Last month I had coffee with a CTO at a mid-sized financial services firm in Colombo. Good guy. Sharp. Knows his infrastructure inside out.

I asked him a simple question: "How many AI tools are your employees using?"

"Three," he said. "Copilot for M365, ChatGPT for the marketing team, and GitHub Copilot for engineering."

I pulled out my phone and showed him a list of 14 AI tools that employees at similar-sized Sri Lankan companies typically use without IT approval.

He went quiet for a moment.

"That can't be right," he said.

It is.

What Is Shadow AI?

Shadow AI is the AI equivalent of Shadow IT — tools and services that employees adopt without the knowledge, approval, or oversight of their IT or compliance teams.

The difference? Shadow IT was usually about project management apps or file-sharing tools. Shadow AI involves your company's most sensitive data being processed by services you've never evaluated, never vetted, and never agreed to terms for.

Here's what Shadow AI looks like in a typical Sri Lankan enterprise:

  • The marketing team uses ChatGPT (free tier) to draft customer emails. They paste in customer names, purchase history, and campaign performance data to "get better outputs."
  • The finance team uses Claude to summarize quarterly reports. They upload Excel files with client financials because "it's faster than reading everything."
  • The legal team uses Google Gemini to review contracts. They paste in full contract text — including client names, commercial terms, and confidential clauses.
  • The HR team uses an AI resume screener they found on Product Hunt. They upload candidate CVs with personal details, salary expectations, and references.
  • The junior analysts use Perplexity, Poe, and half a dozen other AI wrappers they discovered on TikTok or Twitter. They use them for research, data analysis, and report drafting.
  • The CEO's executive assistant uses ChatGPT to draft board meeting minutes. Including confidential financial projections and strategic decisions.

None of this was approved. None of it was evaluated. None of it has an audit trail. And all of it involves personal data — which means all of it is a PDPA event.

Why Shadow AI Happens

Shadow AI isn't a technology problem. It's a human problem. And it happens for three reasons:

  1. AI tools are free and frictionless. You don't need IT to sign up for ChatGPT. You don't need a procurement process for Claude. You need an email address and 30 seconds. The barrier to adoption is zero — which means the barrier to unsanctioned use is also zero.
  2. Employees want to be productive. Your people aren't trying to create compliance risks. They're trying to do their jobs better. AI makes them faster. So they use it. The problem is they don't know — and nobody told them — that pasting customer data into a free AI tool creates a data protection liability.
  3. IT policies don't mention AI. Most Sri Lankan enterprises have IT policies that cover software installation, data storage, and email usage. Very few have policies that specifically address AI tools. This means employees are operating in a grey zone — and they're defaulting to "it's probably fine."

It's not fine.

The Inference Cost Problem Nobody's Talking About

Here's where it gets worse. And this is the part that should make every CFO pay attention.

The AI tools your employees are using for free? They won't stay free.

There's a structural crisis in the AI industry that most people outside of tech haven't heard about. It's called the inference wall.

Here's the simple version:

Building and training an AI model like GPT-4 or Claude requires a massive one-time investment — hundreds of millions of dollars in compute, data, and engineering. That's the upfront cost.

But inference — the ongoing processing that happens every single time someone sends a prompt and gets a response — scales infinitely with usage. Every query costs money. Every response costs money. And as more people use these tools, the costs don't just grow linearly. They compound.

OpenAI reportedly spends billions per year on inference alone. Anthropic, Google, and others face the same math. The more users they acquire, the more they lose per query.

This creates a simple economic reality:

The free tier cannot last.

Right now, the free versions of ChatGPT, Claude, Gemini, and every other AI tool are subsidized by venture capital and the hope that users will eventually convert to paid plans. But the inference wall means the subsidy math gets worse every month. Every free query your marketing intern sends costs the provider real money.

What happens when the subsidy runs out?

  • Option 1: Prices go up. The US$40/user ChatGPT Enterprise plan becomes US$60. The US$30/user Copilot becomes US$60. You have no control over this. You're a price taker.
  • Option 2: Free tiers get gutted. The free version becomes so limited it's useless. Your employees — who've built workflows around these tools — suddenly can't do their jobs the way they've been doing them.
  • Option 3: Data monetization increases. When you can't charge users enough to cover inference costs, you find other ways to monetize. Training on user data. Targeted advertising. Selling aggregated usage patterns. The "free" tool starts paying for itself by using your data in ways you didn't anticipate.
  • Option 4: Tools shut down entirely. We've already seen this. AI startups that raised millions, acquired users, and then folded because the unit economics didn't work. When that happens, your employees' workflows break overnight — and the data they uploaded? Gone. Or worse, sitting on servers you can't access or audit.

Every one of these scenarios is a problem for your enterprise. And every one of them is happening right now to the free AI tools your employees are using without your knowledge.

What Shadow AI Costs You

Let's be specific about the costs. Not theoretical costs. Real costs.

Cost 1: PDPA Liability

Every piece of personal data that enters an unapproved AI tool is a potential PDPA violation. Customer names, employee records, financial data, patient information — if it's processed by a tool you haven't vetted, with terms you haven't reviewed, on servers you can't locate, you are exposed.

PDPA doesn't accept "our employees did it without our knowledge" as a defense. The organization is liable. Full stop.

Cost 2: Data Residency Risk

Most free AI tools process data on servers in the US or Europe. Under PDPA, cross-border transfers of personal data require legal justification. If you don't even know which tools are being used, you can't assess — let alone justify — where data is going.

