
Article
Cross-industry
9 min read
AI sprawl is the uncontrolled spread of AI tools across a company: each team adopts its own, nobody owns or sees the whole, and no one can say what any of it returns. It starts with tools bought one department at a time, and for whoever runs operations it means spend that can't be totaled, data that isn't listed anywhere, and nothing to show when the board asks whether AI is worth what it costs.
A
Part of the EBS Integrator AI-maturity series · Level 2 → 3
the short version:
How common: in 2025, 20.81% of mid-size EU firms used two or more kinds of AI technology, and 13.48% used AI for two or more business purposes (Eurostat).
Why the return is invisible: it arrives slowly, few firms measure it, and each tool's dashboard counts its own activity, not the outcome.
The trap: cutting to one tool, blind, cancels what works and swaps sprawl for dependency.
The way out: one register of every tool, one question per department, a data rule each, then keep the few tools that carry the work.
How AI sprawl happens, one department at a time
Marketing buys a writing assistant. Design adds an image tool. Engineering pays for a coding assistant, and support trials a chatbot nobody cancels.
Each team buys its own tool; nothing reaches one answer.
In 2025, Eurostat found that 30.36% of EU firms with 50 to 249 staff used AI, up from 20.97% a year earlier. In Eurostat's count, 20.81% used two or more of the eight kinds of AI technology it tracks, led by text analysis (18.22%) and generating text or code (14.79%), and 13.70% used three or more.[1]
Eurostat also counts 13.48% using AI for two or more business purposes, up from 8.90%, led by marketing or sales (10.83%) and administration (10.61%).
So many of these firms run several kinds of AI, in several parts of the business, and each tool keeps its own copy of the data it touches. That's how the records multiply. Eurostat counts kinds of technology, not tools: one chatbot can cover two of them, and two chatbots count once.
Eurostat's own figures, 2025: every bar is a share of all EU firms with 50 to 249 staff (financial firms excluded), and every kind and purpose sits inside the 30.36% that use AI. Kinds of technology are what the AI does; business purposes are where it is used. Some firms using AI name none of the seven purposes.
Most AI arrives ready-made. No planned architecture, just a plug-in. In its 2026 survey, Moldova's statistics office counted 1,179 firms with ten or more staff using AI; 886 of them use closed-source software, free or paid, and 267 built their own.[2]
It happens even after a company has listed its AI tools and signed a usage policy. The list records what people use. Nobody decided what the company buys.
What level of AI maturity is AI sprawl?
AI sprawl is level 2 on the EBS AI-maturity ladder AI tool sprawl, with no owner, rule or measure around it. The next level of maturity starts when the company decides what it buys and why.
Vitalie Aremescu, founder of EBS Integrator, decodes this level it in one line:
There are tools, but no systems.
How AI sprawl differs from shadow AI
Shadow AI is the use of AI that nobody can see (people working with AI on accounts the company doesn't hold). That's level 1, and our piece on shadow AI covers how to find it.
AI sprawl is effort and money on tools that nobody owns. The tools are on the company's bills, yet what they return is on no one's.
Where your company sits at this level
level | where you stand | how it looks from perspective of level 2 |
|---|---|---|
0 · AI is off-limits | behind you | AI is no longer banned on paper; it is bought and used in the open |
1 · People use AI | mostly behind you | people no longer work only on their own accounts: the company pays, department by department; personal accounts can still run beside the paid tools, so check |
2 · Tools, no system | you are here ✓ | Each department pays for its own AI: a dozen subscriptions, no owner, no measure. The tools help the teams that chose them, but nobody totals the spend or measures the return. |
3 · Teams trained | next, within reach | The company decides what it buys and why: one register, one question per department, a data rule each, and the few tools that carry the work, with the people you have. |
4 · Routine work on AI | ahead, built on your defined criteria | measured automations, with a person reviewing every output: they are only worth what they measurably save, and the question you set per department now is what they will be measured against |
