GreenPT Advisory
Sources and methodology
Why this page exists
We sell measurement. That means our own figures have to be traceable.
Below is every figure on the Advisory page: where it comes from, what exactly was measured, how large the sample was, and where the research falls short. We link to the original report, not to news coverage of it.
15% of software spend is managed directly by IT
Source: Zylo, SaaS Management Index 2026
What was measured: ownership of software spend within organisations, split across IT, business units and individual employees. Zylo reports 15% for IT, 81% for business units and 4% for applications expensed by individuals. IT also owns 13% of the application count.
Scale: analysis of more than 40 million software licences and 75 billion dollars in spend under management. Some findings in the same report come from a separate survey of 218 IT leaders.
Limitation: the data comes from Zylo's customer base and consists mainly of large American companies. Public bodies and organisations outside North America are underrepresented, and procurement practice varies widely by region and sector. Zylo sells software for managing this problem.
+267% growth in software spend through expense reports
Source: Zylo, SaaS Management Index 2026
What was measured: the year-on-year increase in software spend entering the organisation through expense claims rather than procurement. ChatGPT is the most expensed application in this report.
Limitation: as above. In addition, expense claims are only visible where they reach the expense system. Spend on a departmental card booked as a single line falls outside this measurement. The real figure is probably higher.
47% of AI users work through a personal account
Source: Netskope, Cloud and Threat Report 2026
What was measured: the share of generative AI users accessing tools through personal, unmanaged accounts, either exclusively or alongside company-approved tools.
Scale: anonymised telemetry from millions of users worldwide, collected between October 2024 and October 2025.
Limitation: telemetry only sees traffic passing through Netskope's infrastructure. Use on personal devices or off the corporate network is not counted. The data is global but not broken out by region or sector. Netskope sells security software for this problem.
64% of AI vendors name no AI subprocessor
Source: DataGrail, Privacy and AI Trends Report 2026
What was measured: the legal documentation of software vendors, checked for whether a third-party AI subprocessor is disclosed. Among vendors that prominently advertise AI capabilities, 63.6% do not disclose one.
Scale: analysis of 2,400 widely used business software providers.
Limitation: this is an analysis of vendors, not of organisations. It says nothing about how many of your own vendors are affected, only that the odds of it being more than one are high. DataGrail sells privacy software.
63% of breached organisations have no AI governance policy
Source: IBM and Ponemon Institute, Cost of a Data Breach Report 2025
What was measured: the presence of AI governance policy at organisations that experienced a data breach. 63% have no policy or are still developing one. Of those that do have a policy, 34% regularly audit for unsanctioned AI use. One in five organisations reported a breach involving shadow AI, at an average of 670,000 dollars in additional cost.
Scale: 600 organisations globally, 16 countries, 17 industries, breaches between March 2024 and February 2025. Conducted by Ponemon Institute, sponsored and analysed by IBM.
Limitation: this one matters. The sample consists only of organisations that suffered a breach. The figure therefore does not say that 63% of all organisations lack a policy. It says organisations without a policy are overrepresented among those that were breached, which is a different and weaker claim.
Three limitations that apply to every figure
Vendor interest. Three of the five sources are companies selling software for the problem they measure. We use them because their datasets are by far the largest publicly available, and because the findings corroborate each other across independent sources. But that interest exists, and you should know about it.
No breakdowns. Most research on this subject comes from the United States. The IBM study is global and covers sixteen countries, but publishes no regional breakdown. None of these sources breaks out results by sector, organisation size, or public versus private. An average across thousands of organisations therefore says little about yours, however large the dataset.
Definitions vary. What counts as an AI tool differs by study. Some count only standalone AI services, others every application with an AI feature. Published counts therefore range from roughly ten to several dozen per organisation. This is why we quote no average tool count on the Advisory page.
What we measure ourselves
We run gap analyses at organisations and public bodies across Europe and North America. Those measurements belong to our clients and we do not publish them without consent.
Once we have enough measurements to report on them responsibly, we will publish an anonymised baseline together with the methodology. We will call it a baseline and not a benchmark, because the sample is too small for that. We will only publish breakdowns by region, sector or organisation size where we have at least five measurements per category, so that individual organisations cannot be identified.
Corrections
This page was last checked on 23 July 2026.
If something is wrong, a report has been updated, or we have misrepresented a figure, email hello@greenpt.ai. We will correct it or remove it, and note the change on this page.