This Week In WorkTWIW

Is shadow AI the real risk behind the Ramp numbers?

Paid spend understates workplace AI. Free tools and personal accounts sit outside the ledger — which is exactly where governance usually fails.

RiskShadow AIGovernance

Ramp’s economists do something rare: they admit their own undercount. The AI Index methodology notes that free tools and employees using personal accounts mean observed paid adoption underestimates real workplace use. That sentence is not a footnote. It is the risk thesis.

Finance sees Anthropic and OpenAI dominating token spend — about 95% of maker share in the latest week. Security sees something else: a long tail of consumer apps, browser extensions, and “just this once” pastes that never hit the corporate ledger. The gap between those two views is where operational exposure lives.

Spend without a map

When nearly all metered spend sits with two labs, boards get a comforting illusion of control — “we use the big vendors”. Meanwhile endpoint and identity studies keep finding the same pattern. Cloud Security Alliance research through 2026 puts shadow AI as a definite or probable problem for roughly three-quarters of organisations, with ownership of AI security still fragmented across CIO, CTO, CISO and business units. A large endpoint telemetry benchmark from Code Ninety reported 58.4% of employees using unsanctioned consumer AI tools and 24.1% pasting sensitive corporate data — with only 38.4% of organisations able to detect that movement with AI-aware DLP.

Treat vendor benchmarks with the usual salt. The direction is stubbornly consistent: usage outruns inventory, and policy without detection is theatre.

Operational exposure, not sci-fi

The failure mode is mundane. Source code in a free chatbot. Customer PII in a personal workspace. An agent with a production token and no owner. Ramp’s token board cannot see those. Neither can a policy PDF that nobody reads after onboarding week.

There is a second exposure layered on top of shadow use: sanctioned spend without governance. High token volume with no evaluation harness, no retention rules, and no named owner is still operational risk — just better branded. Price cuts and cheaper default models (documented in Ramp’s September letter) may even increase volume while attention drifts. Cheaper tokens are not safer tokens.

What good looks like this week

  • An AI inventory that includes personal and freemium paths, not only purchase orders.
  • Approved tools that are faster than the forbidden ones — otherwise shadow AI is a product requirement written in guilt.
  • Logging and DLP that understand prompts and uploads, not only email attachments.
  • Named owners for every high-volume API key and agent deployment.

Upbeat, still: the organisations treating shadow AI as a discovery problem rather than a lecture series are already pulling ahead. They can spend boldly on the Ramp-visible path because they are not flying blind on the invisible one. That is the adult version of “AI-first”.

Sources: Ramp methodology notes · CSA — AI security ownership · Shadow AI risk benchmarks 2026 · September 2026 letter