image
HomeBlog

What is AI sprawl, and how do you get it under control?

What is AI sprawl, and how do you get it under control?

AI Consulting

Data Engineering & Analytics

Article

Cross-industry

9 min read

AI sprawl is the uncontrolled spread of AI tools across a company: each team adopts its own, nobody owns or sees the whole, and no one can say what any of it returns. It starts with tools bought one department at a time, and for whoever runs operations it means spend that can't be totaled, data that isn't listed anywhere, and nothing to show when the board asks whether AI is worth what it costs.

A
Part of the EBS Integrator AI-maturity series · Level 2 → 3


the short version:

  • How common: in 2025, 20.81% of mid-size EU firms used two or more kinds of AI technology, and 13.48% used AI for two or more business purposes (Eurostat).

  • Why the return is invisible: it arrives slowly, few firms measure it, and each tool's dashboard counts its own activity, not the outcome.

  • The trap: cutting to one tool, blind, cancels what works and swaps sprawl for dependency.

  • The way out: one register of every tool, one question per department, a data rule each, then keep the few tools that carry the work.

How AI sprawl happens, one department at a time

Marketing buys a writing assistant. Design adds an image tool. Engineering pays for a coding assistant, and support trials a chatbot nobody cancels.

m14-flow-sprawl-builds-up.svgEach team buys its own tool; nothing reaches one answer.


In 2025, Eurostat found that 30.36% of EU firms with 50 to 249 staff used AI, up from 20.97% a year earlier. In Eurostat's count, 20.81% used two or more of the eight kinds of AI technology it tracks, led by text analysis (18.22%) and generating text or code (14.79%), and 13.70% used three or more.[1]


Eurostat also counts 13.48% using AI for two or more business purposes, up from 8.90%, led by marketing or sales (10.83%) and administration (10.61%).


So many of these firms run several kinds of AI, in several parts of the business, and each tool keeps its own copy of the data it touches. That's how the records multiply. Eurostat counts kinds of technology, not tools: one chatbot can cover two of them, and two chatbots count once.

m20-ai-spreading-mid-size.svgEurostat's own figures, 2025: every bar is a share of all EU firms with 50 to 249 staff (financial firms excluded), and every kind and purpose sits inside the 30.36% that use AI. Kinds of technology are what the AI does; business purposes are where it is used. Some firms using AI name none of the seven purposes.


Most AI arrives ready-made. No planned architecture, just a plug-in. In its 2026 survey, Moldova's statistics office counted 1,179 firms with ten or more staff using AI; 886 of them use closed-source software, free or paid, and 267 built their own.[2]


It happens even after a company has listed its AI tools and signed a usage policy. The list records what people use. Nobody decided what the company buys.

What level of AI maturity is AI sprawl?

AI sprawl is level 2 on the EBS AI-maturity ladder AI tool sprawl, with no owner, rule or measure around it. The next level of maturity starts when the company decides what it buys and why.


Vitalie Aremescu, founder of EBS Integrator, decodes this level it in one line:

There are tools, but no systems.

How AI sprawl differs from shadow AI

Shadow AI is the use of AI that nobody can see (people working with AI on accounts the company doesn't hold). That's level 1, and our piece on shadow AI covers how to find it.


AI sprawl is effort and money on tools that nobody owns. The tools are on the company's bills, yet what they return is on no one's.

Where your company sits at this level

level

where you stand

how it looks from perspective of level 2

0 · AI is off-limits

behind you

AI is no longer banned on paper; it is bought and used in the open

1 · People use AI

mostly behind you

people no longer work only on their own accounts: the company pays, department by department; personal accounts can still run beside the paid tools, so check

2 · Tools, no system

you are here ✓

Each department pays for its own AI: a dozen subscriptions, no owner, no measure. The tools help the teams that chose them, but nobody totals the spend or measures the return.

3 · Teams trained

next, within reach

The company decides what it buys and why: one register, one question per department, a data rule each, and the few tools that carry the work, with the people you have.

