AI in the workplace: Managing AI adoption, operations, governance, and spend at scale
August 6, 2026
14 minute read
For two years, IT teams did something genuinely hard: they brought SaaS sprawl under control. After years of unchecked growth, the average software stack shrank resulting in fewer apps, tighter licensing, real discipline. That discipline held. Then AI in the workplace arrived.
It didn’t so much break that discipline as open an entirely new front. The average organization now runs 118 SaaS applications, up 11% year over year, the first meaningful reversal after two years of consolidation.
But this isn’t 2022 all over again. Of those 118 apps, 27 are AI-powered, nearly a quarter of the entire stack. Non-AI SaaS sprawl took the better part of a decade to reach its prior peak. AI built out an equivalent share of the stack in two to three years.
What stands out? It’s the same direction, but a very different speed.
AI-powered apps in the workplace also bring a very different character. This isn’t undisciplined chaos returning, it’s a disciplined stack facing a genuinely new kind of growth it wasn’t built to govern.
That’s the dual reality every IT and SaaSOps leader now manages. Real productivity gains, continually offset by shadow AI, unpredictable spend, and security exposure that didn’t exist in the usual risk register.
The organizations navigating it well aren’t the ones with the flashiest AI pilots; they’re the ones combining discovery, policy, automated enforcement, and spend optimization into operational and governance advantage. That’s what this guide is about.
TL;DR
- AI in the workplace didn’t restart SaaS sprawl, it opened a narrower, faster-moving front on top of a stack that’s otherwise still disciplined.
- Most organizations are stuck in the third AI operational readiness phase, in Tool Deployment” where policies exist but automated enforcement doesn’t, and that stage isn’t a waypoint you quickly pass through, where it’s a lengthy process of refinement.
- Five pillars, including AI SaaS spend management, visibility, automated processes, governance, and data protection, share the same pattern: a cheaper, document-level version that’s fast to build, and a resource-intensive, completely automated version that most organizations haven’t reached.
- Adoption is uneven by design, not accident. AI shows up fastest wherever it arrives pre-installed inside tools IT already owns, and slowest wherever it requires deliberately building something new.
- Managing shadow AI is hard because it’s usually a tool an employee signed up for, or a feature that shipped inside something IT already approved.
- Governing AI well isn’t a brake on speed. It’s the thing that lets IT meet rising executive pressure to move fast without taking on unmanaged risks.
What does “AI in the workplace” mean in 2026?
AI in the workplace usually describes four fairly different things: generative AI, embedded AI features inside SaaS you already use, autonomous agents, and consumption-based AI models billed by usage rather than seat.
| Technology | What it is |
|---|---|
| Generative AI | Models that produce new text, code, or images in response to a prompt (e.g., ChatGPT, Claude) |
| Embedded AI in SaaS | AI features built into software an organization already uses, often enabled by default in a platform update |
| AI agents | Systems that act semi-autonomously on a goal, triaging, escalating, or completing multi-step tasks with limited human review |
| Consumption-based AI models | Tools billed by usage or token volume rather than a fixed per-seat license |
While these 4 categories are handy to know. For governance purposes, there’s a different question to answer.
And that question is: How much visibility and control does IT actually have over each one?
| Category | IT visibility | Example |
|---|---|---|
| Deliberately procured tools | Full. IT chose it, standard governance applies | A team requests and IT provisions a licensed AI writing assistant |
| Embedded features in approved SaaS | Partial. IT approved the platform, not the AI feature switched on inside it | A ticketing platform ships an AI triage feature in a routine update |
| Employee-introduced / shadow tools | None (BYOAI) | An employee signs up for a new AI tool on their own |
| Agentic systems acting semi-autonomously | Visibility of the tool, not necessarily every action it takes | An AI agent independently triages, escalates, or resolves tickets |
That second category in the table above is the sneakiest one on this list.
It arrives disguised as something IT already approved. Nobody signed off on the AI feature. Instead, they signed off on the platform, months or years before the feature existed. That distinction is going to matter a lot when we get to adoption data in the next section.
The technology someone chooses matters less than whether IT chose it at all. In 2026, most of it, they didn’t.
What is the status of AI adoption at work?
Adoption looks strong on the surface. Most workers are using AI and report real benefits from it. At the same time, 61% of IT professionals say executives are applying high or very high pressure to adopt agentic AI, so expect the same trends here as well.
