Every executive we talk to right now says some version of the same thing. "We need AI." And when we ask what outcomes they're targeting, the room goes quiet.
That's the gap. It's everywhere. And it's getting expensive.
We're watching companies adopt AI the same way businesses adopted IT 20 years ago. No strategy. No coordination. No one asking who approved what, where the data is going, or what the monthly spend actually looks like. Departments grab whatever tools look interesting. Marketing is running one set of AI platforms nobody vetted. Operations wants to wire APIs into the ERP system. Sales is scraping data with no compliance review. And somewhere in the office, someone has been using a single chat thread for everything, research, drafts, data analysis, brainstorming, all in one place, for months. That person burned through the company's entire token budget in 3 weeks because nobody taught them how the platform actually charges.
We've written extensively about AI governance frameworks and why they matter. That content ranked #1 in Google and across AI platforms when we published it. But writing about governance and actually delivering it are different things. Now we do both.
The Ad-Hoc Adoption Problem
The pattern is predictable at this point. A company with 150 employees. No AI policy. No approved tool list. No training. Three or four departments all experimenting independently. Nobody reporting costs to finance. Nobody reporting data handling to compliance.
Sound familiar?
PagerDuty's 2026 Shadow AI Survey found that 66% of office professionals at large enterprises have used AI tools they believed weren't permitted under company policy. At companies with $1B+ in revenue, that number hits 72%. And according to Gartner, 25-35% of enterprise AI tool spending now happens entirely outside of IT visibility.
For a manufacturer in Los Angeles or a distribution company in Orange County, the numbers might look different. But the pattern doesn't. We've seen it at professional services firms, food processing operations, and real estate management companies across Southern California. The tools change. The problem is the same.
One thing we keep noticing. It isn't the AI itself that creates risk. It's the absence of any structure around how it gets used. When every team picks their own tools, sets their own rules, and handles data however seems reasonable at the time, you don't get innovation. You get sprawl. Budget overruns. Security gaps you don't find out about until an auditor does.
Same mess. Different decade. Except AI sprawl moves faster than IT sprawl ever did. And the regulatory environment around it is tightening, not loosening.