4 · Routine work on AI

ahead, built on your defined criteria

measured automations, with a person reviewing every output: they are only worth what they measurably save, and the question you set per department now is what they will be measured against

5 · AI runs workflows

futher, built on your data rules

agents running alone in production: they need data with an owner and rules, and the data rule you write in step 3 is where that starts

6 · Agents coordinate work

futher, built on one shared record

agent chains across whole processes: they need one shared record, so the same client must read the same in the CRM, 1C and support first

7 · Processes built on AI

far ahead, built on the level before

processes designed AI-first: that assumes the levels before it already work

8 · AI self-optimizes

the horizon

models that retrain themselves: then the questions become strategic, and not a decision for this year


Levels 0 to 4: getting ready to automate. Levels 5 to 8: processes run on their own. Full ladder on the AI-maturity page


The OECD draws the same line on integration: from AI tools used "without integration or shared infrastructure" to AI "with growing co-ordination, shared data resources and emerging governance mechanisms."[3]

Why nobody can tell you what AI returns

A typical AI use case takes two to four years to reach a satisfactory return, against seven to 12 months for other technology, say most of the 1,854 executives across Europe and the Middle East in a 2025 survey by Deloitte, which sells AI consulting.


One executive Deloitte interviewed could only get "a ballpark estimate" of the benefits, because AI's gains were hard to separate from other changes.[4]


Two surveys show how far most companies are from seeing a return:

  • Return: 56% of 4,454 CEOs surveyed by PwC, which sells AI services, say AI has brought neither higher revenue nor lower costs.[5]

  • Measurement: fewer than one in five organizations track KPIs for generative AI, the practice McKinsey, also an AI consultancy, found most tied to bottom-line impact (1,491 respondents).[6]

Some do see it: Deloitte found 15% of respondents using generative AI already report significant, measurable ROI. Each vendor's dashboard shows activity: drafts written, prompts sent, seats in use. None shows whether a client stayed, a deal closed or a defect was caught, because nobody told it what to count.


Our founder's advice runs the other way

If we start only from data, we may end up with a beautiful report that nobody reads. If we start from questions, such as why we're losing clients for the third month running or why orders get stuck, we can reach an answer that can change a decision, a system, a process.

The same client is a different record in each tool

For AI it's essential that the same term, the same entity, means the same thing everywhere,

Vitalie says.

"A client in 1C is the same client in the CRM. Without that, any answer from the AI can be meaningless.

m16-same-client-three-records.svgMany firms don't have that record at all: their client data sits in data silos, one per tool.


Eurostat reports that in 2025, 69.93% of EU firms with 50 to 249 staff ran an ERP that shares information between functions, the shared record an AI tool would read from. By our arithmetic, about 3 in 10 don't.

What AI sprawl costs

The bill is the visible part.


The cost is in what the bill hides:

  • Unused seats: fewer than 60% of workers with sanctioned access use AI daily, say 3,235 leaders surveyed by Deloitte, an AI consultancy, in 2026.

  • Duplicates: two teams paying for the same kind of tool.

  • Unlisted data: customer data in tools nobody has on record.

Why cutting down to one tool isn't the answer

The obvious fix is the one someone always raises:

Can't we just standardize on one tool?

It fails twice.

  1. Cutting blind cancels what works.

The pilots behind these tools were never set up to show which helped. Vitalie's warning: "No 'let's test and see what comes out', because something will always come out, but most likely that something won't connect to anything, and in a year nobody will even remember it."

  1. One vendor for everything swaps sprawl for dependency

In the EU, that risk is shrinking: under the Data Act, as the European Commission explains it, companies have been able to switch cloud and software providers since 12 September 2025, and from 12 January 2027 providers can no longer charge for the switch.[7]


So consolidate last, and keep the exit.

How to get AI sprawl under control

Nothing here needs a purchase. It takes four moves, in order, with people you already have.

m18-four-moves.svg

The four moves, each needing the one before.

1. See the whole stack (what is paid for and what is used)

Ask finance for every AI charge, department heads for what each tool is for, IT for what it connects to, and whoever handles data protection for what data goes in. The result is one register, a row per tool:

  • what it costs, and who pays

  • what it's for, and who uses it how often

  • what it duplicates

  • what it connects to, and with what access

  • what data goes into it

  • who owns it, and the question it's meant to answer

  • keep, merge or stop

No survey can give you these numbers. Only your own register can.


The connections column deserves the closest look: among breached organizations, IBM, which sells security, found supply-chain compromise, including apps, APIs and plug-ins, was the most common cause of AI security incidents, at 30%.[8]

2. Agree on the one question AI should answer

A useful question names an outcome: reduce unplanned downtime and maintenance cost. A useless one names a tool: implement AI for maintenance.


