
Why Are AI Spend and AI Risk the Same Problem?
AI spend and AI risk belong to different teams entirely, with finance watching the budget while IT and security watch access and controls. In practice, they're looking at the same gap from two different angles. Treating them separately is why so many organizations struggle with both at once, and why so few can point to real ROI on what they've spent.
Why Is AI Spend So Hard to Control?
AI tools rarely get adopted the way traditional software does. A team signs up for a copilot subscription, an engineer starts using a new model through an API, or a department pilots an agentic tool to speed up a workflow. Each of these looks like a small, reasonable decision on its own, and none of them go through the kind of review a new infrastructure purchase would trigger.
Recent industry research backs up what many finance and technology leaders already sense. A Harness report found that close to a quarter of enterprise AI spend delivers no real return, and most organizations can't identify who's truly responsible for that spend. That gap reflects how AI tools enter the business, through dozens of small decisions instead of a deliberate one, rather than a breakdown in forecasting.
Why Do AI Cost Gaps Create Security Risks?
Here is the part that often gets missed. A tool nobody owns financially is usually a tool that’s not being reviewed from a risk standpoint either. If finance can't say what an AI tool costs, security usually can't say what data that tool can access, what it does with that data, or whether it meets the same standards the rest of the organization's software must clear.
This is how shadow AI takes hold, through an accumulation of small, unreviewed decisions, each one adding untracked cost and untracked exposure together.
What Three Questions Should Organizations Ask Before Adopting AI?
Typically, AI adoption decisions get evaluated on a single axis, usually whichever one the person in the room cares about most. Legal asks if it's compliant. IT asks if the infrastructure can support it. The business unit asks if it'll speed things up. None of those questions are wrong, but asking only one of them is how organizations end up with tools that are compliant and unused, or fast and unmonitored.
Three questions, asked together, cover the ground that matters:
Should we do it? This is the ethics, compliance, and regulatory question. Does this tool's use of data hold up under the rules the organization already follows, and does the use case itself pass a basic ethical test?
Can we do it? This is the data infrastructure and governance question. Does the organization know where this tool's data comes from, where it goes, and who can act on it?
To what end? This is the ROI question, and it's the one most governance conversations skip entirely. What problem is this tool solving, what's the expected payback, and how will anyone know if it worked? Answering that well takes the same structured approach to measuring ROI that any analytics investment needs.
The third question is where cost and risk stop being separate conversations. A tool that can't clear "to what end" is usually the same tool finance can’t account for and security can’t see.
What Does Strong AI Governance Look Like?
Asking those three questions is one thing, but building the infrastructure to answer them is another. Real governance is what makes that possible, and it comes down to answering two things at the same time, what's this tool costing us and what's it allowed to do, rather than treating AI governance as purely a compliance exercise. OpenAI made a similar point in recent guidance to enterprise leaders, framing visibility into AI use as the foundation that everything else, cost control included, is built on. Separating those questions is exactly how organizations end up with strong security policy on paper and no insight into which tools are in use, or a tight budget process with no idea what risk it just approved alongside the spend.
A governance model built around data quality, lineage, and transparency addresses both sides by design. When an organization knows where its data goes and who can act on it, it also knows what it's paying for and why.
How Can Organizations Manage AI Governance and Spend Together?
Ownership sits with one person who's accountable for AI decisions end to end, cost and risk both.
New AI tools go through a single review that runs through all three questions and covers cost, data access, and security posture in that same pass.
Visibility gets built in from the start, with tools, spend, and expected ROI tracked together as they're adopted.
Governance functions as infrastructure, shaping how AI gets adopted rather than just how it's audited afterward.
Why Should AI Governance and Cost Control Be Managed as One Effort?
The organizations getting this right build one process for cost and risk instead of two. Asking should we, can we, and to what end on every tool they adopt is what makes that possible, and it's what turns AI governance from a policy on paper into measurable ROI. Reach out today to talk through what a unified approach to AI cost and AI governance, backed by real ROI, could look like for your organization.




