Key findings
- AI governance is becoming an enabler, not an obstacle. Organizations are increasingly using governance frameworks to create the visibility, accountability and confidence needed to scale AI initiatives safely and effectively
- Shadow AI is emerging as one of the biggest barriers to enterprise AI adoption. Without visibility into employee-built applications, AI tools and consumption-based spending, organizations struggle to manage costs, risks and ownership
- AI is bringing ITAM, FinOps and cloud teams closer together. As AI spending spans cloud infrastructure, software licensing and vendor consumption models, organizations need a more collaborative governance model to manage technology investments and business value
For as long as organizations have talked about digital transformation, governance has been cast as the necessary counterweight to innovation. The assumption has often been that speed and control exist in tension with one another. The faster a business wants to move, the more likely it is to run into governance processes that introduce friction.
AI is exposing the limits of that thinking.
As organizations move from experimentation into broader adoption, the biggest obstacles aren’t a lack of interest, investment or potential use cases. The challenge is that AI is introducing a new layer of complexity across cloud infrastructure, software portfolios, security programs and financial management practices. The organizations making progress aren’t the ones avoiding governance; they’re the ones modernizing it.
Recent data from EY illustrates this shift clearly. While 87% of leaders at organizations investing in AI say they have deployed or are piloting programs to develop AI-built software internally, 72% also report challenges that are slowing progress. Instead of technical constraints being the most frequently cited barriers, concerns around how to govern shadow IT from unmanaged employee-created applications are what’s keeping leaders up at night. Instead of technical constraints being the most frequently cited barriers, concerns around how to govern shadow IT from unmanaged employee-created applications are what’s keeping leaders up at night. According to EY, 93% of senior leaders say governance frameworks are necessary to safely enable employees to develop in-house AI-built software.

The biggest barrier on that list, shadow IT, is also where governance has to start. Teams can’t set policy for AI tools they don’t know about or assign costs to apps nobody has registered. An app an employee builds might call a model API on a team credit card or someone’s personal API key, so the spend is real but nobody owns it. Flexera’s research shows how common this is: 45% of organizations don’t know how or when employees use AI. The first step is a working inventory of the AI tools and apps in use, who uses them, what they cost and who is responsible for them. Budgets, chargeback and cost cuts all depend on that list being right.
Taken together, these findings point to something larger than AI adoption. They suggest that governance is evolving from a risk-management function into an enablement function. In many organizations, it’s becoming the mechanism that creates enough visibility and accountability for AI initiatives to move forward with confidence.
The challenge isn’t adopting AI—it’s operating it
The conversation around AI often focuses on models, copilots and emerging use cases. But the operational questions are becoming harder to ignore:
- Who owns AI spending?
- How do organizations track consumption across business units?
- Which teams are responsible for monitoring software usage, cloud costs and compliance requirements?
- How do leaders distinguish between productive experimentation and a growing pool of unmanaged technology?
These questions may feel new in an AI context, but they’re familiar challenges elsewhere in enterprise technology. What makes AI harder is how it’s billed and used. Most software used to be priced per seat, so cost tracked headcount and budgets were fairly easy to plan. Many AI tools now charge by consumption, and each vendor measures it differently. OpenAI’s API bills by input and output tokens, and n8n by workflow executions. Anthropic’s Claude Enterprise mixes the two: a monthly fee per seat, plus token usage billed separately.
The cost isn’t always tied to a person, either. It can come from an AI agent, an automated workflow or one API key shared by hundreds of users, and those change much faster than an employee roster does. Much of this spend also never shows up in the cloud bill. It’s paid directly to AI vendors and spread across separate invoices and admin consoles. So a company can burn through its annual AI budget in a few months without anyone seeing it coming.
Organizations have already spent years building governance structures to manage cloud growth. According to Flexera’s State of the Cloud research, 71% of organizations have established a Cloud Center of Excellence (CCOE), while 63% rely on FinOps teams to help manage cloud investments. At the same time, more than half cite security and compliance concerns as the leading challenge associated with scaling cloud-based AI initiatives. Those aren’t indicators that organizations are becoming more cautious. They’re signs that enterprises recognize scale requires coordination.

What’s emerging is an operating model designed to manage complexity rather than avoid it. Governance structures such as CCOEs, FinOps programs, and dedicated AI governance functions are becoming less about enforcement and more about creating shared accountability across technology, finance, security and business teams.
That distinction matters because AI has quickly become a cross-functional challenge. Unlike previous waves of technology adoption, AI doesn’t sit neatly within a single team or budget. It consumes cloud resources, introduces new software investments, creates new categories of spend and raises questions about risk, compliance and data management. As a result, no single function has complete visibility into the AI landscape.
Why AI is bringing ITAM, FinOps and cloud teams closer together
A key pattern in Flexera’s research is the increasing overlap among disciplines that once operated separately. The boundaries separating cloud management, software asset management, technology finance and governance continue to blur. Organizations increasingly need these teams to work together because AI spans all of their domains.
The Flexera 2026 State of ITAM Report found that 78% of organizations now have a dedicated FinOps team, while 92% of ITAM practitioners report upskilling around FinOps-related disciplines. Meanwhile, 75% of ITAM teams manage cloud software licensing, and 51% now support visibility into AI spending. And the FinOps Foundation’s 2026 State of FinOps Report found like 98% of FinOps practitioners manage AI costs or plan to. These aren’t isolated responsibilities. They’re becoming interconnected parts of the same governance framework.

