Skip to main content

    How to Estimate What Shadow AI Costs Your Organization

    Shadow AI costs money before it causes an incident. Here is where that spend hides, how to estimate it without guessing, and how to put it under a budget.

    The short version

    How do I estimate what shadow AI costs?

    Add up three things: AI subscriptions expensed outside procurement, API keys on team or personal cards, and coding assistant usage. Expense exports cover the first two. For coding tools, Behest Radar shows, with permission, token counts for Claude Code, Codex CLI, and Claude Cowork, and list-price cost for Claude models.

    New to the term? Read the definition of shadow AI spend.

    Where shadow AI spend hides

    It rarely shows up as one line item. It is spread across four places, each owned by someone different.

    • Subscriptions on expense reports

      Individual and team AI subscriptions bought on a card and claimed as software. Each one is small, so nobody adds them up.

    • API keys outside central billing

      Provider API keys on a team or personal card, often created for a prototype that quietly became a production feature.

    • Coding assistants and agents

      Seats a team bought on its own, plus usage-based agents that bill by the token and grow with how much developers lean on them.

    • AI add-ons inside SaaS apps

      Paid AI features switched on inside tools you already license, billed on the vendor's invoice rather than as AI spend.

    How to estimate it in five steps

    1. 1

      Export expense and card data

      Pull the last few months of expense claims and card transactions and filter by AI vendor names. This catches most subscriptions and many API bills.

    2. 2

      Collect invoices billed outside central IT

      Ask finance for provider and AI tool invoices paid by individual teams. Usage-based bills belong in the estimate even when a team budget covered them.

    3. 3

      Compare paid seats with active users

      Use each vendor's admin dashboard to compare the seats you pay for with the people who use them. Idle seats are spend you can reclaim today.

    4. 4

      Measure coding assistant usage on the machine

      With permission, Behest Radar reads exact token counts from the local records of Claude Code, Codex CLI, and Claude Cowork, and estimates list-price cost for Claude models. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost. For a developer on a subscription, the cost figure is a list-price equivalent, not the bill.

    5. 5

      Report a range, not a point

      The low end is what invoices and card records prove. The high end adds estimated usage you found but cannot yet match to a bill. Run the AI cost exposure calculator for a forward-looking view.

    Want a quick forward-looking number? Try the AI cost exposure calculator. To see which AI services a machine reaches, start with Behest Radar, a free download.

    Subscriptions versus usage: read the estimate correctly

    A flat subscription and metered API usage are billed differently, so the same work can cost very different amounts. When a tool reports tokens, pricing them at the provider's list rate gives a list-price equivalent: what that usage would cost if it ran on metered API keys.

    That number is useful for two decisions. It shows which people and projects use AI most heavily, and it tells you what moving a workload from a subscription to a governed API path would cost. It is not the bill, so keep invoices as the record of what you actually paid.

    From an estimate to a budget

    An estimate tells you the size of the problem. A budget is what keeps it from coming back. Give people a sanctioned path that is easier than the workaround, then route that AI through Behest, the control plane for enterprise AI.

    AI Token FinOps, its cost-control layer, attributes every call to a user, team, and project, and enforces budgets before the provider invoice arrives. From there you can set token budgets and charge costs back to the teams that spend them. For the whole picture, from discovery to control, see the shadow AI discovery overview.

    Frequently asked questions

    What counts as shadow AI spend?
    Any spend on AI tools, models, or API usage that happens outside procurement and budget ownership: subscriptions on expense reports, API keys on team or personal cards, coding assistant seats a team bought on its own, and paid AI add-ons switched on inside SaaS apps. It is spend with no owner, no budget, and no forecast.
    Why is shadow AI spend hard to see?
    It arrives in small amounts spread across expense reports, cards, and vendor invoices, and usage-based tools such as coding agents bill by tokens, which grow with how much people use them. No single report adds it up, so nobody sees the total until someone goes looking.
    Is Behest Radar's cost figure what we actually pay?
    Not necessarily. Radar estimates list-price cost for Claude models only, from the tools' local records. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost. If a developer is on a subscription, the figure is a list-price equivalent, not the bill. Use it to size usage and compare options, and use invoices for what you actually paid.
    How do I keep shadow AI spend from coming back?
    Give people a sanctioned path that is easier than the workaround, then put AI calls under budgets. In Behest, AI Token FinOps, the cost-control layer of the control plane, attributes each call to a team and project and enforces budgets before the provider invoice arrives.

    Put a number on it, then put a budget on it

    Estimate your exposure in a few minutes, or see how Behest brings AI spend under budgets on your own stack.

    Behest Radar: Find the shadow AI on your machines. Free download.

    Get Radar free