5 · AI runs workflows | futher, built on your data rules | agents running alone in production: they need data with an owner and rules, and the data rule you write in step 3 is where that starts |
6 · Agents coordinate work | futher, built on one shared record | agent chains across whole processes: they need one shared record, so the same client must read the same in the CRM, 1C and support first |
7 · Processes built on AI | far ahead, built on the level before | processes designed AI-first: that assumes the levels before it already work |
8 · AI self-optimizes | the horizon | models that retrain themselves: then the questions become strategic, and not a decision for this year |
Levels 0 to 4: getting ready to automate. Levels 5 to 8: processes run on their own. Full ladder on the AI-maturity page
The OECD draws the same line on integration: from AI tools used "without integration or shared infrastructure" to AI "with growing co-ordination, shared data resources and emerging governance mechanisms."[3]
Why nobody can tell you what AI returns
A typical AI use case takes two to four years to reach a satisfactory return, against seven to 12 months for other technology, say most of the 1,854 executives across Europe and the Middle East in a 2025 survey by Deloitte, which sells AI consulting.
One executive Deloitte interviewed could only get "a ballpark estimate" of the benefits, because AI's gains were hard to separate from other changes.[4]
Two surveys show how far most companies are from seeing a return:
Return: 56% of 4,454 CEOs surveyed by PwC, which sells AI services, say AI has brought neither higher revenue nor lower costs.[5]
Measurement: fewer than one in five organizations track KPIs for generative AI, the practice McKinsey, also an AI consultancy, found most tied to bottom-line impact (1,491 respondents).[6]
Some do see it: Deloitte found 15% of respondents using generative AI already report significant, measurable ROI. Each vendor's dashboard shows activity: drafts written, prompts sent, seats in use. None shows whether a client stayed, a deal closed or a defect was caught, because nobody told it what to count.
Our founder's advice runs the other way
If we start only from data, we may end up with a beautiful report that nobody reads. If we start from questions, such as why we're losing clients for the third month running or why orders get stuck, we can reach an answer that can change a decision, a system, a process.
The same client is a different record in each tool
For AI it's essential that the same term, the same entity, means the same thing everywhere,
Vitalie says.
"A client in 1C is the same client in the CRM. Without that, any answer from the AI can be meaningless.
Many firms don't have that record at all: their client data sits in data silos, one per tool.
Eurostat reports that in 2025, 69.93% of EU firms with 50 to 249 staff ran an ERP that shares information between functions, the shared record an AI tool would read from. By our arithmetic, about 3 in 10 don't.
What AI sprawl costs
The bill is the visible part.
The cost is in what the bill hides:
Unused seats: fewer than 60% of workers with sanctioned access use AI daily, say 3,235 leaders surveyed by Deloitte, an AI consultancy, in 2026.
Duplicates: two teams paying for the same kind of tool.
Unlisted data: customer data in tools nobody has on record.
Why cutting down to one tool isn't the answer
The obvious fix is the one someone always raises:
Can't we just standardize on one tool?
It fails twice.
Cutting blind cancels what works.
The pilots behind these tools were never set up to show which helped. Vitalie's warning: "No 'let's test and see what comes out', because something will always come out, but most likely that something won't connect to anything, and in a year nobody will even remember it."
One vendor for everything swaps sprawl for dependency
In the EU, that risk is shrinking: under the Data Act, as the European Commission explains it, companies have been able to switch cloud and software providers since 12 September 2025, and from 12 January 2027 providers can no longer charge for the switch.[7]
So consolidate last, and keep the exit.
How to get AI sprawl under control
Nothing here needs a purchase. It takes four moves, in order, with people you already have.
The four moves, each needing the one before.
1. See the whole stack (what is paid for and what is used)
Ask finance for every AI charge, department heads for what each tool is for, IT for what it connects to, and whoever handles data protection for what data goes in. The result is one register, a row per tool:
