How to Estimate What Shadow AI Costs Your Organization
Shadow AI costs money before it causes an incident. Here is where that spend hides, how to estimate it without guessing, and how to put it under a budget.
The short version
How do I estimate what shadow AI costs?
Add up three things: AI subscriptions expensed outside procurement, API keys on team or personal cards, and coding assistant usage. Expense exports cover the first two. For coding tools, Behest Radar shows, with permission, token counts for Claude Code, Codex CLI, and Claude Cowork, and list-price cost for Claude models.
New to the term? Read the definition of shadow AI spend.
Where shadow AI spend hides
It rarely shows up as one line item. It is spread across four places, each owned by someone different.
Subscriptions on expense reports
Individual and team AI subscriptions bought on a card and claimed as software. Each one is small, so nobody adds them up.
API keys outside central billing
Provider API keys on a team or personal card, often created for a prototype that quietly became a production feature.
Coding assistants and agents
Seats a team bought on its own, plus usage-based agents that bill by the token and grow with how much developers lean on them.
AI add-ons inside SaaS apps
Paid AI features switched on inside tools you already license, billed on the vendor's invoice rather than as AI spend.
How to estimate it in five steps
- 1
Export expense and card data
Pull the last few months of expense claims and card transactions and filter by AI vendor names. This catches most subscriptions and many API bills.
- 2
Collect invoices billed outside central IT
Ask finance for provider and AI tool invoices paid by individual teams. Usage-based bills belong in the estimate even when a team budget covered them.
- 3
Compare paid seats with active users
Use each vendor's admin dashboard to compare the seats you pay for with the people who use them. Idle seats are spend you can reclaim today.
- 4
Measure coding assistant usage on the machine
With permission, Behest Radar reads exact token counts from the local records of Claude Code, Codex CLI, and Claude Cowork, and estimates list-price cost for Claude models. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost. For a developer on a subscription, the cost figure is a list-price equivalent, not the bill.
- 5
Report a range, not a point
The low end is what invoices and card records prove. The high end adds estimated usage you found but cannot yet match to a bill. Run the AI cost exposure calculator for a forward-looking view.
Want a quick forward-looking number? Try the AI cost exposure calculator. To see which AI services a machine reaches, start with Behest Radar, a free download.
Subscriptions versus usage: read the estimate correctly
A flat subscription and metered API usage are billed differently, so the same work can cost very different amounts. When a tool reports tokens, pricing them at the provider's list rate gives a list-price equivalent: what that usage would cost if it ran on metered API keys.
That number is useful for two decisions. It shows which people and projects use AI most heavily, and it tells you what moving a workload from a subscription to a governed API path would cost. It is not the bill, so keep invoices as the record of what you actually paid.
From an estimate to a budget
An estimate tells you the size of the problem. A budget is what keeps it from coming back. Give people a sanctioned path that is easier than the workaround, then route that AI through Behest, the control plane for enterprise AI.
AI Token FinOps, its cost-control layer, attributes every call to a user, team, and project, and enforces budgets before the provider invoice arrives. From there you can set token budgets and charge costs back to the teams that spend them. For the whole picture, from discovery to control, see the shadow AI discovery overview.
Frequently asked questions
- What counts as shadow AI spend?
- Any spend on AI tools, models, or API usage that happens outside procurement and budget ownership: subscriptions on expense reports, API keys on team or personal cards, coding assistant seats a team bought on its own, and paid AI add-ons switched on inside SaaS apps. It is spend with no owner, no budget, and no forecast.
- Why is shadow AI spend hard to see?
- It arrives in small amounts spread across expense reports, cards, and vendor invoices, and usage-based tools such as coding agents bill by tokens, which grow with how much people use them. No single report adds it up, so nobody sees the total until someone goes looking.
- Is Behest Radar's cost figure what we actually pay?
- Not necessarily. Radar estimates list-price cost for Claude models only, from the tools' local records. Codex usage shows tokens but no cost; other tools show model and tokens only with the optional certificate, and no cost. If a developer is on a subscription, the figure is a list-price equivalent, not the bill. Use it to size usage and compare options, and use invoices for what you actually paid.
- How do I keep shadow AI spend from coming back?
- Give people a sanctioned path that is easier than the workaround, then put AI calls under budgets. In Behest, AI Token FinOps, the cost-control layer of the control plane, attributes each call to a team and project and enforces budgets before the provider invoice arrives.
Put a number on it, then put a budget on it
Estimate your exposure in a few minutes, or see how Behest brings AI spend under budgets on your own stack.