Skip to content
Home  /  Insights  /  Report
Report

How Much of Your Technology Estate Can You Account For?

About half of provisioned licenses go unused, roughly a third of applications never passed through IT, and regular AI use on corporate devices tripled in a single year. Most organizations cannot answer the question, and the gap between what they own and what they can account for is where the waste and the AI exposure both sit.

By G2 ConnectionsAugust 20267 min read
47%
Large organizations without full visibility into the AI tools their employees use, per Protiviti
~51%
Share of provisioned SaaS licenses that go unused, with waste up 14% year over year
15% → 45%
Rise in regular AI use on corporate devices in a single year, per Verizon's 2026 DBIR
$670K
Additional average breach cost where shadow AI was involved, per IBM

A large share of the applications running in your organization never passed through IT. Gartner has put shadow IT at 30 to 40% of large-enterprise technology spending, a range first published in 2017 and repeatedly confirmed since, and vendor measurements place roughly a third of the average application portfolio outside central procurement.

A separate measurement compounds it. Around 37% of corporate applications sit outside single sign-on. That is not the same statistic, and the overlap is imperfect, since an application can be centrally procured and still sit outside SSO because the vendor charges extra for it. But the practical effect is the same in both cases: the systems IT relies on to know what it owns are incomplete.

That produces most of what follows. An application nobody in IT bought has no owner, no lifecycle, and no renewal date on anyone’s calendar. It does not get cancelled when the team that expensed it reorganizes, and it does not get reviewed when it starts handling customer records. Seven in ten technology leaders now report that teams across the business are deploying technology faster than IT can track it.

It is also why AI arrived in most organizations before anyone approved it.

For a decade the SaaS conversation was about how many applications were being added and how quickly. Counting is a poor proxy, and the counts themselves disagree. Zylo’s index puts the average organization at roughly 305 applications with counts essentially flat year over year, while Torii’s 2026 benchmark reports far larger estates still growing by several applications a month. The two measure different customer bases with different methods, and neither settles the question. What is not in dispute is the utilization rate and the ownership gap, which is where the money and the risk both sit.

Where the money goes now

~51%

Share of provisioned licenses that go unused, the highest waste rate recorded

Only about half of licensed users log in within a 30-day window. A further 23% of licenses show no usage at all.

+14%

Year-over-year growth in spend on licenses nobody opens

Reported dollar averages run to $21M per company, but that figure is pulled upward by very large enterprises and is a poor benchmark for a mid-market estate. The rate travels better than the average.

30–40%

Gartner’s estimate of shadow IT as a share of IT spending in large enterprises

First published in 2017 and repeated since rather than re-measured. Zylo puts more than a third of applications outside IT procurement; Productiv has measured it higher.

17%

Average recovery achieved by organizations running an active renewal management program

The savings sit in the renewal calendar rather than in new negotiations.

The pattern is consistent. Sprawl matured from an acquisition problem into a cost and governance problem. Organizations stopped adding tools at the old rate and never went back to reconcile what they had already bought.

Portfolio size has flattened. The waste, the per-employee spend and the AI line item have not.

Shadow IT did not go away. It changed shape.

The original version of this problem was a marketing team expensing a project management tool on a corporate card. That still happens. What has changed is the security profile of what comes in that way.

Where applications are expensed by employees rather than procured centrally, a majority score poorly on security risk assessment, for the simple reason that nobody performed one. The categories have changed since the shadow IT problem was first measured, but the proportion has not moved much, and it now includes AI-native tools bought on free trials that convert quietly to paid subscriptions.

Shadow IT is an asset management problem before it is a security problem. An application deployed outside IT’s view has no lifecycle, no cost owner and no security record. Every consequence downstream follows from that.

Shadow AI is the same problem with a larger blast radius

The distinction matters. A shadow SaaS application stores your data. A shadow AI tool processes it, may retain it, and in some configurations acts on it.

Verizon’s 2026 Data Breach Investigations Report found regular AI use on corporate devices rose from 15% to 45% in a single year, with shadow AI detections up fourfold and unsanctioned AI use now the third most common non-malicious insider action in breach data. Around two-thirds of that access happens through personal accounts the enterprise cannot see or control.

The behavioral research is blunter. A 2026 PagerDuty survey of office professionals at companies above $500 million in revenue found that 66% had used AI tools at work while believing it was against company policy, and more than a third had entered customer data into public AI models. Source code and intellectual property are the most commonly uploaded data categories. IBM puts the additional cost of a breach involving shadow AI at roughly $670,000.

The visibility gap

Protiviti’s AI Pulse Survey, fielded in February 2026 across roughly 345 C-suite executives, board members and IT leaders, found that 47% of large organizations lack full visibility into the AI tools their employees use. Grant Thornton’s 2026 AI Impact Survey found that 78% of executives lack strong confidence they could pass an independent AI governance audit within 90 days.

