The Shadow Bill

A June 11, 2026, Wakefield Research survey of 1,250 office professionals found 66% had used an AI tool they believed their own company policy prohibited. The survey, commissioned by PagerDuty, also found 88% had shared work information with a public AI tool. Six weeks earlier, Verizon's 2026 Data Breach Investigations Report put 45% of professionals on regular AI use at work, 67% of them through personal accounts IT never approved. Both numbers get covered as a security story, correctly. The cost story sitting underneath gets almost no coverage: Gartner puts 25 to 35% of enterprise AI tool spend outside IT visibility entirely, on a budget line growing 40% year over year. That is close to a third of what a company actually spends on AI, sitting completely outside whatever routing, caching, or volume discount its platform team negotiated, because none of that traffic ever touches the system it was built for. Run the two 2026 surveys' adoption rates against an ordinary 500-employee company and the shadow slice lands within a rounding error of Gartner's real reported range, in duplicate personal subscriptions alone, before counting a single personal API key billed at full retail with no caching or routing in front of it. Here's the math, why shadow spend is structurally the most expensive spend a company has, and what actually shrinks it.

Published 2026-08-15 by Dor Amir on the Nadir blog.

Filed under FinOps & Governance.

On June 11, 2026, Wakefield Research published a PagerDuty-commissioned survey of 1,250 office professionals across four countries: 66% had used an AI tool they believed their own company policy prohibited, and 88% had shared work-related information with a public AI tool like ChatGPT, Claude, or Gemini. Six weeks earlier, Verizon's 2026 Data Breach Investigations Report, drawn from more than 22,000 breaches worldwide, put a sharper edge on the same behavior: 45% of professionals now use AI regularly at work, and 67% of them do it through personal accounts their IT team never approved. Non-malicious insider incidents involving unauthorized AI access were up 4x year over year.

Every one of those numbers gets covered as a security story, and it is one. But read past the breach angle and there is a cost story sitting underneath it that gets almost no coverage at all: Gartner puts 25 to 35% of enterprise AI tool spend outside IT visibility entirely, on a budget line growing 40% year over year. That is not a rounding error. It is close to a third of what a company actually spends on AI, sitting completely outside whatever routing, caching, or cost-optimization work its platform team has done, because none of that traffic ever touches the system it was built for.

The stat everyone quotes, and the one they don't

The security framing of shadow AI is well covered, and worth restating quickly: 90% of companies have workers using personal chatbot accounts for work tasks, while only 40% have an official LLM subscription at all, according to MIT's Project NANDA "State of AI in Business 2025." In financial services specifically, 72% of employees use at least one unsanctioned AI tool. Of the professionals sharing information with public AI tools in the PagerDuty survey, 43% shared emails and correspondence, 40% shared meeting notes, 34% shared customer data, and 31% shared financial or confidential documents.

That is the risk side, and it is real. The side that gets skipped is what Gartner's own spend-visibility number implies for anyone running a cost-optimization program: if 25 to 35% of enterprise AI spend never crosses into IT's field of view, then a routing layer, a caching strategy, a negotiated volume discount, a quality-floor policy, none of it touches that slice. A finance team can build the most sophisticated cost-control stack in the industry and it will only ever see 65 to 75 cents of every AI dollar the company actually spends.

What that looks like on an actual payroll

The bill your gateway can see, and the one it can't. Left: 25-35% of enterprise AI spend sits outside IT visibility, per Gartner. Right: an illustrative 500-employee company already spending roughly half again its sanctioned AI budget on shadow subscriptions nobody itemized.
The bill your gateway can see, and the one it can't. Left: 25-35% of enterprise AI spend sits outside IT visibility, per Gartner. Right: an illustrative 500-employee company already spending roughly half again its sanctioned AI budget on shadow subscriptions nobody itemized.

Run the adoption rates from the two 2026 reports above against an ordinary mid-size company and the shadow number stops being abstract.

Take a 500-employee company. Applying Verizon's 45% regular-AI-use rate gives roughly 225 active users. Applying its 67% unauthorized-access rate to that group gives roughly 151 employees running AI usage through a personal account IT does not manage. Assume, conservatively, that each of those 151 is paying for or expensing a single $20 to $25 monthly consumer subscription, ChatGPT Plus, Claude Pro, Perplexity Pro, whatever they picked. That is roughly $3,400 a month, or about $40,800 a year, in duplicate individual seat licenses that show up nowhere as "AI spend" on a budget line, only as scattered personal expense reports or personal credit card charges nobody has aggregated.