Pick one per department, such as fewer lost clients in sales or a faster month-end close in finance, and judge every tool against it.

3. Write a data rule for each department

We classify data by sensitivity before we choose the tool, not after,

Vitalie says

For each category it's written down what may leave the company and what may not.

Under the GDPR[9], similar to Moldova's Law 195/2024[10] (in force since 23 August 2026), Article 30's record lists who receives personal data, and Article 28 requires a written contract with each vendor that processes it.


Firms under 250 staff are exempt from the record unless the processing is risky, not occasional, or covers special categories of data. A tool your team uses daily on customer data isn't occasional.


Access belongs in the register too. In the same IBM study of 600 breached organizations, 97% of the few whose breach involved an AI model or application lacked proper AI access controls.

4. Keep the few tools that carry the work

Keep the tools that answer the department's question and share the client record. Merge the duplicates; stop the rest.


Two rules keep it from growing back:

  1. Before adding. A new tool joins only if nothing in the stack does its job, and it connects to the systems you run.

  2. One owner. One named person approves every addition and retires every duplicate.

Fewer tools, then, not one, and every exit kept.

What level 3 looks like, and what to show the board

At level 3, the board question has one answer from one place: the register, read against each department's question. Teams report outcomes: hours saved, leads qualified, defects prevented. Level 3, Teams trained unevenly, brings the next problem: the right tools, used well by some teams and barely by others.


To see where your company sits now, take the AI-maturity assessment.


None of this costs a subscription. It costs a list, a question and a rule, and it lets you tell the board whether AI is worth what it costs.




Frequently asked questions

What is AI sprawl?

AI sprawl is the uncontrolled spread of AI tools across a company, bought department by department, with no owner and no shared way to measure what they return.

How is AI sprawl different from shadow AI?

Shadow AI is AI used on accounts the company doesn't hold, so nobody sees it; it's level 1 of AI maturity. AI sprawl is AI the company pays for but nobody owns; it's level 2.

What does AI sprawl cost a company?

Unused seats, duplicate tools and unlisted customer data. No one publishes a total.

How do you stop AI tool sprawl?

Four moves, in order:

  1. List every AI tool, with cost, users, connections and owner.

  2. Agree the one question AI answers in each department.

  3. Write a data rule per department.

  4. Keep the few tools that carry the work. Consolidate last, never first.


Reference

  1. Eurostat, Use of artificial intelligence in enterprises (Statistics Explained) and datasets isoc_eb_ai and isoc_eb_ain2 (AI by business purpose), 2025 data. ↑
  2. Biroul Național de Statistică al Republicii Moldova, Utilizarea produselor TIC în întreprinderi, 2026 edition. ↑
  3. OECD, AI adoption by small and medium-sized enterprises, discussion paper for the G7, December 2025. ↑
  4. Deloitte, AI ROI: The paradox of rising investment and elusive returns, 22 October 2025. ↑
  5. PwC, 29th Global CEO Survey, 19 January 2026. ↑
  6. McKinsey, The state of AI: How organizations are rewiring to capture value, 12 March 2025. ↑
  7. European Commission, Data Act explained (Regulation (EU) 2023/2854). ↑
  8. IBM and Ponemon Institute, Cost of a Data Breach Report 2025. ↑
  9. [11] Regulation (EU) 2016/679 (GDPR), Articles 28 and 30. ↑
  10. Republic of Moldova, Law No. 195/2024 on personal data protection, in force 23 August 2026. ↑

Share this article on:

More insights

Blog Image

Article

Cross-industry

AI Consulting

6 min read

What is shadow AI, and is it already happening in your company?

AI running on accounts that your company does not hold. This article explains what it is, how it spreads, and how to take it to the next level. (AI-maturity series lvl 1)

Published Updated
See more
Blog Image

Article

Cross-industry

AI Consulting

Regulatory & Compliance

7 min read

Is all the AI overhype justified? If so, how can you make the most of it?

Is AI overhyped? Yes, as a purchase promise. No, as what a prepared company can do with it. The evidence, and what the first step off level zero takes.

