We Defunded the Road, Then Blamed People for the Detour

cloud-vs-ai-spending-dark

In May I wrote about the AI stack problem nobody planned for — six platforms running at once, no rationalization, governance showing up after the fact. That post named the condition. It didn’t explain how we paid for it.

Two pieces ran in CIO this week that do, though I don’t think either one was trying to. Read separately they’re ordinary industry coverage. Read together they explain where shadow AI actually comes from, and it isn’t a discipline problem.

The two facts are the same fact

The first: AI governance is becoming an unmanageable chore. Four in five senior leaders are spending meaningfully more time managing AI risk, with working hours up 26% on average. Eighty-six percent have had an AI-related incident. More than a quarter have had repeated incidents of systems taking actions nobody approved. And a third say employees deployed unapproved AI tools because the approved options weren’t available fast enough.

The second: AI spending is squeezing IT modernization. Sixty-one percent of organizations have paused, delayed, scaled back, or abandoned modernization initiatives in the past twenty-four months. More than seventy-one percent say their modernization projects exceeded the original budget. Meanwhile digital transformation budgets grew from $39.4 million to $54.2 million in a single year, with most of the increase going to AI. KJ Kusch at WalkMe was clear this wasn’t scope creep: “It was a deliberate move.”

Put those side by side.

The money that would have modernized the sanctioned stack — identity, data plumbing, the internal tools people are actually issued — got redeployed into AI initiatives. The approved path got slower and older at precisely the moment the unapproved path got faster and better.

Then we wrote a policy expressing disappointment that people took the fast one.

It isn’t a line. It’s a loop. Defund modernization. The issued toolset falls behind what the work requires. Employees close the gap themselves. Unsanctioned usage climbs. Governance scrambles to retrofit controls around tools nobody evaluated. Leadership hours rise 26%, and that time is unfunded labor, drawn from the same team and the same budget that were supposed to be modernizing the stack.

We’re paying for shadow AI twice. Once in risk, and once in the foundation we didn’t build.

Stu Bradley at SAS names the error directly: “Seeing AI and modernization as competing budget lines is a bit of a trap. They’re increasingly two sides of the same coin.”

We already know how this ends. I was there for it.

The new it sprawl is ai sprawl

I was at Elastica when this was the entire business.

CASB was brand new. Gartner had just named the category, ranked it the number one security technology to focus on that year, and projected the market would go from roughly nothing to $590 million inside three years. The money moved accordingly. Within about a year we were acquired by Blue Coat, and Blue Coat was acquired by Symantec. Three badges in twelve months.

Our job was walking into an enterprise and telling them what was already running on their network.

The second slide of every deck asked the same question: How many apps do you think your employees are using?

IT’s answer was consistently 40 to 50.

Our Q4 2015 Shadow Data Report put the real number at 812.

I ran a lot of those assessments, and the shape never changed. Thousands of cloud services inside a single enterprise. Dozens of file-sharing apps where IT believed there was one. Dozens of web-based email services, a third of them scoring high risk.

And it wasn’t cat pictures. A 2014 analysis we ran across a hundred million files found that about twenty percent of them contained protected or regulated data — nearly sixty percent of that personally identifiable information, around thirty percent protected health data, the rest payment card information.

Then the number that still bothers me: sixty-eight percent of the files holding sensitive data had been shared with the entire company. Not leaked. Not stolen. Shared, by someone doing their job, using a permission model that no longer ran through IT.

Nobody ever argued with the number. What happened instead was that somebody in the room would start going down the list, explaining. This team needed to send large files to a client and the file share capped out. That group was collaborating with an agency that wasn’t on our domain. Finance had a thing that just worked.

Every one of those explanations was a requirement. Nobody heard them that way. They heard violations.

The first instinct was always to block. It failed every time. The file still had to reach the client, so it left through a personal account instead, same data, now with no logging and no visibility. We took a problem we could see and made it invisible, then called it solved because the dashboard went quiet.

What worked was inverting the order. Discover first. Sanction a fast path for the common case. Apply policy where the data actually moves.

I don’t think we ever got a single customer to read those reports the way I’d read them now. They were never a security finding. They were the most honest requirements document that organization had ever produced, written by the people who hadn’t been invited to the planning meeting.

