Most mid-size companies believe they have a reasonably complete picture of their SaaS spend. Finance has the invoices. IT manages the major platforms. The CFO approves the significant contracts. The assumption is that anything meaningful shows up somewhere.
The gap between that assumption and reality is what uncontracted SaaS spend measures. And in 2026, with AI tools entering through expense accounts and department budgets, that gap is wider than it has ever been.
What Is Uncontracted SaaS Spend?
Uncontracted SaaS spend is any SaaS tool that is active and generating cost for the company but has no formal contract on record. This is not the same as unused spend. An uncontracted tool can be in daily use, processing sensitive company data, and appearing on invoices every month. The distinction is the absence of a formal contract: no negotiated terms, no data processing agreement, no renewal date in anyone's calendar, no right to audit, and no exit clause.
The definition matters because uncontracted spend creates two separate problems, not one. The cost problem is visible, at least in principle: the tool shows up somewhere on an invoice or expense report. The compliance and risk problem is largely invisible: the company has no documented agreement covering what happens to its data, whether the vendor meets minimum security standards, or what recourse exists if something goes wrong.
For a broader view of how uncontracted spend sits within the full vendor risk picture, see SaaS and Cloud Vendor Risk Management: The Complete Guide for Mid-Size Companies.
Why Mid-Size Companies Consistently Underestimate It
Three structural features of mid-size operations cause uncontracted spend to accumulate faster than finance or IT can track it.
The first is decentralised purchasing. At a company with 200 to 500 employees, individual departments have enough budget authority to purchase SaaS tools without triggering a formal procurement review. A customer success team subscribes to a conversation analytics tool. A finance manager adds a reporting integration. A developer expenses a code assistant. Each purchase is within someone's budget authority. None of them surfaces in the contract management system.
The second is approval thresholds that were set before AI tools existed. Most mid-size companies set their procurement approval thresholds based on traditional SaaS pricing. AI tools often price below those thresholds, or bill via API usage in a way that does not trigger any single invoice above the review threshold, even when cumulative monthly spend is significant.
The third is the pace of adoption. In 2026, the window between an employee discovering a useful AI tool and starting to use it for work is measured in days, not weeks. Formal procurement processes were not designed for that pace.
The Four Main Sources in 2026
Understanding where uncontracted spend comes from is the first step toward finding it.
Department-led purchases below the approval threshold. Tools purchased by team leads or managers that fall below the amount that triggers finance or IT review. These tools are often active for months or years before anyone outside the department is aware of them.
AI tools expensed by individuals or small teams. This is the fastest-growing category. A developer expenses a monthly AI coding assistant. A marketing team member charges an AI image generation subscription. A finance analyst pays for an AI summarisation tool. Each is individually small. Collectively, they represent a material and largely unreviewed slice of the technology budget.
Vendor scope creep. A SaaS contract was signed for 50 users two years ago. Usage has grown to 80 users through onboarding and team expansion. The contract was never formally updated to reflect the expanded scope. The company is now exposed: either the vendor can charge retroactively for unlicensed usage, or the next renewal will carry a significant true-up that nobody budgeted for.
Tools tied to departed employees. SaaS subscriptions linked to individual accounts that were not deprovisioned when the employee left. These tools continue billing. With no one actively using them, no one notices until a finance review surfaces an invoice for a tool no one recognises.
Why AI Has Become the Fastest-Growing Category
The AI dimension of uncontracted spend deserves specific attention in 2026 because the data describes a scale most mid-size companies have not yet reckoned with.
Flexera's 2026 State of ITAM Report found that 55% of employees are using AI tools that were not approved by their organisation, and only 31% of organisations have accurate visibility into their AI software spend. These are not edge cases. They describe the majority of mid-size companies in the current environment.
The problem compounds because AI tools create compliance exposure on top of cost exposure. When an employee uses an AI tool for work without a formal contract, the company typically has no documentation of how the tool handles company data: no data processing agreement, no confirmation of data residency, no right to deletion or portability. For companies in regulated industries or operating across multiple jurisdictions, this is a material compliance risk, not just a budget concern.
For more on how AI tool adoption has reshaped the unmanaged spend picture across SaaS, cloud, and AI together, see Why AI Tools Are Becoming Mid-Size Companies' Fastest-Growing Unmanaged Spend.
Is AI Spend Running Outside Your Contracts?
