,600.00 a year, modelled annual cost of 40 personal AI subscriptions expensed individually [calculated] Source: A modelled 40 staff each holding one $20 monthly personal subscription: 40 x $20 = $800.00 a month, and $800.00 x 12 = $9,600.00 a year. Every input is modelled and deliberately conservative, assuming one subscription each with no team tools, bundled add-ons or externally held API keys. ## FAQ Q: What counts as shadow AI spend? A: Any AI tool in use that nobody registered: personal subscriptions on expenses, browser extensions, trials that converted, and features bundled into products you already buy. The defining trait is that it never went through procurement, so it never reached the AI budget. Q: How much is it usually? A: Smaller than people fear and larger than nothing. A modelled 40 staff on $20 personal subscriptions is $800.00 a month and $9,600.00 a year. The reason to total it lies elsewhere than the money. Q: Can a cost tool find shadow AI? A: Not if the traffic never touches your infrastructure, which is usually the case. Cost tooling prices calls it can see. Discovery comes from expense data, card statements and asking team leads what they use. Q: Should we just ban unapproved tools? A: Banning without providing a sanctioned alternative tends to move usage further out of sight, because the need that created it doesn't go away. Offering an approved option first and consolidating onto it gets both the visibility and the saving. ## Sources - Anthropic pricing: https://platform.claude.com/docs/en/docs/about-claude/pricing Run the free Cost Leak Scan: https://app.getculpa.com/scan?source=pseo&slug=shadow-ai-spend&cluster=problem Machine-readable index of every guide: https://getculpa.com/api/pages Human-readable index of every guide: https://getculpa.com/guides Site overview: https://app.getculpa.com/llms.txt Privacy: Culpa runs on your infrastructure. Your prompts and responses never leave it. Culpa counts calls to run your plan, and it fails open, so if it ever breaks your app keeps running.