SaaS sprawl is not a spend problem. It is a SaaS inventory problem, and an inventory problem is the exact condition that makes shadow AI possible.
Most IT Directors I speak to have a pretty good handle on their sanctioned SaaS stack. They know what's in Okta, they know what shows up on the credit card statements, they have a rough count of licences. What they don't have is visibility of everything else: the project management tool one team started a free trial of six months ago and forgot to cancel, the AI writing assistant three people in marketing are using with company data, the analytics platform someone connected via OAuth that nobody approved.
That gap, between what IT thinks it manages and what the organisation actually uses, is where shadow AI lives. And closing it requires something most organisations skip: a complete, continuous inventory before you try to govern anything.
How Sprawl Produces Shadow AI Exposure
SaaS sprawl and shadow AI are not separate problems. They are the same problem at different stages of the same cycle.
It starts with decentralised procurement. A department head approves a SaaS tool on a company card without going through IT. Six months later, that tool releases an AI feature; embedded, auto-enabled, processing whatever data is already in the platform. Nobody reviewed it. Nobody consented to it. This is SaaS governance failing at the point where it matters most: the moment a tool changes what it does with your data.
This is not an edge case. Montro's discovery audits consistently find that roughly half the AI tools in a given environment arrived not as deliberate AI procurement decisions, but as features inside SaaS tools that were already there; activated by a product update, enabled by default, never reviewed. Harmonic Security's 2025 Annual AI Usage Index, drawing on over 22 million enterprise prompts, found 665 distinct AI tools in active use across enterprise environments, the vast majority with no central IT oversight. A Fishbowl survey of over 11,700 professionals found that 70% of those using generative AI for work had not disclosed that usage to their employer. Employees are not just adopting AI tools that IT can't see, they are actively keeping it that way.
The pattern looks like this: SaaS sprawl creates an unmonitored application estate. AI features activate inside that estate. The result is shadow AI exposure that no governance programme can address because it was never discovered in the first place.
The Three Places Your AI Inventory Breaks
When I look at how organisations' SaaS inventories fail to capture AI usage, it tends to break in three consistent places.
1. SSO coverage gaps
Most IT teams use their identity provider; Okta, Azure AD, Google Workspace, as their de facto SaaS inventory. If it's in SSO, it's managed. The problem is that in Montro's audit experience, SSO coverage across a typical mid-market organisation sits at around 60–70% of the actual application estate. The remaining third are connected via OAuth grants, shared credentials, or individual sign-ups that never touched the IdP. Those applications, the ones outside SSO, are precisely where unreviewed AI tools cluster, and where software inventory management that relies on the identity provider alone systematically fails.
2. Embedded AI that bypasses procurement
Tools like Microsoft 365 Copilot, Salesforce Einstein, Slack AI, and HubSpot's AI features don't arrive through a purchasing decision. They are toggled on by an admin, often during a routine update, sometimes by default. The procurement team never saw a contract. IT never ran a risk assessment. The tool is live and processing data before anyone has a chance to ask whether it should be.
Montro's discovery consistently surfaces these embedded activations as some of the highest-risk findings in an audit, not because the tools themselves are necessarily dangerous, but because the organisation has no documentation of their existence, no DPA in place, and no way to demonstrate governance over them.
3. Remote and hybrid workforce adoption
The shift to distributed work accelerated SaaS adoption in ways that central IT still hasn't fully mapped. Employees working from home adopted tools to solve problems that used to be solved by walking across the office. Many of those tools are AI-native. Many were signed up for on personal email addresses, with company data being processed on consumer-tier accounts that have no data processing agreements and no enterprise controls.
Harmonic Security's Q3 2025 analysis of over three million enterprise prompts found that 11.84% of sensitive data exposures occurred through personal or free-tier AI accounts, tools that sit entirely outside corporate controls. That figure is almost entirely invisible to an IT team relying on SSO logs and expense reports as their primary discovery mechanism.
Why the Spend Data Finance Has Is Your Fastest Discovery Shortcut
Here is something most IT Directors and CFOs don't realise they have in common: the Finance team's expense data is one of the most reliable early signals of shadow AI adoption in the organisation.
A conversation that rarely happens in an organisation is the one between IT and Finance. IT has the SSO logs, and Finance has the expense lines. Neither is sufficient on its own, but if combined, they produce a more complete picture of the application estate than either team has seen before. In every organisation where we have run that cross-reference for the first time, both teams were surprised. IT finds tools they had no record of, and finance finds spend categories it had never thought to flag. The data was always there, but nobody thought of putting it together. - Ankur Arora, Co-Founder, Montro |
When an employee signs up for an AI tool on a company card; ChatGPT Plus, Midjourney, Otter.ai, Notion AI - it shows up as a line item in the expense system. The amount is small enough to pass through without scrutiny. But aggregated across a department or across the organisation, those line items add up to a meaningful picture of what people are actually using.
Gartner estimates the average organisation now runs over 100 SaaS applications, with analysts consistently finding that 30% or more of software spend represents waste, licences paid for that generate no active usage. A significant and growing portion of new SaaS spend is on AI tools, often without any procurement process, any security review, or any contract that gives the organisation the rights it needs to use the tool compliantly.