Compare that to a company that also pays for an official platform: 225 seats at a representative $30-per-user enterprise plan comes to $6,750 a month, the number IT can actually see and report on. The shadow slice in this model, roughly $3,400 against $6,750 visible, lands close to a third of total AI spend, almost exactly inside Gartner's real reported 25-to-35% range. That check is the point: this is not a contrived worst case, it is what the two real 2026 adoption surveys predict when you run them against a normal headcount.

Monthly costWho sees itOptimized how
Sanctioned platform seats (225 users)~$6,750IT, finance, whoever owns the contractVolume pricing, usage dashboards, whatever routing sits behind the gateway
Shadow personal subscriptions (151 users)~$3,400Nobody, until an expense report is auditedNone. Flat retail rate, no volume discount, no caching, no routing
Personal API keys billed per tokenNot sized hereNobody, and rarely even the individual until the card statement arrivesNone. Full frontier retail rate on every token, every time

And that table understates it. It only counts flat-fee consumer subscriptions. Any employee running a personal API key, wiring a personal OpenAI or Anthropic key into a side script, a browser extension, or an unsanctioned internal tool, is billing every single token at full retail, uncached, unrouted, with no volume discount and no quality-floor policy watching it. That is precisely the traffic a cost-optimization program exists to fix, and precisely the traffic it structurally cannot reach.

Why shadow spend is always the most expensive spend

This is the mechanical reason the cost problem compounds rather than sitting flat. Every technique this blog has covered for cutting an AI bill, model routing to the cheapest capable tier, prompt caching, batch inference discounts, negotiated enterprise rates, requires the request to pass through infrastructure that can apply it. A personal ChatGPT Plus subscription or a bare API key pasted into a script has none of that in front of it. It talks straight to the provider's default, usually the most capable and most expensive model the tool ships with, at full list price, every time.

So the least visible dollar in a company's AI budget is also, structurally, the most expensive dollar. It is the one slice of spend that cannot benefit from anything a platform or FinOps team builds, because it was never routed through anything at all.

It is the same governance failure Gartner already named twice

This blog covered Gartner's prediction that over 40% of agentic AI projects will be canceled by the end of 2027, citing escalating costs, unclear business value, and inadequate risk controls, in that order. Gartner has a separate, more recent projection that lands on the same mechanism from a different angle: shadow AI is expected to be a contributing factor in 40% of enterprise AI project failures by 2027, and organizations without formal AI governance spend 2.5x more on remediation when something goes wrong.

Those are two different Gartner numbers, not the same statistic restated, but they rhyme for an obvious reason. A budget committee cannot compute ROI on spend it cannot see, and cost that is invisible reads, to whoever is deciding whether to keep funding a project, exactly like cost that does not exist until the invoice or the incident report proves otherwise. Shadow AI spend is a special case of that same blind spot: it is not merely under-optimized, it is actively excluded from whatever number a team presents when it argues the project is worth keeping.

Policy alone does not fix a routing problem

The instinctive response is a ban, or a memo. It does not work well on its own: 86% of respondents in the PagerDuty survey already work at organizations with a formal AI policy, and 66% used an unauthorized tool anyway, believing at the time that it violated that same policy. Separately, 52% of organizations have no formal AI use policy at all, per KPMG's 2025 research, so a meaningful share of shadow usage is not even a policy violation, it is simply undefined territory nobody wrote a rule for yet.

This is the same lesson enterprise IT already learned from shadow SaaS and shadow cloud a decade earlier, and it applies again here without much modification: a ban only works if the sanctioned path is not worse than the workaround. Employees route around IT-approved tools for the same reasons they always have, the approved option is slower, more restricted, harder to get provisioned on, or simply worse at the task than the consumer product they already know. A policy that says "don't" without making the sanctioned path competitive just pushes the same usage further out of sight.

What actually reduces the shadow slice

Four things that follow from the mechanism above, not from writing a stricter policy:

  1. Measure it before trying to ban it. You cannot fix 25 to 35% of spend you have never sized. Survey actual usage, cross-reference expense reports for AI-adjacent subscription line items, and get a real number for your own organization instead of assuming Gartner's range applies unchanged.
  1. Make the sanctioned path actually good. If the company-approved tool is slower, capped, or missing the model an employee wants, it will lose to the free or $20 alternative every time. The fix competes on merit, not on the memo.
  1. Give the sanctioned path a real cost advantage. A routed, cached, volume-priced gateway should cost less per unit of useful work than a flat-rate consumer subscription or a bare personal API key, not just be "the approved option." That price gap is the actual incentive to consolidate, and it is measurable per request instead of asserted in a policy document.
  1. Put a dollar figure on every request, not just a monthly total. A monthly aggregate cannot tell you which 25 to 35% is missing. Per-request visibility, the same principle the Linux Foundation's Tokenomics Foundation named abstraction transparency in its August 2026 Big-T framework, is what lets a team actually see the gap closing instead of guessing at it.