Separately, an Okta-commissioned study of 292 executives and 492 knowledge workers across seven countries found a consistent disconnect between how leaders believe AI is being used and what employees report doing.

Most leadership teams are not making a bad decision about shadow AI. They are making a confident decision from a picture that does not match what is happening on their endpoints.

Two further dynamics make this harder than shadow SaaS ever was. AI tools are largely browser-based and often accessed through personal accounts, so they leave little trace in procurement or expense data. And AI-native application spend is the fastest-growing line in the software budget, with a meaningful share of it originating in free trials that convert quietly into paid subscriptions nobody approved.

How IT leadership is managing it

The organizations making progress have converged on a similar sequence. None of it depends on buying another dashboard first.

  1. Discover from financial data, not from the identity systemStart with expense reports, corporate card statements and accounts payable rather than SSO logs. The applications that matter most are precisely the ones missing from your identity provider.
  2. Separate unused from underusedA license with zero logins is a cancellation. A license at 20% utilization is a tier change or a reallocation. Treating them the same produces either missed savings or an internal fight you did not need.
  3. Put the renewal calendar under managementRenewal dates and notice windows held as structured data, with an owner and a trigger date. This is where the recoverable money reliably sits, and auto-renewal is what removes the leverage.
  4. Give AI a sanctioned path before restricting the unsanctioned oneBlocking without providing an approved alternative moves usage to personal devices, where visibility drops to zero. Organizations that provided approved tools saw unauthorized use fall materially. Access to AI now also affects hiring and retention.
  5. Set data classification rules that name specific categoriesA policy stating that customer records, source code, financial projections and regulated personal data must not be entered into unapproved tools is enforceable. A policy saying to use AI responsibly is not.
  6. Monitor at the endpoint and browserBecause unsanctioned AI use runs through personal accounts in the browser, network-level and procurement-level controls miss it. Detection has to sit where the behavior actually happens.
  7. Assign an owner to every application and agentIncluding AI agents with credentials into production systems, which increasingly act autonomously and are frequently governed by nobody.

What this means for buyers

The vendor market has reorganized around these problems, and it is crowded. Four categories overlap heavily and are sold as though they are interchangeable:

  • SaaS management platforms
  • IT asset management tools
  • Security posture management for SaaS
  • AI governance products

They are not interchangeable, and most organizations do not need all four. The determining factor is where your exposure actually sits. An organization with a stable portfolio and 51% license waste has a renewal and utilization problem, which is a different purchase from an organization whose main exposure is regulated data moving into consumer AI tools. Buying the wrong category is expensive, and it leaves the real gap open while the budget is spent.

How G2C approaches it

We start with the financial record rather than the tool inventory, because that is where shadow purchasing is visible. We establish what you are spending across SaaS, cloud and AI-native applications, identify what is unused, underused and duplicated, and map which applications sit outside your identity and security controls.

From there we help you decide whether the answer is consolidation, a management platform, a governance program or some combination, and we evaluate the options across our provider network. We do not license a SaaS management platform of our own, which means we have no reason to tell you that you need one.

Sources

  1. Zylo SaaS Management Index and Torii SaaS Benchmark Report 2026, portfolio size, license utilization, waste and renewal recovery figures. The two report materially different portfolio sizes and growth rates, reflecting different customer bases and measurement methods.
  2. Verizon Data Breach Investigations Report 2026, AI use on corporate devices, shadow AI detection rates and insider action ranking.
  3. PagerDuty Shadow AI Survey 2026, conducted by Wakefield Research among office professionals at companies above $500M revenue.
  4. IBM Cost of a Data Breach Report, incremental breach cost associated with shadow AI.
  5. Gartner shadow IT spending estimate for large enterprises, originally published 2017 and widely cited since.
  6. Protiviti AI Pulse Survey, “No Visibility, No Confidence,” fielded February 2026, approximately 345 respondents.
  7. Grant Thornton 2026 AI Impact Survey, executive confidence in AI governance audit readiness.
  8. AI Agents at Work 2026, commissioned by Okta and conducted by Apprize360, March 2026, 292 executives and 492 knowledge workers across seven countries.
  9. BetterCloud SaaS statistics, single sign-on coverage and technology deployment pace.
  10. Flexera State of ITAM, underutilized and redundant license spend.
  11. Figures drawn from vendor benchmark studies reflect the customer bases of the vendors publishing them and vary by measurement method.

Find out what is running, and who is paying for it.

A SaaS and AI spend review works from your financial records to establish what you actually own, what nobody uses, and which applications and AI tools are operating outside your security controls.

Schedule a SaaS Review
Get Started

Let's find your right solution.

Ready to make a confident technology decision? Tell us about your challenge and we'll be in touch within one business day.

Free, no-obligation consultation. We’ll respond within one business day.