what it costs, and who pays
what it's for, and who uses it how often
what it duplicates
what it connects to, and with what access
what data goes into it
who owns it, and the question it's meant to answer
keep, merge or stop
No survey can give you these numbers. Only your own register can.
The connections column deserves the closest look: among breached organizations, IBM, which sells security, found supply-chain compromise, including apps, APIs and plug-ins, was the most common cause of AI security incidents, at 30%.[8]
2. Agree on the one question AI should answer
A useful question names an outcome: reduce unplanned downtime and maintenance cost. A useless one names a tool: implement AI for maintenance.
Pick one per department, such as fewer lost clients in sales or a faster month-end close in finance, and judge every tool against it.
3. Write a data rule for each department
We classify data by sensitivity before we choose the tool, not after,
Vitalie says
For each category it's written down what may leave the company and what may not.
Under the GDPR[9], similar to Moldova's Law 195/2024[10] (in force since 23 August 2026), Article 30's record lists who receives personal data, and Article 28 requires a written contract with each vendor that processes it.
Firms under 250 staff are exempt from the record unless the processing is risky, not occasional, or covers special categories of data. A tool your team uses daily on customer data isn't occasional.
Access belongs in the register too. In the same IBM study of 600 breached organizations, 97% of the few whose breach involved an AI model or application lacked proper AI access controls.
4. Keep the few tools that carry the work
Keep the tools that answer the department's question and share the client record. Merge the duplicates; stop the rest.
Two rules keep it from growing back:
Before adding. A new tool joins only if nothing in the stack does its job, and it connects to the systems you run.
One owner. One named person approves every addition and retires every duplicate.
Fewer tools, then, not one, and every exit kept.
What level 3 looks like, and what to show the board
At level 3, the board question has one answer from one place: the register, read against each department's question. Teams report outcomes: hours saved, leads qualified, defects prevented. Level 3, Teams trained unevenly, brings the next problem: the right tools, used well by some teams and barely by others.
To see where your company sits now, take the AI-maturity assessment.
None of this costs a subscription. It costs a list, a question and a rule, and it lets you tell the board whether AI is worth what it costs.
Frequently asked questions
What is AI sprawl?
AI sprawl is the uncontrolled spread of AI tools across a company, bought department by department, with no owner and no shared way to measure what they return.
How is AI sprawl different from shadow AI?
Shadow AI is AI used on accounts the company doesn't hold, so nobody sees it; it's level 1 of AI maturity. AI sprawl is AI the company pays for but nobody owns; it's level 2.
What does AI sprawl cost a company?
Unused seats, duplicate tools and unlisted customer data. No one publishes a total.
How do you stop AI tool sprawl?
Four moves, in order:
List every AI tool, with cost, users, connections and owner.
Agree the one question AI answers in each department.
Write a data rule per department.
Keep the few tools that carry the work. Consolidate last, never first.
Reference
- Eurostat, Use of artificial intelligence in enterprises (Statistics Explained) and datasets
isoc_eb_aiandisoc_eb_ain2(AI by business purpose), 2025 data. ↑ - Biroul Național de Statistică al Republicii Moldova, Utilizarea produselor TIC în întreprinderi, 2026 edition. ↑
- OECD, AI adoption by small and medium-sized enterprises, discussion paper for the G7, December 2025. ↑
- Deloitte, AI ROI: The paradox of rising investment and elusive returns, 22 October 2025. ↑
- PwC, 29th Global CEO Survey, 19 January 2026. ↑
- McKinsey, The state of AI: How organizations are rewiring to capture value, 12 March 2025. ↑
- European Commission, Data Act explained (Regulation (EU) 2023/2854). ↑
- IBM and Ponemon Institute, Cost of a Data Breach Report 2025. ↑
- [11] Regulation (EU) 2016/679 (GDPR), Articles 28 and 30. ↑
- Republic of Moldova, Law No. 195/2024 on personal data protection, in force 23 August 2026. ↑
Share this article on:
More insights