Published Updated
See more
Blog Image

Article

Cross-industry

Cloud & DevOps

Data Engineering & Analytics

8 min read

Upgrading a 15 TB Aurora PostgreSQL cluster from 14 to 18.3

Moving a 15 TB production Aurora PostgreSQL cluster from 14 to 18.3 with sub-minute cutover: Blue/Green prerequisites, worker math, and the storage trap.

Published Updated
See more
Blog Image

Article

FinTech

AI Consulting

Data Engineering & Analytics

Regulatory & Compliance

5 min read

A guide to getting AI in fintech ready for use

AI in fintech is everywhere, yet few systems would survive an audit. Why projects stall, what regulators expect, and the three steps that fix it.

Published Updated
See more
Blog Image

Article

EdTech

Systems Integration

Data Engineering & Analytics

11 min read

The cost of data silos in higher education administration

Legacy administrative platforms across European education institutions were procured separately with no shared architecture, creating education data silos that force daily manual reconciliation, while 70% of IT capacity is consumed maintaining these systems.

Published Updated
See more
Blog Image

Article

Retail & eCommerce

Data Engineering & Analytics

AI Consulting

8 min read

What does BigData have to do with modern retail?

Big Data is changing the retail industry. (internal expertise) Learn how businesses use data to make smarter decisions, create personalized experiences, and improve customer service with real examples of BigData applied to today’s fast-moving market.

Published Updated
See more
Blog Image

Article

Retail & eCommerce

Business Analysis

AI Consulting

6 min read

Why 'omni'-channel your online and physical stores?

How omnichannel strategies and AI-driven personalization help retailers connect online and in-store experiences, improve operations, and keep shoppers coming back.

Published Updated
See more
Blog Image

Article

Retail & eCommerce

AI Consulting

Data Engineering & Analytics

6 min read

Online shopping gets better if 'personalisation'

Find out how technology-driven personalization x AI creates closer relationships with customers.

Published Updated
See more
Blog Image

Article

Retail & eCommerce

Data Engineering & Analytics

AI Consulting

6 min read

How technology and data helps your store adapt to market changes

Reach customers wherever they shop with AI and real-time data. Discover how targeted marketing, a seamless online and offline shopping experience, and predictive analytics can personalize recommendations and boost sales. Our retail expert, Olga, shares practical insights and strategies to help you take your store digital. Read the full article for actionable tips and real-world examples.

Published Updated
See more
Blog Image

Article

Retail & eCommerce

Business Strategy

Digital Transformation

Data Engineering & Analytics

7 min read

How to sell the digital way in (e)commerce

Learn about personalized customer experiences, data-driven decision-making, omnichannel approaches, AI/AR and real stories of how we help businesses implement new business models.

Published Updated
See more
Blog Image

Article

Cross-industry

Cloud & DevOps

Data Engineering & Analytics

IT Consulting

9 min read

Cloud Migration/ or moving data from off to online

Data storage has evolved from paper/floppy disks to cloud tech. See through our experts' experience what cloud migration is, how can you use it for your business and what you get from migrating your data to the cloud.

Published Updated
See more
Blog Image

Article

Cross-industry

Programming Languages

Data Engineering & Analytics

7 min read

Django ORM vs SQL Alchemy

The world of Data Sciences’ is an ever-changing place, new applications and requirements appear on a daily basis. With all that, a professional SQL-guru who can optimize their interactions with databases is valued in his weight in gold. Luckily for us we have just such master. In this post we hope to explore the world of ORMs (particularely Django ORM vs SQL Alchemy) with our Python specialist and get his opinion on which he prefers! And provide some nifty examples to boot.

Published Updated
See more
Blog Image

Article

Cross-industry

AI Consulting

Process Automation

7 min read

How AI Chatbots transform customer service

From ELIZA to modern AI: explore chatbot evolution in customer service. Learn how 1.4 billion users benefit from automated support and instant query resolution.

Published Updated
See more
Blog Image

Article

Cross-industry

Data Engineering & Analytics

Software Development

7 min read

Data-centric vs data-driven (explained)

Peeling this BASICs digital onion, we’ve left some details out (particularly in our last article). As stated, data-centric and data-driven applications deserve their series, a journey we’re kicking off today. Before talking about BigData, strategies and mechanics, let’s filter the messy data-centric vs data-driven dilemma.

Published Updated
See more