Ask an owner what their business spends on AI and most name a subscription total. Ask what their staff actually use day to day and the answer is usually longer: a marketing coordinator's personal ChatGPT account, a bookkeeper's Gemini tab, a project manager's free-tier Claude account for drafting emails. None of it shows up on the finance report because none of it is paid for by the business. That does not make it free.
The three places the cost actually lands
Free internal AI is a fair description of what happens when a team adopts tools ahead of any formal decision. It works, mostly, which is why nobody stops it. But the cost has just moved off the P&L and onto three things nobody is tracking: data exposure, duplicated effort, and lost institutional memory.
Data exposure is the sharpest edge. A staff member pasting a client's financial summary into a personal free-tier account is not doing anything malicious. They are trying to get a Friday-afternoon task done. But that data may now sit inside a consumer product with different retention and training terms to whatever the business would choose if it were making the call deliberately. For a Sydney business handling client financial or health information, that gap matters under the Privacy Act even when no breach ever surfaces, because the exposure existed the moment the paste happened.
Duplicated effort is quieter but adds up faster. When five people in a 20-person business each work out their own way to get Claude or ChatGPT to draft a proposal, summarise a call, or clean a spreadsheet, the business pays for that learning curve five times over. None of the five shares their prompt, their template or their workaround with the others, because there is no shared place to put it. We have measured this directly with a Melbourne services client: three team members were independently solving the same weekly reporting task with three different free-tier setups, at a combined cost in reworked hours we costed at roughly $9,200 a year before anyone owned the workflow.
What a sanctioned setup actually buys back
The fix is not banning free tools. Staff will always route around a blocker if the sanctioned option is slower than the workaround. The fix is giving the workaround a home: one paid account structure, one place prompts and workflows get saved, and one person accountable for what data goes where.
A single business-tier subscription with proper data handling terms, typically $30 to $90 per seat per month depending on the plan and headcount
A shared prompt and workflow library so the third person solving a problem finds the answer in two minutes instead of two hours
A named owner for AI use, even a part-time one, who can answer 'is this okay to paste in' without an email chain
A short internal policy, one page is enough, covering what data classes are fine, borderline, or off-limits
None of this needs to be expensive or slow to stand up. A properly scoped rollout for a business under 30 staff typically costs $4,000 to $8,000 in one-off setup, plus the ongoing seat cost. Compare that to the $9,200 a year in duplicated effort from the Melbourne example above, and the case makes itself inside twelve months, before counting the risk avoided.
The honest audit question
There is also a slower cost that only shows up over a year or two: lost institutional memory. When a staff member who built a good ChatGPT prompt for drafting client proposals leaves the business, that prompt leaves with them. Nothing was captured anywhere the business owns. A new hire starts from zero on a task the business has effectively already solved twice. Multiply that across a handful of roles over a few years and the business has been quietly re-learning the same lessons on repeat, at a real cost in ramp-up time even if nobody ever put a dollar figure on it.
None of this is an argument for slowing staff down. Teams that reach for AI on their own initiative are usually your most capable people, not a compliance problem to be shut down. The point is that a business with 15 to 50 staff can bring that initiative inside a governed structure in a matter of weeks, at a cost that is smaller than the hidden cost of leaving it ungoverned, and end up with faster adoption, not slower, because the workaround stops being necessary.
If you want to know whether your business already has a free internal AI problem, the test is simple. Ask three people in different roles what AI tool they used last week for work, and what account it was under. If the answers are three different tools and three personal logins, the business already has an ungoverned AI footprint. The good news is that turning that into something accountable is usually a matter of weeks, not months, and Automata AI can run the audit and the fix as one engagement rather than two.



