FIVE Surprising Stats About SaaS Waste in Enterprise IT
Five numbers on SaaS waste — unused licences, portfolio sprawl, dollars burned, AI spend growth and cloud waste — and why visibility alone never fixes any of them.
- SaaS
- AI
- Governance
- FinOps
Most AI spend is not arriving as new invoices. It is arriving inside software you already own, priced per token, owned by nobody. Six commercialisation patterns, why per-seat governance cannot see them, and what to do instead.
You think you know what your AI costs. You are looking at a handful of model-API invoices and a short list of standalone subscriptions, and you are treating that as the bill. That understates the problem by an order of magnitude.
The real AI spend is not arriving as new line items. It is arriving inside software you already own — folded into Microsoft 365, switched on in Salesforce, bundled into Google Workspace. It carries no separate purchase order, triggers no security review, and reports to no single owner. Call it the invisible layer: the copilots, agents and embedded AI features running across your organisation that nobody is tracking as a single asset.
Gartner forecasts worldwide AI spending will reach $2.59 trillion in 2026, a 47% rise year on year (Gartner, Gartner Forecasts Worldwide AI Spending to Grow 47% in 2026, 19 May 2026). The headline number is not the danger. The distribution is. Much of that money moves through channels your current tooling cannot see, priced in a way your current playbooks cannot manage.
The mental model most organisations run is built for purchasing. Procurement watches for new vendors. Security reviews new applications. FinOps reconciles new invoices. Every gate is placed at the front door.
Embedded AI does not come through the front door. It does not announce itself as new. It appears as a price rise on a renewal, or as a feature toggle inside an application you approved two years ago. The controls you built were designed for a purchase event, and this is not one.
The shape of the growth backs that up. Across enterprise SaaS portfolios, use of applications in the AI category grew 181% year on year, and spending on AI-native applications at large enterprises grew 393%. That is not a handful of new contracts. That is an existing portfolio changing what it does and what it costs.
The structural failure is ownership. Right now every relevant function sees a fragment:
Four functions. Four partial views. No accountability for the whole. The AI asset — its cost, its data reach, its entitlement obligations, its renewal exposure — falls through every gap between them.
Your Cloud Access Security Broker will not close this. CASB tools were built to flag unsanctioned applications and inspect traffic to known destinations. They cannot see an AI capability activated inside an application they have already approved. When a user enables Copilot in a sanctioned Microsoft 365 tenant, the CASB sees sanctioned Microsoft 365 traffic. The AI is invisible by design.
You cannot govern what you cannot see, and right now you cannot see the layer growing fastest.
Shadow AI is often treated as another shadow IT category. That understates it.
The consequences are already measurable. One in five breached organisations was compromised through shadow AI — unsanctioned generative AI tools adopted without security sign-off — and a high level of shadow AI added roughly $670,000 to the average breach cost. Among organisations that suffered an AI-related security incident, 97% said they lacked proper AI access controls, and 63% of organisations had no AI governance policy at all (Source: IBM, Cost of a Data Breach Report 2025).
Exposure is widespread. Controls are not.
The mechanism is what makes it different. Shadow IT exfiltrates data at the speed of a misconfigured share. Shadow AI does it at the speed of a single prompt. One paste into a public model can move source code, customer records or commercial terms outside your control in seconds, with no log, no recall and no boundary on where it lands.
A copy-paste of your legacy shadow IT playbook will not cover this. Shadow AI needs its own discovery and governance lens.
You cannot manage the cost until you understand how vendors charge for it. AI is being commercialised through six distinct patterns, each with different cost behaviour, and each defeating a different assumption in your current controls.
1. The flat-rate per-seat add-on. A fixed monthly fee per user, layered onto an existing licence. Microsoft 365 Copilot is the reference case. The trap is utilisation: you are paying per seat for a capability that consumes per token, and the seats you bought do not match the usage you are getting. Nothing in a per-seat contract tells you which of those seats went cold.
