Companies racing to deploy artificial intelligence may be underestimating the full financial cost of the technology. Beyond model subscriptions, computing capacity and software licences, expanding AI adoption is creating new expenditure around cybersecurity, data governance, monitoring, legal risk, intellectual property and operational controls. As AI becomes embedded deeper inside corporate workflows, these costs are increasingly becoming a board-level capital allocation issue rather than something that can be managed entirely within the technology department. That was the central argument presented at Ai4 2026 in Las Vegas by Sandeep Desai, Chief Information Security Officer at the Arizona Department of Education, and Joe Vatican, founder of Atomic Zero, who examined how organisations should translate emerging AI risks into financial exposure that chief executives, chief financial officers and boards can evaluate alongside more familiar investment risks.
The shift is being driven by the speed at which AI is entering companies. Employees are adopting public AI tools, developers are incorporating coding assistants into production workflows and organisations are experimenting with increasingly autonomous agents capable of retrieving information and performing actions across several systems. Each application can potentially increase productivity, but it also expands the number of places where company information can leave controlled environments or where automated actions can create unintended consequences. One of the clearest examples is shadow AI. Employees may use personal or unapproved generative-AI accounts to summarise documents, write code, analyse financial information or process customer data because the tools save time, but confidential information may consequently enter systems over which the company has little visibility.
IBM’s 2025 Cost of a Data Breach research illustrates why that behaviour has become financially relevant. The global average cost of a data breach was approximately $4.44 million, while organisations with significant shadow-AI exposure experienced materially higher breach costs. The lesson is not necessarily that companies should prevent employees from using AI. Attempting to become an organisation that simply says no could drive activity further underground. Instead, companies increasingly need approved alternatives that employees actually want to use, together with clear policies defining what information can be processed, which systems are permitted and what activities require additional controls.
This creates a category of expenditure that can easily be missed when organisations calculate AI budgets. Buying access to a model may be relatively inexpensive compared with the infrastructure required to deploy it securely across a large enterprise. Identity management, access controls, data-loss prevention, audit logs, monitoring, model testing and incident-response capabilities all add to the total cost of ownership. AI agents make the issue more complicated because they do not simply provide information. They may potentially retrieve customer records, update software, communicate with external systems, modify documents or initiate transactions. Every additional permission therefore expands the consequences of an incorrect instruction, compromised account or manipulated input.
The financial question changes as autonomy increases. A chatbot that produces an inaccurate answer creates one level of exposure, while an agent capable of acting across company systems creates another. Boards consequently need to understand not only how much AI their organisation is using but how much authority those systems have been given. This makes inventories increasingly important. Companies should be able to identify which AI systems are operating inside the organisation, which models they rely on, what information they access, who owns them and which actions they are permitted to perform. Without that visibility, it becomes difficult to calculate either their financial benefits or the risks attached to them.
Third-party software adds another layer. Many established cloud and business applications are adding AI functionality into existing products, meaning organisations may begin using AI indirectly without buying a dedicated AI platform. Companies therefore need to understand whether suppliers use customer information to improve models, where that information is processed and whether subcontractors or external model providers become part of the data chain. Vendor management consequently becomes part of AI governance. Traditional procurement reviews concentrating mainly on functionality, price and cybersecurity may no longer be sufficient. Businesses increasingly need to know what models sit underneath an application, how prompts and outputs are retained and whether sensitive information can be reused outside the intended service.
Intellectual property is another potentially significant area of exposure. Generative AI can help employees create code, images, marketing material and documents much faster, but companies need to understand where source material originates and what rights exist over resulting outputs. Litigation surrounding the training of commercial AI models has already demonstrated that copyright and data ownership remain unsettled areas of the AI economy. This does not mean every company using generative AI automatically inherits those liabilities, but boards should recognise that AI introduces legal questions extending beyond conventional technology procurement. Organisations producing valuable intellectual property also need controls preventing employees from inadvertently transferring proprietary information into external systems.
