Blog 6 Questions Every IT Procurement Leader Should Be Asking About Shadow AI Aug 18, 2026AI Share This Article Subscribe For Updates Uncover negotiation leverage and unlock savings across your IT spend. For years, the conversation about Shadow IT was fairly straightforward: employees found a piece of software they wanted, signed up without going through the normal approval process, and created a visibility and governance problem for IT and procurement. Shadow AI is making that problem much harder to spot. Today, AI doesn’t necessarily enter the enterprise through a rogue application or an unfamiliar supplier. It can arrive as a new feature from a vendor you’ve worked with for years. It can show up as an AI SKU added during a renewal, a consumption meter inside an existing cloud account, or an agent an employee builds on an approved platform. In many cases, there’s no new supplier, purchase order or sourcing event to alert procurement that something has changed. That changes what IT procurement teams need to look for and, just as importantly, how they manage AI spend. What Is Shadow AI? Shadow AI is the use or deployment of AI capabilities without adequate visibility, commercial oversight or governance. The important word here is capabilities. An enterprise may have approved a vendor or platform without fully understanding every AI capability being activated or created within it. There are two primary paths. The first is vendor-driven AI, where an approved application introduces a new AI feature, pricing meter or commercial model. The second is employee-built AI, where employees use approved platforms to create agents, applications and automations of their own. The entry points are different, but both can leave procurement without a clear view of ownership, permissions, data use, pricing, monitoring and business outcomes. That’s why Shadow AI is, first and foremost, an inventory problem. Why Traditional Procurement Controls Can Miss AI Spend Most procurement processes are designed around recognizable commercial events. A business unit wants new software. A vendor needs to be onboarded. Someone submits a purchase request. A contract comes up for renewal. AI increasingly bypasses those triggers. In our recent webinar, Welcome to the Era of Shadow AI: What Can Procurement Do About It?, we identified five common entry points: embedded AI within existing SaaS applications, AI SKUs and credits introduced during renewals, model and agent services consumed through cloud accounts, APIs purchased by engineering teams, and employee-built agents created on approved platforms. The common thread is that the vendor may be visible while the AI capability is not. That creates a new challenge for procurement. You can have an approved supplier, negotiated contract and established purchasing process and still lack a complete picture of how AI is being used and what it is costing. AI Pricing Makes the Visibility Problem More Expensive AI also introduces a growing number of ways to charge. Depending on the supplier and product, enterprises may encounter per-user licenses, tokens, credits, actions, conversations, premium editions, add-ons and other consumption measures. Several of those meters can exist within the same supplier relationship. Salesforce Agentforce offers a useful example. Its commercial models have included $2-per-conversation pricing, Flex Credits priced per action, and per-user licenses and add-on editions. Meanwhile, Salesforce increased pricing for some broader editions, citing additional value from AI capabilities. For procurement teams accustomed to benchmarking seats and subscription rates, the job now includes understanding the meter itself. What generates consumption? Who can generate it? How quickly can usage grow? Where does it appear on the invoice? Can the organization forecast it? What happens when the vendor changes the commercial model? Those questions need answers before usage scales. Procurement Has More Leverage Than It May Think The fact that AI features are arriving through existing suppliers doesn’t mean enterprise customers have to accept every change on the vendor’s terms. A complete veto over a SaaS provider’s product roadmap is unlikely, but there are more practical protections that procurement teams are successfully negotiating. NPI has seen enterprise customers negotiate no-training provisions for customer data, prior written consent requirements for vendor use of generative AI, and notify-and-explain provisions covering new AI features or changes. Supporting protections can include audit rights, AI price caps, exit rights and termination rights for material changes. One particularly useful approach is requiring vendors to provide advance notice to designated customer contacts when they introduce a new AI feature, change an underlying model, alter how customer data is handled or change the associated fees. Procurement can also push for new AI capabilities to remain off and incur no fees until the customer chooses to activate them. That gives sourcing teams something they badly need in the AI market: time to evaluate a change before it becomes the new normal. Employee-Built Agents Create Another Procurement Blind Spot Vendor-driven AI is only half of the issue. Employees can now build apps, agents, copilots and skills in a matter of hours. These tools may read data, write to systems, send information, trigger workflows or even approve actions. An organization can approve the platform used to create an agent without ever reviewing the individual agent itself. For procurement, the relevant question is expanding from “Which AI tools are employees using?” to “Which AI capabilities and agents can access our systems, data and business processes?” An enterprise AI agent registry can help close that gap by documenting the owner, approved data