Plainstart Back to the kit

Article

Six AI Subscriptions and No Idea Who Is Paying: Fixing AI Tool Sprawl

AI adoption, done properly.

Most AI sprawl happens without a single bad decision. Nobody went rogue. Nobody was careless. A few people in different parts of the business found tools that helped them, signed up, started using them, and got on with their work. Six months later, the business has six subscriptions on four different cards, two of which belong to people who have left, and nobody can say with confidence what data has been shared with which service.

This is the starting point for a lot of small and medium businesses right now. It is not a crisis, but it does need fixing before it becomes one.


How Sprawl Happens Without Anyone Doing Anything Wrong

The pattern is consistent. A marketing coordinator signs up for an AI writing tool on a free trial. The trial converts to a paid plan because cancellation requires effort and the tool is genuinely useful. Meanwhile, a developer has added a code assistant to their editor. The finance manager is using a different AI tool to summarise documents. The founder signed up for something at a conference six months ago and has not opened it since.

Each decision, in isolation, was reasonable. The problem is that nobody was coordinating. There was no agreed list of approved tools. There was no policy about what data could be shared with a third-party AI service. There was no single person responsible for tracking what the business was paying for.

The result is a fragmented picture that creates three real problems.

First, there is a data risk. Business data, client names, internal documents, financial figures, have been pasted into tools with terms of service that most people in the business have never read. Some of those tools use submitted content to train their models unless you have a paid plan with specific data protections. Many businesses have no idea which category they are in.

Second, there is a cost problem. Individually, AI subscriptions seem small. Collectively, they add up faster than most finance teams expect, especially when several people have independently signed up for overlapping tools that do similar things.

Third, there is an ownership problem. If the person who signed up for a tool leaves, the subscription often sits on their personal card and their personal email address. The business loses access or keeps paying without knowing it.

None of this happened because people were negligent. It happened because AI tools became easy to adopt individually before most businesses had any structure around adoption collectively.


The One-Afternoon Audit

You do not need a consultant for this. You need a few hours, a spreadsheet, and access to the right information.

Step one: Card and email sweep (one hour)

Ask every person in the business to look at their work email inbox and filter for subject lines containing words like "subscription", "receipt", "invoice", "trial", "plan", "renewal". Do the same for personal cards if those have been used for business tools, which they often have. Ask the finance team to pull transaction data for the last twelve months and flag anything that looks like a software subscription.

Collect every tool that surfaces into a single spreadsheet. Columns: tool name, who signed up, which email address, which payment method, monthly or annual cost, what it is used for, who currently uses it.

Step two: Usage check (thirty minutes)

For each tool on the list, ask the person who signed up one question: who in the business used this in the last thirty days? If they cannot name at least one specific person, the tool is a candidate for cancellation.

Step three: Terms check (thirty minutes)

For each active tool, find the privacy policy or terms of service and answer these questions: does the provider use submitted content to improve their models by default, and if so, can you opt out, and under what plan? Where is data stored, and in which jurisdiction?

You do not need a lawyer for this step, though you should get professional advice if you have specific legal or compliance obligations. This is general operational guidance, not legal advice. The goal at this stage is simply to identify which tools have terms you have never read and which ones are storing data in ways you were not aware of.


A Worked Audit Finding

During an audit at a fifteen-person services business, the operations lead discovered the following for a single tool on the list.

The business had been using an AI document summarisation tool for eight months. Three people had signed up independently for separate accounts. Two accounts were on free plans. One was on a paid plan. The two free accounts had terms that explicitly allowed the provider to use submitted content for model training. The content submitted over those eight months included client proposals, internal meeting notes, and a draft contract.

The business had not consented to that use on behalf of their clients. It had not checked whether that was permissible under its own client agreements. It had also been paying for a feature, the paid plan's data protections, that only covered one of the three accounts.

The fix was consolidating to one paid account with appropriate data protections, deleting the two free accounts, and adding a line to the data governance checklist requiring a terms review before any new tool goes into use.

That finding took ninety minutes to surface and thirty minutes to fix. The cost of not finding it was ongoing and indefinite.


The Questions That Decide Whether a Tool Stays

Apply these five questions to every tool on your list.

One: Does more than one person actively use this? A tool used by one person is a personal preference, not a business tool. It belongs in a personal account with no business data in it.

Two: Do we have a paid plan that protects our data? If the answer is no, and the tool processes any business or client data, either upgrade or stop using it for that purpose.

Three: Does another tool on the list do the same thing? If two tools overlap significantly, pick one. Consolidation reduces cost and makes governance simpler.

Four: Does the business own the account? The account should be registered to a business email address and tied to a business payment method. If it is not, fix that before anything else.

Five: Can we write down what this tool is for? If you cannot write a one-sentence description of what the tool does and who uses it for what purpose, that is a sign the tool has not been properly adopted. It may still be worth keeping, but it needs a clear owner and a clear use case.


How to Consolidate Without a Mutiny

The instinct when doing a tool audit is to cut everything that looks unnecessary. That is often the wrong move. People have built habits and workflows around the tools they use. Removing a tool without a plan for what replaces it creates friction and resistance.

A better approach: identify your consolidation targets first. These are tools where you have two or three doing similar things. Then talk to the people using them before you make a decision. Ask what they are actually using the tool for. Often, one tool in a pair is covering a use case the other does not, and the right answer is to keep one and be clear about what it is for.

Give people enough notice before cancelling anything. Two weeks is reasonable for most tools. Provide a short note explaining what is being cancelled, why, and what they should use instead. Keep the note plain and specific. This is not a policy lecture, it is information people need to do their work.


How to Stop It Recurring

The audit fixes the current state. These four things prevent it from happening again.

Maintain an approved tool list. A simple shared document listing every approved AI tool, its purpose, its owner, and its renewal date. Update it when anything changes. Review it quarterly.

Set a default on data. Decide, as a business, what kinds of data are permitted to go into AI tools and under what conditions. Write it down. Make it part of onboarding. This does not need to be a lengthy document, but it does need to exist.

Centralise payment. All software subscriptions go on a business card or through a purchase request. Personal cards are not used for business tools. This one change makes future audits much faster.

Require a sign-off before a new tool goes in. It does not need to be a committee. It can be a single person, a manager, or a founder. The requirement is that someone checks the terms, checks for overlap with existing tools, and approves the use case before the account is created.


Start With a Policy

None of this requires a large project. It requires a few clear decisions made once and written down in a place where people can find them.

The place to start is an AI usage policy. A policy sets the boundary between approved and unapproved tools, specifies what data can and cannot go into AI systems, and gives people enough information to make sensible decisions without asking permission every time.

Plainstart's free AI Usage Policy gives you a plain-language starting point built for small and medium businesses. It covers data classification, approved tool categories, staff responsibilities, and breach handling. It is written to be used, not filed.

Download it free at Plainstart. No email tricks, no upsell before you get the document.

If you want to take the full step, the AI Adoption Kit at $149 includes the policy alongside a data governance checklist, a 90-day adoption plan, a tool scorecard, prompt libraries, an ROI tracker, and a staff one-pager. Everything you need to run AI properly without building a dedicated team to manage it.

AI adoption, done properly.


This article is general operational guidance only. It is not legal, financial, or compliance advice. If your business has specific legal obligations around data handling, seek professional advice before making decisions based on this content.

Free, no email required

Build your own AI usage policy in about two minutes

Answer eight questions and the full policy writes itself around your business. Copy it, download it, put it in front of staff today.

Open the policy generator