Andrius Buinovskis is Head of Product at NordLayer, a toggle-ready network security platform for business.
AI is increasingly associated with efficiency and scale, prompting more organizations to formalize strategies for adoption. However, beneath the rollout of this technology lies a significant instrumentation gap. Without a unified view of both sanctioned and shadow AI usage, any calculation of return on investment (ROI) is less of a metric and more of a blind bet.
Writer’s 2026 AI Adoption in the Enterprise survey reveals that 59% of companies are investing over $1 million annually in AI technology. Despite the large investments, only 29% of respondents report seeing significant ROI from generative AI.
According to a report from the University of Melbourne, 70% of employees use free, publicly available AI solutions at work, while only 42% use tools provided by their employer. The data points to a worrying reality: A substantial share of workplace AI usage is happening outside official oversight.
The Denominator Problem
Calculating AI ROI requires comprehensive telemetry—everything from token spend to cost per output. But even the most detailed dashboards from enterprise LLM solutions provide only a partial view; shadow AI remains the invisible denominator that makes any claim of objective ROI little more than a blind bet.
ROI depends on two basic variables—total investment and measurable return. Shadow AI distorts both. If employees are using AI tools outside of the approved and monitored solutions, organizations have no visibility into actual usage volume and token consumption. Consequently, teams are calculating ROI against the approved costs alone, while a significant share of AI-driven productivity (and risk) sits in the shadows.
This scenario can result in a flawed equation. Companies might falsely conclude that a licensed enterprise tool is underperforming and that AI adoption at the organization is low based on dashboards alone. In reality, employees may be relying heavily on public LLMs for daily tasks, while organizations remain unable to measure or manage that adoption.
The ROI math is further complicated by potential wasted spend. Organizations may invest large sums into licensed AI tools, while employees bypass them in favor of unsanctioned solutions. Corporate AI exploitation is even harder to track. Without visibility into LLM use, organizations can’t be certain that the tools they’ve purchased are being used for business purposes rather than personal projects.
The Forgotten Variable: Risk
Apart from the challenges in measuring value and overall AI adoption in the company, unsanctioned AI use also introduces another crucial layer in calculating ROI: the potential for catastrophic costs stemming from security vulnerabilities.
A report by IBM found that the global average cost of a data breach in 2025 was $4.4 million. The report found that unsanctioned AI security incidents were more common than sanctioned AI security incidents and often cost more. According to the report, these types of incidents contribute an additional $200,000 to the global average breach cost.
The leading security risk posed by unauthorized AI use is data exfiltration. Employees can paste confidential corporate data, personal identifying information, credentials or API keys in a publicly available model, which could eventually become part of a public LLM’s training set and surface for other users. If the data pasted in the model is regulated, this can also result in compliance violations, which can ultimately result in huge financial and reputational losses.
Establishing A Unified AI Control Plane
Closing the AI visibility gap requires a technical shift toward AI observability. To move from a blind bet to a managed strategy, organizations should focus on two main priorities:
1. Discovery
The first step is to map AI use across the company and identify shadow AI. Observability into what shadow AI is actually being utilized in the company equips security teams with the specific telemetry needed to prioritize threat detection. It also illuminates the hidden consumption data required for an objective ROI calculation.
2. Consolidation
The final step is to unify all of the established telemetry into a single control plane. This step requires centralizing data from sanctioned LLM solutions and shadow AI discovery tools into a single “pane of glass.” By unifying visibility, organizations gain a clearer picture of total AI adoption, consumption and risk exposure. In turn, leadership can benchmark AI’s full cost more accurately against real-world outputs, turning raw usage data into a more objective foundation for ROI.
Conclusion
For many organizations, AI ROI remains more of a gamble than a measurable outcome. Shadow AI distorts the equation by obscuring actual usage, consumption and risk exposure, leaving leaders to assess value based on only part of the picture. Until organizations can identify unauthorized AI use and consolidate that telemetry into a unified view, any claim of objective ROI will remain incomplete.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?


