Ask most finance leaders how many AI tools their company uses and you’ll get a number that’s confidently wrong. It’s usually the count of AI tools that came through formal procurement, the ones with a signed contract and a line item somebody can point to. It’s rarely the real number, because a meaningful share of the AI tools running inside any given company today were never bought through procurement at all. They were added by a team lead with a corporate card, a free tier that quietly became load bearing, or a feature that shipped inside a tool the company was already paying for and nobody flagged as a new AI purchase.
Two industry benchmarks published this year put real numbers on how big that gap actually is. BetterCloud’s State of SaaS research found that the average business now runs around twenty seven AI-powered applications, a mix of AI-native tools and AI features bolted onto existing software, and that only around half of all applications in use carry formal IT approval. Torii’s benchmark report, using a different methodology, found the average enterprise running more than eight hundred applications total, with well over sixty percent of them sitting outside formal IT oversight. The two numbers aren’t measuring exactly the same thing, and I’d treat either one as directionally true rather than precise to the decimal point. But they’re both describing the same shape: a much larger and messier AI footprint than the one showing up in anyone’s official inventory.
This is the part of the AI ROI conversation that gets skipped most often, and it’s the part that matters most for anyone trying to actually price their exposure. A measurement tool that only covers the vendors a company deliberately signed contracts with is, by definition, only measuring a fraction of what’s actually running. If a fifth of an organization’s software footprint is AI-powered and half of that fifth was never formally approved, then any ROI number built exclusively from procurement data is missing real spend, real risk, and real value sitting entirely outside its view.
This is the reason we built Nymbral to cover the full stack rather than a single vendor or a curated list of approved tools. Full coverage isn’t a feature we added later to round out a pitch deck. It was the starting assumption, because a partial picture of AI spend isn’t a smaller version of the right answer. It’s a different, less useful answer that happens to look complete on a dashboard. If the goal is a number a board can actually rely on, it has to account for the AI a company is really running, not just the AI a company remembered to put on a purchase order.