AI Governance Starts with Knowing Who's Using AI and What It Costs
6 min read | Published


Most organizations think they can see their AI footprint. A 2026 survey of over 650 senior enterprise security leaders found that 90% believe they have visibility into AI usage across their organization, yet 59% simultaneously confirm or suspect shadow AI is running somewhere inside it (Purple Book Community / ArmorCode, State of AI Risk Management 2026). AI governance does not start with audit trails or compliance frameworks. It starts with closing that gap: knowing who is using AI, in which workspaces, and what it costs.
This guide covers what to track first, how usage visibility relates to frameworks like the EU AI Act and NIST's AI Risk Management Framework, and why cost tracking is its own governance problem, not a footnote to it. For the broader picture of AI observability, see What Is AI Observability? A Practical Guide; for the agent-behavior side specifically, see AI Agent Observability; for the build-vs-buy tooling decision, see AI Observability Tools: Do You Need a Separate One?
Key Takeaways
- 59% of security leaders confirm or suspect shadow AI in their organization, even though 90% believe they already have visibility, a gap that usage tracking closes first.
- AI governance starts with adoption and usage visibility (who, where, how much), not with deep audit trails or compliance automation.
- Regulatory frameworks like the EU AI Act and NIST's AI RMF matter, but usage visibility supports that compliance work rather than satisfying any specific regulation on its own.
- Token-based pricing means AI cost scales with usage in ways that are easy to lose track of without per-workspace or per-user breakdowns.
- 52% of organizations still lack a formal AI governance framework, despite near-universal AI adoption (Cycode, State of Product Security for the AI Era 2026).
Why AI Governance Starts with Usage Visibility, Not Audit Trails
The confidence gap in AI visibility is not a minor data quality issue. When 90% of security leaders believe they have AI visibility but 59% also confirm or suspect shadow AI, the problem is not that organizations lack governance ambitions; it is that they are governing AI they cannot fully see. Separate research puts a number on how common this is at the foundation: 52% of organizations still lack a formal AI governance framework despite AI now running in nearly every business function (Cycode, 2026).
This is why usage visibility, not audit trails or policy documents, is the practical starting point. An audit trail answers "what happened in this specific interaction." A governance policy answers "what should be allowed." Usage visibility answers a more basic question that has to come first: "is AI running here at all, and how much." Without that baseline, both audit trails and policies are being applied to a footprint nobody can fully confirm.
For data and analytics leaders specifically, this usually shows up as a resourcing question before it shows up as a compliance question: which teams are actually using AI features, is that usage growing, and where should governance attention go first. Usage data answers that with evidence instead of assumption.
What to Track: Adoption, Usage, and Cost per Workspace and User
At the governance level, three categories of usage data matter most, and all three need to be broken down by workspace and user, not just reported as an organization-wide total.
Adoption. How many workspaces or teams have at least one active AI user, and how many users have triggered at least one AI action in a given period. This helps close the visibility gap for AI activity within the systems and workspaces you monitor.
Usage volume. How many AI actions or queries ran, broken down by workspace and by user. A single workspace generating a disproportionate share of activity is worth knowing about before it becomes either a scaling success story or a governance blind spot. This is also the data point most likely to feed into broader business KPIs once AI adoption becomes something leadership tracks alongside other operational metrics.
Cost. Token usage and query costs, broken down the same way. Token consumption is the leading indicator here: aggregate spend tells finance what was spent; per-workspace and per-user breakdowns tell governance where it was spent and whether that matches expected usage.