2. The bundled price rise. AI is folded into the base product and the whole customer base pays more, whether they use it or not. Google folding Gemini into Workspace Business and Enterprise plans is the pattern to study: there was no opt-in line item to scrutinise. The AI cost arrived as a renewal number. Silent inclusion, mandatory payment.
3. The consumption-based token or credit pool. Cost tracks usage directly — tokens drawn down, credits depleted, overages billed. This is the honest model economically, and the one per-seat asset management was never designed to handle. A pool that looks generous on day one empties faster as users get fluent, and the bill scales with adoption rather than headcount.
4. The agentic outcome model. You pay per task, per conversation or per resolved action, and this is where budgets break. The mechanism is token intensity: an agent does not answer once. It reasons, retrieves, calls tools and iterates. Each loop is a cost event. Multiply that across a workforce and the forecast you approved bears little resemblance to the invoice you receive.
5. The tiered persona model. Vendors gate features and usage ceilings across tiers mapped to personas — casual, power, professional — each at a different limit. The structure is sound, but it shifts the burden to you: match the right person to the right tier, then keep that mapping accurate as usage shifts. Get it wrong and you over-provision the light users while throttling the heavy ones.
6. The hybrid model. A flat subscription for baseline access, plus usage-based overages for the tail. This is becoming the default, because it captures the mass market on a predictable fee while protecting the vendor’s margin against power users. For you it means one product billing under two logics at once, and reconciliation that has to track both.
The through-line: every one of these produces cost that is consumption-driven, structurally volatile and impossible to forecast from a seat count. Per-seat governance is the wrong instrument for a token-priced world.
The patterns above are the present. Agents are the near future, and the trajectory is already set.
Gartner predicts 40% of enterprise applications will feature task-specific AI agents by 2026, up from under 5% in 2025 (Gartner, press release, 26 August 2025). That is not a niche. That is your application portfolio quietly becoming a fleet of token-consuming agents, most of them switched on without a cost model attached.
Then comes the correction. Gartner also predicts over 40% of agentic AI projects will be cancelled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls (Gartner, press release, 25 June 2025). Both halves of that matter. Costs escalate because nobody modelled token intensity. Value is unclear because nobody attributed the spend to an outcome. Risk controls are inadequate because the capability arrived inside something already approved.
The discipline has noticed. The FinOps Foundation’s State of FinOps 2026 names FinOps for AI as the top forward-looking priority, with 98% of respondents now managing AI spend — up from 31% two years earlier. The most requested tooling capability in that survey is granular monitoring of AI spend: tokens, model requests and GPU utilisation.
You cannot prove return on spend you cannot see, attribute or forecast.
The failure mode is fragmentation — four functions each holding one piece of an asset none of them can see whole. The fix is to assemble the whole thing into a single view and act on it.
That is what CerteroX does, and these are the parts that ship today:
The sequence is simple: discover, then attribute, then govern. Discovery without attribution is a list with no decision rights. Attribution without governance is a report nobody acts on. You need all three, connected.
The invisible layer is not going to shrink. AI spending is forecast to climb 47% this year, AI-category usage inside existing SaaS portfolios is growing faster than that, and 40% of your applications will carry task-specific agents by the end of the year. Left unmanaged, that is a renewal shock with no owner and no off-ramp.
Make it visible. Connect every AI capability to its owner, its cost, its entitlement and its risk. Turn runaway AI spend from a surprise on a renewal into a line item you manage on purpose.
That is the whole job, and it starts with seeing what you own.
Other posts covering the same ground.
Five numbers on SaaS waste — unused licences, portfolio sprawl, dollars burned, AI spend growth and cloud waste — and why visibility alone never fixes any of them.
FinOps began as a reaction to engineers being able to spend money faster than finance could see it. Here is how it got from there to a formal discipline that now covers SaaS, licensing and AI as well as cloud.
What a SaaS management platform has to do in 2026, how the market divides, and the six criteria to score your shortlist against — including where Shadow AI detection now sits as a first-class requirement rather than a tag.
Everything argued above is checkable. Name the publisher, the billing account or the platform you would argue with, and the session is built around it — the reasoning attached, not a summary slide.
No gated download at the end of it.