CostRoom maps every active SaaS, cloud, and AI tool across your portfolio, including the ones that arrived through expense accounts and department budgets.
What Uncontracted Spend Actually Costs
There are three cost layers, and the most visible one is typically the smallest.
The direct cost layer is what the company pays for tools it did not formally procure. Because these tools entered without a benchmarking review, the company is almost certainly paying list price. No negotiation has happened. No volume discount has been applied. No competitive alternative was evaluated before purchase.
The compliance cost layer is less visible but often more significant. A tool processing company data without a reviewed data processing agreement creates exposure under data protection regulations and, for companies in regulated industries, under sector-specific compliance requirements. Remediating compliance exposure after an audit or incident is materially more expensive than preventing it.
The operational cost layer sits between the two. Uncontracted tools do not appear in renewal calendars. They auto-renew without review. They carry terms set entirely by the vendor. And when a contract dispute or vendor incident occurs, the company negotiates without leverage, documentation, or recourse.
How to Find Your Uncontracted Spend
Finding uncontracted spend requires reconciling three data sources, because no single source is complete on its own.
The finance or ERP system captures tools on direct invoice. The IT system, whether through SSO logs, mobile device management, or a similar platform, captures tools that were assigned an organisational login. Expense management captures tools purchased by individuals below the invoice threshold.
The gap between what appears in the finance system and what appears in expense management and SSO logs combined is the uncontracted spend category. In practice, reconciling these three sources typically surfaces more tools than finance or IT expected. A spend review is the most efficient mechanism for doing this systematically before budget planning, rather than reactively after an audit. For the structure of a full technology spend review and what it produces, see Technology Spend Review: How to Run One Before Your Next Budget Cycle.
What to Do Once You Have Found It
The uncontracted spend list needs two types of action, in sequence.
First, prioritise by risk. Tools that are processing sensitive company data, operating in regulated environments, or connecting to core business systems without a data processing agreement should be addressed first, regardless of their cost profile. The compliance risk is time-sensitive in a way that cost risk is not.
Second, for each tool on the list: formal contract with a reviewed data processing agreement, right-sizing to current usage, or discontinuation. Continuing to use a tool without a contract after it has been identified is a decision, and it creates documented exposure.
Going forward, the goal is to close the structural gap that allowed these tools to accumulate. A structured intake process for new tool requests, combined with a renewal calendar that tracks every active tool, provides the operational baseline. For how renewal management works as an ongoing practice, see SaaS and Cloud Contract Renewal Management: The Complete Guide for Mid-Size Companies.
CostRoom's Spend Analysis and Optimisation identifies every active tool across the portfolio, including uncontracted spend, and delivers a prioritised action plan covering both cost and compliance exposure.
Find What's Running Outside Your Contracts
CostRoom maps your full SaaS, cloud, and AI portfolio and identifies uncontracted spend before it compounds into a larger cost or compliance problem.
Frequently Asked Questions
What is uncontracted SaaS spend?
Uncontracted SaaS spend is any SaaS tool that is active and generating cost for the company without a formal contract on record. This is distinct from unused spend: an uncontracted tool can be in daily use, processing sensitive company data, and billing monthly. The absence of a contract means no negotiated terms, no data processing agreement, no renewal date, and no recourse if something goes wrong.
How much uncontracted spend does the average mid-size company have?
Most mid-size companies underestimate the number of uncontracted tools in their portfolio significantly. Reconciling finance systems, IT logs, and expense management typically surfaces tools that neither finance nor IT was fully aware of. The uncontracted category tends to be largest in companies where department-led purchasing is common and where AI tools have entered through individual or team expense accounts in the last 12 to 24 months.
Why are AI tools the fastest-growing source of uncontracted spend?
AI tools are priced below most procurement approval thresholds, adopted quickly, and often billed via API usage rather than a traditional invoice. Flexera's 2026 State of ITAM Report found that 55% of employees are using AI tools not approved by their organisation, and only 31% of companies have accurate visibility into AI software spend. These tools also carry data handling requirements that make an absent contract a compliance issue, not just a cost one.
What risks does uncontracted SaaS spend create beyond wasted cost?
The compliance and risk exposure is typically more significant than the direct cost. Uncontracted tools have no documented data processing agreement, which creates regulatory exposure under data protection frameworks. They have no audit rights and no exit clause. They auto-renew without review. And because they have never been formally assessed for security or financial stability, they carry the highest concentration of third-party risk in the portfolio.