Where Nadir fits

Nadir cannot see traffic that never reaches it, no routing layer can. What it changes is the incentive on the other side of that gap: the sanctioned path becomes a two-line integration that scores each request, applies caching, reports actual cost, and adds nadir_metadata.benchmark_comparison.savings_usd when a benchmark comparison is available. That makes the approved path cheaper and more auditable than a personal subscription, which is the lever that pulls usage back into a system a company can see and optimize—not a policy that asks people to stop using the tool that works.

The 25 to 35% Gartner reports outside IT visibility is not a fixed tax. It is the size of the gap between how good and how cheap the approved path currently is, versus the workaround sitting one tab over. Close that gap and the shadow slice shrinks on its own, because there stops being a reason to route around it.

Related reading


Sources: PagerDuty/Wakefield Research, ["Shadow AI Workplace Survey"](https://www.pagerduty.com/newsroom/shadow-ai-workplace-survey-2026/), June 11, 2026 (1,250 office professionals, US/UK/Australia/Japan). Verizon, "2026 Data Breach Investigations Report," covered in The Register, ["Shadow AI invades the workplace, up 4x in the last year"](https://www.theregister.com/ai-ml/2026/05/19/shadow-ai-surges-in-the-workplace/5242868), May 19, 2026. MIT Project NANDA, "The State of AI in Business 2025," August 19, 2025, covered via Yahoo Finance. Gartner, cited in Airia, ["Shadow AI Statistics: Key Data Points Every CISO Needs in 2026"](https://airia.com/blog/shadow-ai-statistics-key-data-points-every-ciso-needs-in-2026/), 2026, for enterprise AI spend visibility, year-over-year growth, remediation cost multiples, and 2027 project-failure projections. KPMG, "AI governance research," 2025, for formal AI policy adoption. Linux Foundation, "Linux Foundation Launches the Tokenomics Foundation," August 4, 2026.

What Nadir is

Nadir is an LLM router. Nadir sizes every prompt and routes it to the cheapest model that still clears your quality bar. A trained pre-classifier scores each prompt in under 10 ms, with no LLM call in the routing step.

Nadir runs two ways. The decision API returns a model, reasoning-effort, cache, context, and policy recommendation without calling a model provider, beside the gateway you already run. That is how a shadow-mode evaluation works, and its projected savings stay advisory. The OpenAI compatible managed proxy executes the route, and migration is a two-line change: point the base URL at api.getnadir.com and set model to auto. On that path an optional verifier can score a complete non-streaming answer and escalate to a stronger model when it misses the configured bar. Streaming bypasses post-generation verification. BYOK is supported on every tier.

What the numbers are, and what they are not

Nadir publishes each evaluation with its scope. On checkable code, run-check-escalate solved 392 of 395 common HumanEval and MBPP problems (99.2%), graded by running the canonical tests; that applies only to tasks with runnable deterministic tests. Nadir-Tumbler posts an arena_score of 72.3 on RouterArena's public scorer, 5th of 23 routers, which measures the routing decision on RouterArena's own model pool. A reference-assisted RouterBench evaluation over 11,420 held-out triples produced a 60% lower projected cost than always-Opus with about 98% retained quality and a 1.7% catastrophic-route rate. That experiment gave the verifier the expensive-model reference answer, which production does not have, so it is a research ceiling and not the deployed path.

None of these is a production guarantee, a universal savings rate, or a forecast for any particular workload. Customer savings are reported from measured execution against a declared baseline, and customer quality only from outcome-labelled traffic. Projected savings and realized savings are separate artifacts and are never blended.

Design-partner program

Three rungs, picked by risk appetite. Rung 0 Shadow runs advisory decision calls alongside live traffic and returns a projected receipt, with nothing in the request path changed. Rung 1 Hosted is the two-line swap on a production slice and returns a realized receipt. Rung 2 On-prem is a supervised six-week proof of concept inside the partner's VPC, where no prompt, response, or usage reaches Nadir. The commitments are the same at every rung. Apply for a rung directly: Rung 0 Shadow, Rung 1 Hosted, or Rung 2 On-prem. Not sure which fits? Start at getnadir.com/contact/?reason=design-partner.

Licensing

NadirClaw is the self-hosted core, source-available under the PolyForm Noncommercial License. Source-available is the correct label; NadirClaw is not open source. Nadir Route's hosted plan has no base fee and charges a variable fee only on measured savings from requests Nadir executed.

Pages on this site

Machine-readable summaries of this site: llms.txt and llms-full.txt.