Cost 3: Zero Audit Trail

When a regulator asks "what personal data was processed by AI tools in your organization, and where did it go?" — can you answer? If Shadow AI is in play, the answer is no. You can't produce an audit trail for tools you don't know exist.

Cost 4: Vendor Lock-In by Accident

When employees build workflows around free AI tools, those tools become embedded in your operations — without procurement review, without vendor assessment, without exit planning. When prices go up (and they will — the inference wall guarantees it), you're locked in. Not by contract, but by habit.

Cost 5: IP and Confidentiality Leakage

Your strategic plans, your pricing models, your client lists, your proprietary processes — if any of this has been entered into a free AI tool, it may have been used for model training. Most free-tier terms of service allow this. Your competitive advantage may already be someone else's training data.

The Shadow AI Audit: What To Do This Week

You can't fix what you can't see. Use this quick audit to find out what is actually happening inside your organization this week.

Step 1: Send a short Shadow AI survey.

Send the survey to every department head, not just IT. Shadow AI usually sits outside IT's line of sight.

  1. What AI tools does your team use for work? Include free tools, browser extensions, mobile apps, and AI features inside existing software.
  2. What data does your team enter into these tools? Examples: customer data, financial data, employee data, strategy documents, contracts, or reports.
  3. Were these tools approved by IT? Yes / No / Don't know
  4. Do you know where these tools process data? Yes / No
  5. If these tools became unavailable tomorrow, would your team's work be affected? Yes / No / Not sure

Step 2: Map the findings.

Create one simple tracker so the pattern is visible at a glance:

  • ChatGPT (free) — Marketing — customer names, campaign data — approved? No
  • Claude — Finance — client financials — approved? No
  • Gemini — Legal — contracts, client terms — approved? No
  • Perplexity — Analysts — research queries — approved? No
  • [Tool X] — HR — candidate CVs, salary data — approved? No

Step 3: Classify the risk.

For each tool, answer three questions:

  • Does it process personal data? (If yes → PDPA risk)
  • Does data leave Sri Lanka? (If yes → cross-border transfer risk)
  • Do you have a data processing agreement? (If no → governance risk)

If any answer creates risk, that tool needs to be addressed before PDPA enforcement.

Step 4: Make a decision.

For each Shadow AI tool, choose one of three paths:

  • Approve — The tool is valuable and can meet governance requirements. Evaluate it properly, negotiate a data processing agreement, add it to the approved list, and set usage guidelines.
  • Replace — The use case is valid, but the tool is not compliant. Find a sovereign alternative that keeps data in Sri Lanka. This is where Neurux fits.
  • Eliminate — The risk outweighs the value. Ban the tool, explain why, and provide an approved alternative so employees are not left without a solution.

Step 5: Write the policy.

Every enterprise needs an AI usage policy. It doesn't need to be 50 pages. It needs to answer five questions:

  • Which AI tools are approved for use?
  • What data can be entered into approved tools?
  • What data is prohibited from AI tools?
  • Who approves new AI tools?
  • What happens if someone uses an unapproved tool?

If you don't have this policy, your employees are writing it for you — one ChatGPT prompt at a time.

The Inference Wall Changes Everything

Here's the strategic insight that most enterprises are missing.

The AI tools landscape is not stable. It's not going to look the same in 12 months. The inference wall — the structural cost problem where every AI query costs real money and those costs scale with usage — is going to reshape the entire industry.

What this means for your enterprise:

  • Prices will rise. Microsoft, OpenAI, Google, and Anthropic are all losing money on every query. At some point, they'll pass those costs to you. The $30/user Copilot is a promotional price for a market-share land grab. It's not the long-term price.
  • Free tiers will shrink. The free ChatGPT your employees love? It's being subsidized by billions in venture capital. When that subsidy ends — and the inference wall means it will — the free tier either disappears or becomes so limited it's useless.
  • Data practices will change. When you can't cover inference costs with subscription revenue, you find other revenue streams. User data is the obvious one. The terms of service will change. The data you thought was private may not stay private.
  • Vendor lock-in will deepen. As prices rise and free tiers shrink, enterprises that built workflows around a single vendor will face a choice: pay more or rebuild everything. That's not a choice. That's a hostage situation.

The enterprises that will navigate this transition successfully are the ones that:

  • Know exactly which AI tools are in use (no Shadow AI)
  • Control where their data goes (sovereign infrastructure)
  • Maintain model flexibility (switch providers without rebuilding)
  • Have audit trails for everything (compliance-ready)

If you don't have these four things today, you're not just exposed on PDPA. You're exposed on cost, on data security, and on operational continuity.

The Bottom Line

Your employees are already using AI. That's not the problem. The problem is you don't know which tools, you don't know what data is being entered, and you don't know where that data goes.

The inference wall — the structural cost crisis in the AI industry — means the free ride is ending. Prices will rise. Free tiers will shrink. Data practices will change. And the enterprises that didn't audit their Shadow AI exposure will be the ones scrambling.

PDPA enforcement is approaching. The inference wall is approaching. Both are inevitable. Both affect your organization today.

The question isn't whether your employees are using unapproved AI tools. They are.

The question is: what are you going to do about it?

Start with the survey. Map the findings. Make decisions. Write the policy.

Or take five minutes and use our free tool to get a picture of your exposure:

Take the PDPA AI Risk Check

You might be surprised by what you find.