AI spending itself can also be difficult to predict. Conventional enterprise software is often purchased through relatively stable annual licences, whereas generative AI can introduce consumption-based pricing in which expenditure rises with the number of requests, the quantity of information processed and the sophistication of the models being used. Agentic systems can intensify this effect because a single employee request may trigger several automated model calls behind the scenes. One agent may retrieve information, another analyse it, another verify the result and another perform an action. What appears to the user as a single interaction can therefore involve considerably more computing activity.
As adoption scales across thousands of employees, relatively small unit costs can become meaningful operating expenses. Finance departments therefore need better visibility into AI consumption rather than treating model usage as an unlimited resource. One response is to avoid using the most capable model for every task. Routine activities may be handled by traditional software, deterministic rules or smaller models, while more sophisticated systems are reserved for problems requiring greater reasoning capability. This makes AI architecture partly an economic decision rather than a purely technical one.
The same principle applies to security investment. Not every AI application carries equal risk. A system helping employees draft internal meeting summaries does not necessarily require the same controls as one influencing financial transactions, customer decisions or critical infrastructure. Organisations therefore need to concentrate security spending around the systems capable of causing the greatest financial or operational damage. Desai and Vatican argued that AI risk should increasingly be expressed in financial terms. Rather than presenting boards with technical vulnerability scores, companies can estimate the likelihood of an event, the potential impact and the degree to which existing controls reduce that exposure.
The numbers cannot provide perfect predictions, but they can create a common language between cybersecurity teams and financial decision-makers. Companies can begin by identifying which AI-enabled processes affect the greatest amount of economic value. A customer-service assistant handling routine enquiries creates a different exposure profile from an autonomous system capable of changing prices, approving credit or modifying production environments. Management can then determine what additional controls would reduce those risks and compare the cost of those controls with the potential financial loss.
This approach also helps prevent over-regulation. Security departments can sometimes respond to emerging technology by placing restrictions around everything equally. If risk is assessed according to business impact, companies can instead apply stronger controls to high-value systems while allowing lower-risk experimentation to continue. The distinction matters because AI governance needs to enable innovation rather than simply restrict it. Employees who find approved corporate systems too cumbersome may return to consumer AI products, recreating the shadow-AI problem companies were trying to eliminate.
A balanced approach therefore requires both boundaries and accessibility. Organisations need policies defining which information may be processed, role-based permissions controlling access to sensitive systems and technical measures preventing high-risk activities. At the same time, employees need sanctioned AI tools capable of delivering enough value that they do not feel compelled to work around those controls. Existing governance weaknesses are also likely to become more visible as AI adoption expands. Companies with fragmented data estates, weak vendor oversight or inconsistent access controls already carry those vulnerabilities, and AI can amplify them because automated systems can access and process information much faster than individual employees.
In that sense, many of the hidden costs attributed to AI are not completely new. They are partly the cost of fixing longstanding weaknesses that were easier to tolerate when fewer systems could operate autonomously. The NIST AI Risk Management Framework provides one established structure for approaching the problem by encouraging organisations to govern, map, measure and manage AI risks throughout the technology lifecycle rather than treating security as something added after deployment. The urgency of that approach increases as AI systems gain more autonomy and organisations need to monitor what agents actually do rather than assuming they will remain within their original instructions.
For boards, the resulting question is therefore not simply how much money should be allocated to AI. It is how much of the organisation’s revenue, intellectual property, operational continuity and reputation will eventually depend on AI-enabled systems. That requires AI budgets to expand beyond licences and computing capacity. Companies may need to fund governance teams, model inventories, continuous monitoring, cybersecurity testing, identity controls, employee training, third-party assessments and incident-response capabilities alongside the applications themselves.
The organisations that understand those costs early may ultimately be able to deploy AI more aggressively rather than less. Strong controls can allow companies to give automated systems greater access and autonomy because management understands the boundaries and can monitor what happens inside them. The alternative is a cycle familiar from earlier technology transitions: rapid experimentation followed by an unexpected security, cost or compliance problem that causes management to halt programmes across the organisation.
AI adoption is therefore becoming a capital-risk decision. Boards need to understand which uses create genuine economic value, how much the organisation is spending to operate them and how much financial exposure accompanies that value. The companies that manage all three together, return, cost and risk, are likely to be in a stronger position than those that treat AI as simply another technology budget.
Source: CIJ.World Research & Analysis Team