Article
Cross-industry
AI Consulting
6 min read
AI running on accounts that your company does not hold. This article explains what it is, how it spreads, and how to take it to the next level. (AI-maturity series lvl 1)
Article
Cross-industry
AI Consulting
Regulatory & Compliance
7 min read
Is AI overhyped? Yes, as a purchase promise. No, as what a prepared company can do with it. The evidence, and what the first step off level zero takes.

Article
Cross-industry
Cloud & DevOps
Data Engineering & Analytics
8 min read
Moving a 15 TB production Aurora PostgreSQL cluster from 14 to 18.3 with sub-minute cutover: Blue/Green prerequisites, worker math, and the storage trap.

Article
FinTech
AI Consulting
Data Engineering & Analytics
Regulatory & Compliance
5 min read
AI in fintech is everywhere, yet few systems would survive an audit. Why projects stall, what regulators expect, and the three steps that fix it.

Article
EdTech
Systems Integration
Data Engineering & Analytics
11 min read
Legacy administrative platforms across European education institutions were procured separately with no shared architecture, creating education data silos that force daily manual reconciliation, while 70% of IT capacity is consumed maintaining these systems.

Article
Retail & eCommerce
Data Engineering & Analytics
AI Consulting
8 min read
Big Data is changing the retail industry. (internal expertise) Learn how businesses use data to make smarter decisions, create personalized experiences, and improve customer service with real examples of BigData applied to today’s fast-moving market.

Article
Retail & eCommerce
Business Analysis
AI Consulting
6 min read
How omnichannel strategies and AI-driven personalization help retailers connect online and in-store experiences, improve operations, and keep shoppers coming back.

Article
Retail & eCommerce
AI Consulting
Data Engineering & Analytics
6 min read
Find out how technology-driven personalization x AI creates closer relationships with customers.

Article
Retail & eCommerce
Data Engineering & Analytics
AI Consulting
6 min read
Reach customers wherever they shop with AI and real-time data. Discover how targeted marketing, a seamless online and offline shopping experience, and predictive analytics can personalize recommendations and boost sales. Our retail expert, Olga, shares practical insights and strategies to help you take your store digital. Read the full article for actionable tips and real-world examples.

Article
Retail & eCommerce
Business Strategy
Digital Transformation
Data Engineering & Analytics
7 min read
Learn about personalized customer experiences, data-driven decision-making, omnichannel approaches, AI/AR and real stories of how we help businesses implement new business models.

Article
Cross-industry
Cloud & DevOps
Data Engineering & Analytics
IT Consulting
9 min read
Data storage has evolved from paper/floppy disks to cloud tech. See through our experts' experience what cloud migration is, how can you use it for your business and what you get from migrating your data to the cloud.

Article
Cross-industry
Programming Languages
Data Engineering & Analytics
7 min read
The world of Data Sciences’ is an ever-changing place, new applications and requirements appear on a daily basis. With all that, a professional SQL-guru who can optimize their interactions with databases is valued in his weight in gold. Luckily for us we have just such master. In this post we hope to explore the world of ORMs (particularely Django ORM vs SQL Alchemy) with our Python specialist and get his opinion on which he prefers! And provide some nifty examples to boot.

Article
Cross-industry
AI Consulting
Process Automation
7 min read
From ELIZA to modern AI: explore chatbot evolution in customer service. Learn how 1.4 billion users benefit from automated support and instant query resolution.

Article
Cross-industry
Data Engineering & Analytics
Software Development
7 min read
Peeling this BASICs digital onion, we’ve left some details out (particularly in our last article). As stated, data-centric and data-driven applications deserve their series, a journey we’re kicking off today. Before talking about BigData, strategies and mechanics, let’s filter the messy data-centric vs data-driven dilemma.