61% report high/very high pressure from executives to adopt agentic AI
But let’s look closer at how that adoption is really happening. A different picture emerges. Much of that adoption is invisible to IT, unevenly distributed across functions, and harder to measure than the headline numbers suggest.
Adoption rates and power users
Three-quarters of global knowledge workers now use AI at work, and nearly half started within the last six months, according to Microsoft and LinkedIn’s Work Trend Index.
Among the heaviest users, what Microsoft calls “power users,” 90% say AI makes an overwhelming workload more manageable. Leaders in that group report saving more than an hour a day.
But there’s a real gap growing between leadership and staff: 67% of leaders report being familiar or extremely familiar with AI agents, compared to just 40% of employees.
Take note that adoption numbers vary wildly by definition. Bain & Company found 95% of US companies now use generative AI. Pew Research, asking about individual daily use rather than organizational adoption, found just 21% of U.S. workers use AI at work.
“Adoption” is a slippery number, and that slipperiness is itself a governance problem.
Shadow AI and expense-driven entry
Most of that adoption isn’t happening through IT. Microsoft’s 2024 Work Trend Index found 78% of AI users bring their own tools to work. More than half are reluctant to admit they used AI on a critical task.
BetterCloud’s 2026 State of SaaS report puts a sharper number on the visibility gap: only 56% of all apps currently in use carry IT approval. Nearly half the software running in the average organization is managed outside IT’s line of sight entirely, including risky Shadow AI tools.
That’s the adoption IT doesn’t control.
Growth and visibility gaps
But even the adoption IT does control, the AI use cases IT itself is deliberately rolling out, isn’t happening evenly.
As we see in that same 2026 BetterCloud report, not every corner of IT is adopting AI at the same pace, and the unevenness itself is informative.
Across three tracked IT use case categories, ITSM AI adoption jumped from 47% to 77% year over year, by far the largest increase of the three. Performance-monitoring AI grew from 29% to 44%. Infrastructure and data-security AI use cases grew from 27% to 38%.

The ServiceNow effect
ITSM’s outsized jump almost certainly reflects vendor-shipped AI features. Think ticket triage, auto-categorization, and predictive routing. They’re getting switched on inside platforms IT already owns, which is happening through routine updates, not deliberate buying decisions.
Infrastructure and security AI, by contrast, usually require actively selecting and deploying new tooling into sensitive pipelines. That’s a much higher-friction path, and the growth rate shows it.
The big conclusion is that the categories closest to “a feature got turned on” moved fast. The categories that require real integration work moved slowly, a pattern we’ll see again.
Not a single vendor’s data point
Bain & Company’s independent Q3 2025 survey found IT is the fastest-growing AI use case domain of any function it tracks, with software development adoption alone climbing from 66% to 73% year over year.
Two unrelated surveys, using different methodologies, landing on the same finding: IT is where AI adoption is accelerating fastest, largely because so much of it arrives pre-installed.
Meanwhile, 97% of organizations are investing in at least one AI use case and 84% are piloting or deploying agentic AI. But 90% still lack true cross-app orchestration. That means most of what gets called “automation” today is very likely just basic identity deprovisioning, not the end-to-end workflow elimination the term implies. It’s no surprise, then, that 62% of IT leaders say manual work is actively preventing them from doing strategic projects.
What employees report gaining from AI at work
| Benefit | % Reporting | Source |
|---|---|---|
| Time saved | 90% | Microsoft/LinkedIn Work Trend Index |
| Focus on important tasks | 85% | Microsoft/LinkedIn Work Trend Index |
| Increased creativity | 84% | Microsoft/LinkedIn Work Trend Index |
| Job satisfaction | 83% | Microsoft/LinkedIn Work Trend Index |
| Power users saving 1+ hour/day | ~33% of leaders | Microsoft Work Trend Index 2025 |
| ITSM AI use case adoption (ticket triage/routing) | 47% → 77% YoY | BetterCloud 2026 State of SaaS |
Even where adoption was passive and vendor-driven, the ServiceNow effect again, the productivity capture is real.
The governance blind spot and the legitimacy of the gain are two separate questions, and it’s you who can hold onto both at once.
Managing shadow AI, cost, and the risks IT must address
The same forces driving adoption, low friction, high visibility for employees, low visibility for IT, are what make AI’s risks harder to manage than a typical SaaS rollout. Three areas deserve the closest attention.