What’s happening is less about organizational realignment and more about operational necessity.
AI spend shows up in the cloud bill, in SaaS contracts and in vendor consumption bills that no single team sees on its own. And visibility into AI value becomes difficult to achieve without understanding how technology assets, cloud consumption and financial accountability connect to one another.
For many organizations, that reality is creating a more collaborative operating model. The teams responsible for governing technology investments are no longer focused solely on optimization or compliance. They’re increasingly responsible for helping the business understand where AI is being used, what value it is delivering and what risks need to be managed along the way.
Governance is becoming the confidence layer for AI
Much of the early discussion around AI governance centered on control. Organizations were concerned about misuse, compliance failures and unmanaged risk. Those concerns remain valid, but they’re no longer the whole story.
Today, the focus is shifting to what organizations need in place to sustain AI adoption beyond early experiments. That starts with the basics: visibility into where AI is being used, clear accountability for who owns it, policies that set consistent expectations and optimization practices that keep investments tied to value over time.
Those capabilities give organizations something they need just as much as speed: confidence.
Confidence that AI spending is aligned with business priorities. Confidence that security and compliance obligations are being met. Confidence that experimentation can occur without creating unnecessary risk. And, perhaps most importantly, confidence that successful initiatives can scale beyond isolated pilots and become part of the broader business.
That’s why governance increasingly looks less like a brake and more like an accelerator.
AI without governance is a jet with no air traffic control – not efficient, just a very expensive way to collide.
As AI becomes embedded across cloud platforms, software portfolios and business processes, the organizations that move fastest may not be the ones with the most ambitious pilot programs. They will likely be the ones that have developed the operational discipline to scale innovation repeatedly and predictably.
In that sense, governance is no longer a supporting function for AI. It’s becoming one of the foundational capabilities that determines whether organizations can realize AI’s value at enterprise scale.
Learn more about AI Cost Management
What is AI governance?
AI governance is the framework of policies, processes and accountability structures that help organizations manage how AI technologies are used. It includes oversight of AI spending, security, compliance, data usage and risk management. Effective governance creates the visibility organizations need to scale AI initiatives confidently while reducing unmanaged risk.
Why is AI governance becoming more important?
As AI adoption expands across business units, organizations face new challenges related to cost control, security, compliance and operational oversight. Governance helps leaders understand where AI is being used, who owns it, how much it’s costing and whether it’s delivering business value. Without that visibility, AI programs can become difficult to manage at scale.
What is shadow AI?
Shadow AI refers to AI tools, applications and workflows that employees use or create without formal organizational oversight. These tools may operate outside approved procurement, security or governance processes. Shadow AI can create challenges related to spending, compliance, data protection and accountability because organizations often lack visibility into how these tools are being used.
How does shadow AI affect AI costs?
Shadow AI can make AI spending difficult to track because costs may be distributed across individual subscriptions, departmental budgets, API keys or third-party services. Without centralized visibility, organizations may struggle to understand total AI expenditures, allocate costs accurately or identify opportunities for optimization.
What’s the difference between AI governance and AI risk management?
AI risk management focuses on identifying and mitigating potential risks such as security vulnerabilities, compliance issues or unintended outcomes. AI governance is broader and includes risk management alongside financial accountability, operational oversight, policy enforcement and value measurement. Governance provides the structure that enables organizations to manage AI responsibly while continuing to innovate.
How do FinOps, ITAM and cloud teams support AI governance?
AI consumption often spans cloud platforms, SaaS applications and specialized AI services. FinOps teams help track and optimize costs, ITAM teams provide visibility into technology assets and licensing, and cloud teams monitor infrastructure usage. Together, these disciplines create a more complete view of AI investments and their business impact.
Why is visibility critical for managing AI initiatives?
Organizations can’t effectively govern what they can’t see. Visibility into AI tools, applications, costs and ownership helps leaders make informed decisions about resource allocation, risk management and future investments. A comprehensive inventory is often the foundation of successful AI governance programs.
How can organizations balance AI innovation with governance?
Governance doesn’t have to slow innovation. Modern governance frameworks focus on creating transparency, accountability and consistent policies that allow teams to experiment safely. When organizations establish clear ownership and visibility, they can support innovation while minimizing operational and financial surprises.
Who should be responsible for AI governance?
AI governance is typically a shared responsibility. Technology, finance, security, legal and business teams all play important roles because AI affects multiple parts of the organization. Many organizations establish governance councils, Cloud Centers of Excellence (CCOEs) or cross-functional teams to coordinate decision-making and accountability.
What does successful AI governance look like?
Successful AI governance provides clear visibility into AI usage, defined ownership for AI investments, consistent policies for responsible use and ongoing measurement of costs, risks and business value. The goal isn’t to restrict adoption but to create the confidence needed to scale AI initiatives sustainably.