Running a cross-reference between expense data, credit card statements, and your SSO logs takes a few hours and produces a list of applications that almost nobody in IT or Finance knew they needed to care about. That list is the starting point for a real SaaS inventory, and a real SaaS governance programme.
Visibility Has to Come Before Governance. There Is No Other Order.
The instinct when shadow AI becomes a boardroom concern is to reach for policy. Write an acceptable use policy. Create an AI register. Ask employees to declare what tools they're using.
Declaration-based inventories are structurally incomplete. In Montro's audit work, management-declared AI inventories consistently undercount the actual application estate, often by half or more. The tools employees forgot to mention, the embedded AI features nobody knew had activated, the free-tier accounts nobody thought counted, those don't show up in a survey.
A governance programme built on a 50% inventory is not a governance programme. It is a compliance document that will be wrong when a regulator or auditor asks to see it.
The sequence has to be: discover first, then classify, then govern. Not the other way around.
This is what we call the discovery-first principle at Montro. Before we ask whether an AI tool is compliant, we need to know it exists. Before we can classify it against any risk framework, we need accurate data about what it does, where it processes data, and how it reached the organisation.
None of that is possible without a complete, continuously updated inventory.
What a Working SaaS Intelligence Layer Looks Like
Montro's discovery runs across four vectors simultaneously, because no single source is sufficient on its own:
- IdP and SSO integration captures sanctioned applications with user-level access data, the 60–70% of the estate that went through a proper process
- Browser extension or network telemetry captures the applications that exist outside SSO; the OAuth grants, trial sign-ups, and shadow tools that never touched the identity provider
- Email and calendar metadata analysis surfaces SaaS tools that communicate via API or notification but don't appear in the IdP, a category that consistently surprises IT teams
- Expense and financial data ingestion catches AI tool spend that bypassed IT entirely, the ChatGPT Plus subscriptions, the Notion AI upgrades, the tools someone put on the company card because the free tier wasn't enough
An organisation relying only on SSO will miss the 30–40% of its stack that never went through the IdP. An organisation relying only on expense data will miss the tools employees signed up for on personal accounts or free tiers. Only when these vectors are combined and deduplicated does a complete picture emerge.
What comes out the other end is an application record for every tool in use, including AI-specific metadata: what type of AI the tool uses, whether it trains on company data, where that data is processed, and whether the vendor has a data processing agreement in place. That record is the asset your compliance team needs to work from. It is what makes an AI register accurate and a governance policy enforceable.
The Cost of Getting the Order Wrong
Organisations that try to govern before they discover run into the same wall every time: the policy applies to the tools people declared, not the tools they're actually using. An acceptable use policy that covers the AI your employees told HR about is not a policy that covers shadow AI. By definition, shadow AI is the portion nobody declared.
When something goes wrong; a data exposure, a regulatory enquiry, a vendor breach, the first question is always 'what tools were involved?' If the answer is 'we're not sure,' that is an expensive position to be in. The cost of a 30-day discovery audit is fixed and low. The cost of finding out your governance programme had gaps during an incident is neither.
Frequently Asked Questions
What's the difference between SaaS sprawl and shadow AI?
SaaS sprawl refers to the unmanaged proliferation of software applications across an organisation; tools procured outside IT, unused licences, redundant functionality. Shadow AI is what happens inside that sprawl: AI features that activate within ungoverned SaaS tools, or AI applications that employees sign up for independently. The two are connected because shadow IT rarely arrives as a deliberate procurement decision, it arrives as a consequence of an unmanaged application estate.
How do most organisations currently try to discover shadow AI, and why does it fail?
The most common approaches are SSO log analysis and employee declaration surveys. Both have significant coverage gaps. SSO logs miss the 30–40% of applications that were never connected to the identity provider. Employee surveys capture what people remember and choose to disclose, which consistently underestimates actual usage by 50% or more. Multi-vector discovery; combining SSO, browser telemetry, email metadata, and financial data, is the only approach that produces an inventory accurate enough to build governance on.
Our CFO wants to address SaaS spend waste. Our CISO wants to address shadow AI risk. Are these the same project?
They start in the same place: a complete, accurate inventory of every application in use. The same discovery process that identifies unused licences and duplicate tools also surfaces ungoverned AI applications and unreviewed data processing relationships. Running a single discovery audit addresses both agendas, it gives Finance the spend visibility it needs and gives the security team the application estate it needs to classify and govern AI tools. The ROI case for a Discovery Audit is easier to make when both stakeholders are in the same room.
How often does a SaaS inventory need to be refreshed to stay accurate?
In a mid-market organisation of 200–1,000 employees, the application estate changes materially every few weeks. New tools are adopted, free trials convert to paid subscriptions, embedded AI features are toggled on during product updates. A point-in-time audit is useful as a starting baseline, but accurate governance requires continuous or near-continuous discovery; at a minimum, a refresh every 30 days. The organisations that get this right tend to treat discovery as infrastructure, not a project.