Renewed tool sprawl makes managing Shadow AI challenging
As stated earlier, about a quarter of the average stack is an AI-powered tool, up from only 7% the prior year.
Thus, it’s very likely much of the net-new growth in the average stack is attributable to AI tools specifically. While this may not signal a general return to old SaaS sprawl habits, it points to a return to a familiar challenge that results from unknown and unapproved tools – unmanaged risk exposure.
Data exposure, oversharing, and compliance
The 2026 BetterCloud report also uncovers that the past 12 months, organizations revealed a consistent set of gaps:
- 21% discovered new unsanctioned SaaS or AI tools in use
- 20% caught sensitive data being shared publicly
- 18% experienced a breach caused by an offboarded user who retained access
- 18% found data leaks originating directly from AI tools and chatbots
This tracks with the single most credible “critical gap” finding in BetterCloud’s own readiness research: data protection is explicitly the worst-scoring pillar in the index.
Most organizations are still relying on basic policies and manual checks, not the real-time automated data-loss prevention and continuous permissions monitoring today’s tools require.
AI SaaS spend management: unpredictable consumption costs and licensing
More than a third of AI tools in the average stack are now billed on usage or token-consumption models rather than predictable per-seat pricing. That shift is exactly why AI SaaS spend management has become its own discipline, separate from general SaaS cost control. That’s not just a budgeting inconvenience.
A single employee’s unmanaged prompts can mount into thousands of dollars, which means AI governance can no longer be separated from cost control. Financial predictability is, at this point, a security issue.
Recent studies back up the critical importance of detecting Shadow AI tools and keeping a close eye on AI SaaS spend management. A July 2026 McKinsey report found that nearly all (93%) of surveyed organizations exceeded their AI budgets after moving beyond pilots. More than half of CEOs, 56% per a January 2026 PwC survey, report zero measurable ROI from AI investment over the past 12 months.
Meanwhile, against this backdrop, it’s no surprise that security and governance concerns are now the #1 SaaS management challenge.
Up sharply from 28% just a year earlier, 47% of IT leaders reported that it’s the top concern. That jump alone tells you how fast the risk perception is moving, even if the underlying tooling hasn’t caught up yet.
Building AI operational readiness
BetterCloud’s 2026 State of SaaS report introduces a SaaS and AI Operational Readiness Index: a 0 to 100 scale across four phases:
- No controls
- Manual effort
- Tool deployment
- Autonomous future
Among SaaS-first organizations (orgs with at least a quarter of applications that are SaaS), the average score is 61. That’s effectively the broad, mainstream SaaS-using market, not an exclusive or favorable slice of it.

That 61 score lands us squarely in the 3rd, the tool deployment phase
So what does that score mean and not mean?
Keep in mind that it’s self-reported by IT and security professionals rating their own organizations, so it’s reasonable to treat the precise value with some healthy skepticism rather than as a neutral external fact.
What’s more interesting than the score itself are the implications about how organizations actually move through these phases.
Moving through AI readiness phases is not likely linear
Let’s think about Phase 1 of No Controls. It can persist for a surprisingly long time, because outside competitive forces, there’s no natural forcing function to leave ad hoc chaos behind. Plenty of organizations have been happy to tackle a lot of operations with no specific plan.
In contrast, Phase 2, which is Manual Effort, can move fast by comparison. Writing a policy or standing up a spend management dashboard can be paper-cheap, and often doesn’t require buy-in across teams that don’t report to the same person.
Phase 3 is where organizations spend a lot of time
Instead of steadily climbing toward Phase 4, many organizations will oscillate between manual effort and policy rewrites, learning through experience of what actually needs governing.
That oscillation isn’t necessarily dysfunction. It’s about experience.
After all, you can’t write a good AI usage policy before you’ve watched how people actually try to use AI, what breaks, where legitimate work gets blocked by an overcautious rule. That information only surfaces after deployment, after real usage collides with a real policy.
An organization that wrote a “perfect” policy on day one, without that feedback loop, would likely have a worse policy, not a better one, because it would be guessing. The refinement is the mechanism by which good governance gets built, not a detour from it.
But there’s a second kind of Phase 3 oscillation that looks identical on a maturity score, but isn’t the same thing at all.
This time, it’s driven by the usual occurrences that happen in every organization. There’s leadership turnover. Silos. Unclear ownership. And there’s also that oh, so human tendency toward reactive, incident-driven policy-making rather than deliberate iteration.
