Dark teal cover with a node-and-edge motif and the Good Transformer wordmark, marking an article on cutting AI tool sprawl in a small firm.
AI toolsAI governanceShadow AIAI adoptionSmall business

Too many AI tools? How to cut the sprawl without losing value

Most firms now pay two or three times for the same AI job. A short register, an owner per tool and a quarterly cull cut the cost and the risk without banning anything.

Good Transformer8 min read

A stack of AI subscriptions is usually a good sign. It means your team went looking for tools that help, which is the behaviour you want.

The cost is that the same job often gets bought two or three times over, and nobody has the full list. You can keep the enthusiasm and cut the waste. Pick one main assistant, fold the tools that do the same job into it, and review the list once a quarter.

The reason to do this now, rather than next year, is that AI tools have started to act. A year ago an assistant answered questions in a chat box. In 2026 it reads your files, drafts from your inbox and takes actions across your systems. So it is now worth deciding on purpose what each tool can reach, rather than leaving it as a line on a card statement.

How the second and third AI subscription creeps in

Sprawl rarely arrives as a decision. It arrives one sign-up at a time.

Someone tries a meeting-notes tool and expenses the monthly fee. A colleague prefers a different assistant and puts it on their own card. A free trial converts because nobody cancelled it. None of these is wrong on its own. Together they leave a firm paying for several tools that overlap, with no single person able to name them all.

The most common overlap is paying for something you already own. Microsoft 365 and Google Workspace now write meeting notes, summarise long threads and draft replies. Zoom's paid plans include an AI notetaker. A firm that also pays for a standalone transcription or notes tool is buying the same capability twice.

The scale of this is measured in larger organisations, so treat the figures as a general trend rather than your own numbers.

In Zylo's 2026 SaaS Management Index, a survey of 218 IT leaders across more than 40 million licences, companies leave 36% of their software licences unused. BetterCloud's 2026 State of SaaS puts the average company at 106 separate software apps, and found a third of organisations consolidated overlapping tools last year. The pattern holds at every size: subscriptions accumulate faster than anyone reviews them.

Why the pile-up matters more now than a year ago

An unused subscription used to be a money problem and nothing more. That has changed, because the tools now do more than talk.

Give an assistant access to your shared drive and your inbox and it can read a client file, act on an email and send a reply. That is genuinely useful. It also opens a risk that did not exist when the tool only answered questions in a chat window.

The clearest account of that risk comes from the developer Simon Willison, who calls it the lethal trifecta. Trouble starts when one tool has all three of these at once: access to your private data, exposure to content written by someone outside the firm, and a way to send information out.

An assistant wired into your mailbox has all three. As Willison explains, an attacker can email your assistant and tell it what to do, and the assistant cannot reliably tell your instructions from a stranger's.

None of this is a reason to pull back from AI. The useful response is to know which tools can reach real data, and to turn on the controls the vendors have built.

ChatGPT lets an administrator set what each connected app may do, from read-only to full access. Microsoft 365 makes a staff-built agent wait for admin approval before anyone else can use it, and keeps it inside the firm's existing file permissions. Claude's Google Drive connector is read-only by default.

The tools are being built to be managed. A tool nobody manages is the one to worry about.

The fix: one main assistant, a short register, one owner each

The fix is not a project. It is three habits a small firm can start this month.

Standardise on one main assistant. Most firms do not need ChatGPT and Claude and Gemini and Copilot all running at once. Pick the one that fits how you already work, usually the one built into your email and documents, and make it the default. Keep a second only where it does a job the first genuinely cannot.

Keep a short register. That is one shared list of every AI and software tool the firm pays for, with four things next to each: who owns it, when it renews, what it costs, and what it can reach (chat only, read-only, or able to act on your files and mail).

That last column is new, and it is the one that makes the register worth keeping. A simple written policy naming which tools are approved does the same job from the other direction.

Give every tool one named owner, not a committee. That person approves new users, notices whether anyone still uses it, and decides at renewal. Without an owner, nobody ever decides to cancel it.

Banning the rest is the tempting move, and it backfires. Ethan Mollick of the Wharton School, who studies how firms actually adopt AI, puts it plainly. When a company does not allow AI use, the use does not stop. It goes underground, and the learning that comes with it stays hidden.

The better read on the tools staff chose for themselves is that they are telling you where the work is broken. Firms are already moving this way, and it is working.

In Netskope's 2026 Cloud and Threat Report, the share of AI users working through personal accounts fell from 78% to 47% in a year, while the share on accounts the organisation manages climbed from 25% to 62%. That is firms swapping tools they cannot see for ones they can.

The quarterly cull

Once a quarter, spend an hour on the list. Here is the whole routine.

1. Pull the list. Get every AI and software subscription in one place. Three sources between them catch almost all of it: the expense records, for anything on a personal card; the login or single-sign-on logs, for what people actually open; and the admin console of your main assistant, for connected apps and agents.

2. Check usage. For each tool, ask when it was last used and by how many people. If one person uses a tool and they last signed in three months ago, it has quietly become a charge that renews itself. Flag it.

3. Check the owner and the reach. Confirm each tool still has a named owner. Note what it can reach, and flag anything that can act on files or mail without a clear reason to.

4. Give a verdict: keep, merge or kill. Every tool gets one of three outcomes.

Verdict When Worked example
Keep Used by several people, does a job nothing else you own does, has an owner Your main assistant, used across the firm most days. Keep it, and note the owner.
Merge Its job is already done by a tool you pay for A standalone meeting-notes app, when your office suite already writes notes. Cancel it and switch the built-in feature on.
Kill Barely used, or nobody will own it A writing tool two people trialled and nobody signs into. Drop it and reclaim the spend.

Run that four-step pass once a quarter and the list stays short on its own. A one-off clear-out helps once. Repeating it each quarter is what keeps the pile-up from rebuilding.

Keeping the good tools, without the free-for-all

The aim is a short, well-chosen set of tools that people actually use, with an easy way to add a good new one. Before the firm signs up for the next subscription, a quick check helps: five questions that catch a duplicate before it lands on someone's card.

Getting this organised is the kind of work we do with leaders one to one. We help a firm turn a scattered set of subscriptions into a short, managed list with a named owner for each, so it saves money and holds up to scrutiny.

What is AI tool sprawl?

AI tool sprawl is the slow build-up of overlapping AI and software subscriptions across a firm. They get bought one at a time by different people, until the same job is paid for more than once and nobody holds a full list. It is the AI version of a problem most firms already had with software in general, now growing faster because AI subscriptions are cheap to start and easy to expense.

Should we ban AI tools that staff signed up for themselves?

Usually not. Banning tends to push the use out of sight rather than stop it, and you lose the signal about what people find useful. The better move is to bring those tools onto a managed list, keep the ones that earn their place, and give each an owner. Turn a tool off for a real reason, such as it can reach client data without oversight, rather than as a blanket rule.

How often should we review our AI tools?

Once a quarter is enough for most small firms. An hour spent pulling the list, checking usage, and giving each tool a keep, merge or kill verdict keeps the pile-up from rebuilding. Tie the review to renewal dates, so you look at a tool before you re-commit to it.


The next quarter is the place to start. Pull your list, give each tool an owner and a verdict, and cancel the one you are paying for twice. If you would like a hand getting your firm's AI use organised, book a call and we will work through it with you.

Work with Good Transformer

Turn this thinking into working practice.

Explore team advisory

Newsletter

Get new Insights by email

Practical notes on using AI with judgement, and the AI news leaders actually need. No hype, no spam, unsubscribe anytime.

Choose how often you want the digest

Keep reading