The number that made the room go quiet

There was another slide near the front of those decks, and it had nothing to do with anyone’s network. It was Gartner’s 2014 public cloud forecast: over the next five years, enterprises would spend $1.1 trillion on public cloud services.

That number did work in a room. You didn’t have to argue that cloud was real after people saw it. It reframed the conversation from should we to how fast.

Here’s where we are now.

Public cloud end-user spending was roughly $723 billion in 2025 — in one year, not five.

Worldwide AI spending in 2026 is forecast at $2.7 trillion, up 49.5% from $1.79 trillion the year before. AI infrastructure alone accounts for about $1.48 trillion of it.

Set that against the 2014 slide. The infrastructure line item, for a single year, is now larger than the entire five-year forecast for all of public cloud that made a room full of executives go quiet.

Gartner’s John-David Lovelock describes the AI data center buildout as the largest infrastructure project humanity has ever undertaken. Having watched the last buildout from the vendor side, I believe him.

And that is what makes the budget decision so strange. We are spending at that scale while 61% of organizations have paused or scaled back the modernization work underneath it, and while fewer than one in five have data infrastructure ready for what they’re putting on top of it.

We didn’t just defund the road. We defunded it in the middle of the largest construction project in history.

What makes shadow AI harder this time

In the CASB era, the gap between issued tools and needed tools came from procurement inertia. Slow, frustrating, nobody’s fault exactly. Nobody sat in a room and chose it.

This time we chose it. Deliberately, as a funding decision, in a budget meeting, with a slide.

And three things make this version harder to catch than the last one.

You can fingerprint a file. You cannot fingerprint a paragraph typed into a box. The sensitive thing isn’t a document leaving the building anymore.

The tool you evaluated in March is not the tool running in September. As Blake Brannon at OneTrust put it, “Whatever AI they were using at the beginning of the year, it’s probably more than 2x.”

And a file share holds your data. An agent acts on it. We never had to govern a tool that could take initiative.

What transfers

Discover before you block. You cannot govern what you haven’t counted, and the count is always higher than the estimate. Read the inventory as requirements, not as a list of offenders.

Make the sanctioned path faster than the workaround. A third of unapproved deployments trace directly to approved options being too slow. That is a procurement SLA problem wearing a security costume.

Publish a yes. Most AI policies are a list of nos with no accompanying yes. If there’s no sanctioned way to do the obvious thing everyone needs to do, the policy isn’t a control. It’s a suggestion with a legal department attached.

Stop treating modernization and AI as competing lines. That 26% of leadership time going to AI cleanup ismodernization work — reclassified as an emergency and moved off the books. Budget it as foundation or keep paying it as overtime. You’re paying either way.

The line that stuck with me

Governance ends up scrambling to put controls around something that was never properly evaluated.

The evaluation didn’t happen because nobody asked the people already using it. They were right there. They’d run the pilot for you, on their own time, and found the edges — and we’d already classified them as the problem.

They weren’t going around governance. They were doing the integration work the organization stopped funding.

Be Human First.

Sources:
CIO, AI governance is fast becoming an unmanageable chore: https://www.cio.com/article/4225293/ai-governance-is-fast-becoming-an-unmanageable-chore.html

CIO, AI spending puts the squeeze on IT modernization, risking ROI: https://www.cio.com/article/4225165/ai-spending-puts-the-squeeze-on-it-modernization-risking-roi.html

Gartner, worldwide AI spending forecast, 16 Sept 2026: https://www.gartner.com/en/newsroom/press-releases/2026-09-16-gartner-forecasts-worldwide-ai-spending-to-grow-49-point-5-percent-in-2026

Gartner, public cloud end-user spending 2025: https://www.gartner.com/en/newsroom/press-releases/2024-11-19-gartner-forecasts-worldwide-public-cloud-end-user-spending-to-total-723-billion-dollars-in-2025

Gartner 2014 forecast: “Forecast: Public Cloud Services, Worldwide, 2012–2018, 2Q14 Update” (G00263154) — cite by document ID, from your own deck

Leave a Comment

You must be logged in to post a comment.