Measuring a point in time, two organizations can both sit at 61, while one is narrowing the gap between policy and real usage with every cycle, the other is stalled and rewriting the same document for different reasons each time.
The score can’t tell you which one you’re looking at. Only internal IT teams know.
The five pillars behind the score
BetterCloud’s index breaks readiness into five components, and each one shares the same underlying shape: a cheap, document-or-dashboard version that’s fast to stand up, and an expensive, automated version that requires all the work, as well as the resources and time to deploy.
- Spend optimization. Dedicated cost-tracking tools exist almost everywhere now, driven by post-pandemic budget mandates. What’s missing is automated license reclamation and rightsizing, neither of which is fully possible without the complete visibility described next.
- Visibility. Discovery dashboards are functional at most organizations. What’s missing is continuous, real-time monitoring of embedded AI specifically, which hides inside tools IT already approved, with no clean “new app” signal to catch it. Without it, spend optimization has an incomplete picture to optimize against.
- Automated processes. Early, isolated automation exists in pockets, and it’s often mistaken for the job being done. Full integration across processes and apps doesn’t yet exist at most organizations.
- AI governance. Policy frameworks are being written across the board; writing a document is fast. Active enforcement and monitoring tooling lags.
- Data protection. The worst-scoring pillar in the index. Basic policies and manual checks are common, for the same reason enforcement lags in governance: the automated tooling to act on policy in real time isn’t there yet.
There’s a reason the pillars are in this order.
Spend and visibility are naturally linked, and mature first, because their payoff is easy to see and easy to justify to a budget-holder. Automation is in the middle because it’s never one and done. Governance and data protection lag because their return on investment is invisible until there’s an incident; nobody gets approval for the breach that didn’t happen.
The automated processes pillar deserves a closer look.
Why? Because the gap there is less about missing tools and more about a potential mismatch in what “automated” means.
Recall the cross-app orchestration gap from earlier: 90% of organizations lack it, meaning most of what gets called “automation” is basic, single-purpose workflow triggers, not integration across entire processes and including all apps. That points to something a little incongruous in how IT judges its own progress here.
Regardless, automation that’s sufficient for day-to-day operational efficiency isn’t the same as automation that meets the governance standard this index aims to measure. However, within IT, those two bars can look similar while sitting quite far apart.
Full integration is harder than single process automation
There are a few different reasons why:
1. Visibility limitations hold IT back, as you can’t integrate what you don’t know is there.
2. Ownership limitations because apps that need to talk to each other are run by different teams with different budgets and roadmaps, so no single person has the authority to wire the whole thing together, only their own piece of it.
3. Fundamental integration limitations, as some apps simply don’t offer an integration to build on, and others charge steeply for the API access that would make one possible, although AI agents are starting to close this gap.
But for now, all of these, ownership, integration limits, and blind spots alike, are holding many organizations back.
Company size doesn’t predict readiness
Mid-size organizations outscore both ends, a consistent pattern also seen in networking, security and DevOps maturity research. Small orgs have agility but limited resources, whereas large orgs have budget but less agility. AI operational readiness tracks organizational topology more than company size.

Readiness, in other words, is bounded less by intent or awareness than by organizational structure. The pressure to adopt AI is constant and visible, while the capacity to govern it lags, because its payoff, again the incident that didn’t happen, stays invisible until it isn’t.
Governing AI in the workplace: a practical playbook for IT and SaaSOps
The 2026 BetterCloud report also says that only 4% of IT leaders list “adding or refining AI governance” as their top priority for the next 12 to 18 months. That’s not neglect. 86% of IT leaders say SaaS management platforms are crucial (not just helpful) to good AI governance.
Governing AI well in 2026 isn’t about writing more policy; it’s about closing the gap between what’s written and what’s enforced.
86% find SaaS Management Platforms crucial to good AI governance
This is why IT leaders have concluded automation is governance. Rather, the work ahead is building the automated infrastructure that turns written policy into automatically enforced practice, closing the exact gap the readiness index describes.
1. Use multi-layer discovery.
Combine SSO, browser-extension-based visibility, financial/spend data, and identity signals to see the full stack, including the embedded AI features hiding inside tools already approved. This is the direct fix for visibility’s real-time blind spot.
