The explosion of AI SaaS tools is creating a new category of shadow IT. How to stay ahead without becoming a blocker.
In 2026, the average knowledge worker uses at least three AI-powered SaaS tools — and fewer than a third of those were formally approved by IT. AI tools create a particularly acute governance challenge because they often ingest sensitive data (documents, emails, code, customer records) in ways that are difficult to audit after the fact.
Traditional shadow IT risk is primarily about access control and cost. AI tool risk adds a data exfiltration dimension: an employee uploading customer contracts to an AI summarisation tool may be violating your data processing agreements with clients, even if completely unintentionally. The stakes are higher, which means the governance response needs to be more robust.
The most practical approach is a tiered framework. Tier 1 (AI tools that process only public data or anonymised internal data) can be approved through a lightweight self-service request. Tier 2 (tools that process internal documents, communications, or code) require IT and security review before adoption. Tier 3 (tools that process customer data, personal data, or regulated information) require legal and DPO sign-off in addition to IT review.
The biggest failure mode in AI governance is a process so slow that employees adopt tools before approval arrives. Set a target of 48 hours for Tier 1 requests and five business days for Tier 2. Anything slower will be routinely bypassed. Use a standardised request form that collects the information you need to assess risk without requiring lengthy back-and-forth.
AI tools have a distinct cost profile compared to traditional SaaS: in addition to the subscription fee, usage-based costs (API tokens, compute credits, image generation credits) can scale significantly with adoption. Build both dimensions into your AI tool inventory — the fixed subscription cost and the variable usage cost — and set up monthly usage alerts for tools with variable pricing models. The first month you don't monitor API spend closely is often the month it exceeds your budget by a material amount.
Per-seat utilisation data matters even more for AI tools than for conventional SaaS, because the gap between licensed and active users is typically wider. Enthusiasm at purchase is high; sustained adoption requires training, workflow integration, and meaningful use cases that connect the tool to daily work. Monitor adoption at 30, 60, and 90 days post-deployment and intervene with training or use-case workshops if adoption is lagging.
One of the most effective ways to reduce AI shadow IT is to build and publicise a catalogue of approved AI tools — a list that employees can browse, understand the acceptable use parameters for, and adopt immediately without going through an approval process. When employees know that ChatGPT Enterprise is available, approved for internal documents with the data handling addendum in place, and accessible through SSO, they're far less likely to use a personal ChatGPT account that has no data protection controls.
The AI catalogue should be living documentation — updated as new tools are approved, as approved tools change their data policies, and as use case guidance evolves. Assign a named owner for the catalogue and set a quarterly review cycle. Communicate additions and policy changes through channels employees actually see — a Slack post and a calendar invite for a brief information session will reach more people than an intranet update alone.
Your Data Protection Officer needs to be a standing participant in the AI tool approval process, not an afterthought. Many AI tools' data processing practices are genuinely ambiguous — whether inputs are used for model training, how long they're retained, whether they're processed by human reviewers — and these ambiguities have direct GDPR implications. The DPO is best positioned to assess these risks and negotiate appropriate contractual protections through a Data Processing Agreement or an Enterprise Agreement with specific data handling addenda.
For tools already in use that haven't gone through a DPO review, conduct a rapid triage: which tools process data that could constitute personal data under GDPR? Prioritise those for immediate review. The conversation with the DPO is easier before an incident than after one.
Track every licence, cut waste, and automate renewals — in one platform.
Comments are moderated before appearing publicly.
No comments yet. Be the first to share your thoughts.
Ronke
Liceo product guide · AI assistant
Hi, I'm Ronke, Liceo's product guide. I can help you understand how we bring licence, vendor, and spend visibility together, or walk through plans and integrations. What are you trying to solve today?