Meeting EU AI Act, NIST AI RMF & GDPR Requirements
Regulatory frameworks are a major driver of AI governance investment, but usage visibility is best understood as a foundation for compliance work, not a substitute for it. The table below maps what usage visibility supports under each framework, and where it stops.
| Framework | What usage visibility supports | What it does not cover |
|---|---|---|
| EU AI Act | Evidence about where AI is deployed, who uses it, and operational usage patterns that can support monitoring and risk-management processes | Documentation, human oversight, and conformity requirements for high-risk systems |
| NIST AI RMF | Supports MAP by establishing usage context and MEASURE by providing operational evidence for monitoring and assessment | The broader governance, risk identification, prioritization, treatment, and organizational processes across GOVERN, MAP, MEASURE and MANAGE |
| GDPR | Helps identify where AI systems process personal data | Data minimization design, consent mechanisms, and the right to explanation for automated decisions |
The EU AI Act's timeline is worth knowing because not all provisions apply at the same time. The Regulation became generally applicable on August 2, 2026, but the core requirements for high-risk systems have later dates: Annex III use cases apply from December 2, 2027, and Annex I systems embedded in regulated products from August 2, 2028 (European Commission, AI Act Service Desk; Digital Omnibus on AI). NIST's AI Risk Management Framework, by contrast, is voluntary guidance rather than binding law, and GDPR predates most AI-specific regulation but still applies wherever AI systems process personal data.
None of these frameworks are satisfied by usage visibility alone, but knowing who used AI, where, and how much is the evidence base the rest of a compliance program, including auditability and audit trails, depends on. For a broader framework covering accountability, policy infrastructure, and risk management, see GoodData.AI's enterprise blueprint for AI governance.
Discover how GoodData.AI helps you build, govern, and scale analytics, AI, and agents from one platform.
Request a demo
Why Token-Based Cost Is Its Own Governance Problem
Traditional software costs scale with seats or infrastructure, both of which are easy to forecast and cap. Token-based AI pricing scales with usage in a way that is far less predictable: a single workspace running more complex queries, longer conversations, or a newly popular AI feature can shift monthly cost significantly without anyone making an explicit decision that should happen.
This creates a specific governance problem: cost overruns in AI systems often are not the result of misuse or a security incident, and rarely rise to the level of compliance violations on their own. They are the natural result of adoption succeeding faster than expected, in a pricing model where nobody set an upper bound. Without per-workspace or per-user cost breakdowns, that pattern is invisible until the total bill arrives, at which point the conversation shifts from governance to damage control.
Treating cost visibility as a governance function, not just a finance one, changes when the conversation happens. A governance team watching cost trends per workspace can flag an unusual spike while it is still a data point, not after it becomes a budget escalation. Inference cost, model choice, and architecture decisions add another layer to this; for a deeper technical look at what drives AI inference cost in production, see The Hidden Cost of AI Analytics.

How GoodData.AI Approaches AI Usage Visibility Today
GoodData.AI approaches AI usage visibility as part of the analytics environment itself rather than as a separate governance data pipeline.
GoodData.AI Observability provides organization administrators and analytics engineers with a ready-made view of AI activity across their GoodData organization. It tracks adoption and usage across users and workspaces, conversations, agent activity, reliability, errors and timeouts, token consumption, and usage trends.
The observability data is collected automatically as users interact with GoodData AI features and is exposed through a standard GoodData workspace. Teams can therefore explore the managed dashboards, filter the data, or extend the provided analytics with their own metrics and visualizations.
This provides a useful operational foundation for AI governance: teams can see where AI is being adopted, which users and workspaces are generating activity, how different agents are being used, and where unusually high token consumption or reliability issues appear.
Where to Go From Here
AI governance that starts with usage visibility gives an organization something audit trails and policy documents cannot: a factual answer to whether AI is being used, where, and by whom, before deciding what to govern more deeply. That answer is also the fastest one to get, since it does not require instrumenting every interaction before it delivers value.
If your team owns AI governance and wants usage data broken down by workspace and user without standing up a separate stack, see how GoodData.AI's agentic analytics platform surfaces AI usage out of the box, or request a demo to see it in action.
Discover how GoodData.AI helps you build, govern, and scale analytics, AI, and agents from one platform.
Request a demo
Frequently Asked Questions
Usage visibility: knowing who is using AI, in which workspaces, and how much. This closes the gap between organizations that believe they have AI visibility and the shadow AI that often exists anyway, and it is the evidence base that later governance and compliance work depends on.
Not by itself. Usage visibility supports compliance work by providing the evidence base for risk assessment and monitoring, but the EU AI Act's requirements for high-risk systems, which apply from December 2, 2027 (Annex III) and August 2, 2028 (Annex I), involve additional obligations around risk management, documentation, and human oversight that usage data alone does not cover.
Shadow AI is AI tool usage inside an organization that runs outside official approval, monitoring, or governance processes. It is common even in organizations that believe they have full visibility into their AI footprint; a 2026 survey found 59% of security leaders confirm or suspect it despite 90% reporting confidence in their visibility.
Because token-based pricing scales with usage in ways traditional software licensing does not. A single workspace can generate a disproportionate share of AI spend without anyone deciding that should happen, and without per-workspace or per-user cost breakdowns, that pattern stays invisible until the bill arrives.
No. It is voluntary guidance, unlike the EU AI Act, which is binding law. Organizations use it as a structured approach to identifying and managing AI risk, organized around functions for governing, mapping, measuring, and managing risk.
It typically starts with data and analytics leaders, since usage visibility answers governance and resourcing questions before it becomes a compliance or legal matter. As AI governance matures, ownership often expands to include compliance, security, and finance stakeholders working from the same usage data.