2. Automate user lifecycle and least-privilege access.
This is especially true for AI tools. Error-prone manual offboarding is exactly how a breach from a former employee happens in the first place.
3. Protect data and automate policy enforcement.
This is the direct remedy for Data Protection, the weakest pillar in the entire index. It moves teams from manual checks to real-time, automated data-loss prevention and continuous file-permission monitoring.
4. Maintain human oversight.
Automation should handle detection and enforcement at scale. Judgment calls on edge cases, exceptions, and ambiguous situations still belong with a person. Full autonomy without a review layer is how a defensible policy turns into an indefensible one applied a thousand times before anyone notices.
5. Measure impact beyond usage metrics.
Usage metrics like hours saved or percentage of employees using AI are what’s typically measured today, and they’re not enough. The ITSM adoption jump is the clearest illustration of why. Because that adoption was vendor-driven, most IT teams never built baselines to measure its actual impact in the first place.
In IT, getting metrics around:
- Ticket deflection rate and mean-time-to-resolution change attributable specifically to AI tools for IT
- License reclamation dollars recovered through automated rightsizing
- Shadow AI incidents caught before versus after governance tooling went live
- Time-to-detect an unsanctioned tool or embedded AI feature
- The percentage of written policies that have automated enforcement behind them, the metric most directly tied to the readiness argument above
AI operational readiness checklist to get started now
- Run a full multi-layer discovery pass (SSO, browser, financial, and identity signals together) to find all tools, including embedded AI features hiding inside already-approved tools.
- Audit which AI tools are on usage-based or token billing versus fixed per-seat pricing, and flag any without a spend ceiling or alert threshold.
- Confirm user lifecycle automation includes AI tools, not just core SaaS, so an offboarded employee loses expensive AI access immediately, not eventually.
- Audit written AI policies: to identify which AI policies have any automated enforcement behind them, and which are enforced by hope alone.
- Prioritize data protection first. It’s generally weakest for most orgs, and the one with the least visible ROI until it’s tested by an incident.
- Track outcomes, not usage. Pick 2 or 3 concrete metrics and start tracking them before your next AI tool rollout, not after.
- Look honestly at your last policy revision. Did it close a real gap between what the policy said and how people were using AI, or was it written in reaction to an incident? That’s the difference between productive Phase 3 churn and being stalled in it.
- Revisit your AI usage policy on a real cadence, treat revision as expected iteration rather.
Close the policy-to-enforcement gap with BetterCloud
Operational readiness for AI isn’t a ladder you climb once. Most organizations will spend real time oscillating for a while in the Tool Deployment Phase. It’s not because they’re behind, but because good governance must be calibrated against real usage.
And that calibration with a SaaS management platform for governing AI in the workplace takes cycles to get right. As your governance partner, look for a tool with:
- Multi-layer discovery, including browser extensions for surfacing and managing Shadow AI
- An AI agent for IT that keeps a human in the loop
- Automated user lifecycle management
- File governance for data protection
- Spend optimization for AI SaaS spend management, including automated rightsizing and license reclamation
- A unified Activity Hub ties it all together for easier management
Beyond avoiding the next data leakage or security incident, there’s another benefit. Top management won’t ease up on pushing AI adoption any time soon.
What good AI governance buys IT isn’t relief from that pressure. Instead, it gives you the confidence to move fast and stay competitive while managing risks.
FAQs on AI in the Workplace for IT and SaaSOps leaders
What does “AI in the workplace” mean?
AI in the workplace covers generative AI tools, AI features embedded inside existing SaaS platforms, autonomous AI agents, and consumption-based AI models. For IT and SaaSOps purposes, what matters most is how much visibility and control IT has over each one, not the technology type itself.
What is Shadow AI?
Shadow AI is the use of AI tools or features without IT’s knowledge or approval, including both employee-introduced tools and AI features embedded inside platforms IT already approved for other reasons.
What is the BetterCloud AI Operational Readiness Index?
The BetterCloud AI Operational Readiness Index is a maturity framework measuring how prepared an organization is to govern AI at scale, typically scored across pillars like visibility, spend optimization, automated processes, governance, and data protection, rather than adoption alone.
Why is AI SaaS spend management so hard?
AI SaaS spend management is so difficult because a growing share of AI tools bill by usage or token consumption rather than fixed per-seat licensing, which means costs can scale unpredictably with employee behavior rather than headcount.