sources, permissions, security testing, usage monitoring, recertification requirements and a kill switch for each agent. The goal shouldn’t be to count how many agents the company has deployed. A better measure is whether those agents are part of governed workflows tied to defined business outcomes, with clear decision rights and human approval where it matters. The webinar illustrates this with a procurement workflow spanning spend intelligence, sourcing, risk and contract agents, followed by a human decision gate and measurement of business outcomes. Procurement Needs Visibility Across the Entire AI Supply Chain There’s another reason supplier-level visibility is no longer enough: the company named on the contract may represent only one layer of the AI service. Behind that vendor can sit model providers, cloud infrastructure, data and retrieval services, orchestration layers, monitoring tools and other dependencies. Each can affect cost, data handling and commercial risk. Procurement therefore needs to understand the full AI supply chain: vendor of record, underlying model providers, cloud infrastructure, data paths and retention, pricing meters, change-notice rights, and exit and portability provisions. If an underlying provider changes its pricing, terms or availability, the cost of an AI application can change even though your organization hasn’t signed a new agreement. 6 Questions IT Procurement Leaders Should Be Asking About Shadow AI A useful test is surprisingly simple: If one of your vendors tripled your AI bill next quarter, would you know before the invoice arrived? If the answer isn’t an immediate yes, start with these questions: 1. How many vendors are charging us for AI? Include embedded AI, add-ons, cloud services, APIs, departmental purchases and expense channels. 2. Where is our AI spend occurring today? Break it down by vendor, business unit, deployment path and purchasing channel. 3. Which costs are consumption-based? Identify whether you’re paying by tokens, credits, actions, conversations or another measure. 4. Where are we paying for overlapping capabilities? Map what your assistants and agents actually do rather than looking only at vendor names. 5. Who owns each AI cost and business outcome? Every meaningful deployment should have both a business owner and a commercial owner. 6. Can we forecast AI spend with confidence? Build forecasts around rates, usage and adoption, and establish thresholds that trigger review when actual consumption moves outside expectations. These questions move the AI conversation away from a generic inventory of vendors and toward the information procurement actually needs to govern spend. What Should IT Procurement Do About Shadow AI Right Now? Procurement shouldn’t try to solve Shadow AI alone. Finance and FinOps can help with allocation and forecasting; IT with architecture and inventory; security and privacy teams with risk controls; legal with enforceable terms; and engineering with optimization and business outcomes. Commercial governance, however, is squarely within procurement’s wheelhouse. That means maintaining an AI inventory by vendor, capability, owner and deployment path; normalizing different pricing meters; identifying capability overlap; creating renewal triggers when AI SKUs, models, meters or terms change; negotiating stronger contractual protections; benchmarking pricing and terms; and working with FinOps to establish budgets, thresholds and anomaly alerts. For teams wondering where to begin, NPI recommends four priorities for this quarter: build the AI inventory, instrument upcoming renewals with AI-specific questions and approval triggers, establish baseline unit economics, and begin a recurring cross-functional review of AI spend and anomalies. The bigger change is moving away from treating Shadow AI as something you audit periodically. AI products, usage and pricing can change too quickly for a once-a-year exercise. Procurement needs an ongoing view of what is being used, what it costs, what changed and where intervention may be required. How NPI Helps Enterprises Get Control of AI Spend Getting visibility into Shadow AI is only part of the job. Procurement also needs a way to turn that visibility into better buying decisions, stronger agreements and ongoing cost control. NPI helps enterprises do that in two ways. AI Agreement Optimization is designed for organizations approaching a specific AI purchase or renewal, combining consumption analysis, forecasting, pricing benchmarks, contract intelligence and negotiation support to help clients buy the right amount of AI at the right price and terms. NPI’s AI FinOps Managed Service provides ongoing analysis across an organization’s AI vendors, including consumption trends by vendor and business unit, optimization recommendations, invoice validation, renewal support and benchmarking against peer organizations. Together, these services help procurement teams move from trying to piece together where AI spend is coming from to having the intelligence and ongoing oversight needed to manage it as it grows. Watch: Welcome to the Era of Shadow AI Shadow AI is already inside most enterprises, and the challenge now is finding it early enough to govern the commercial impact. In our webinar, Welcome to the Era of Shadow AI: What Can Procurement Do About It?, we dig deeper into how AI is bypassing traditional procurement controls, where hidden spend and risk are emerging, what contractual protections enterprise customers are successfully negotiating, and how procurement can build a more effective operating model for AI governance. If you’re responsible for IT sourcing, software renewals, AI agreements or technology spend, it’s worth watching. Share This Article Subscribe For Updates Uncover negotiation leverage and unlock savings across your IT spend.