Enterprise AI is entering a more demanding phase. The question is no longer whether organisations are using AI, but whether those investments are translating into measurable business value. As copilots, foundation models and autonomous agents move deeper into enterprise workflows, a new challenge is emerging: AI tokenism,deploying AI for the sake of adoption without a clear understanding of the outcomes it creates.
For CIOs and CISOs, this is becoming both a technology and an economics challenge. Unused licences, overlapping tools, expensive model choices, uncontrolled consumption and shadow AI can quietly drive-up costs even as organisations celebrate growing AI adoption. The shift towards agentic AI adds another layer of complexity, as autonomous systems can generate significant value while also increasing inference, compute, retrieval and tool-use costs.
In this conversation, Maya Ramchandran, Leader, Risk Market, EY India, explores where organisations are losing money, why visibility and telemetry are becoming essential to AI governance, how enterprises can make smarter model and workload choices, and what separates AI initiatives that deserve to scale from those that should be optimised, or stopped.

Leader, Risk Market
EY India
CISO Forum: You have previously spoken about the risks of AI—from shadow AI and agentic systems to visibility, access and control. Is “AI tokenism” now another risk enterprises need to confront: deploying AI without being clear about the value it is actually creating? From what you are seeing across enterprises, where is the biggest disconnect today between AI adoption and actual business impact?
Maya Ramchandran: AI tokenism is a very real risk: having AI is not the same as creating value with AI.
We have been advising clients on managing software spend, and the risks, inefficiencies and costs associated with shadow IT remain a challenge.
The use of AI has moved from experimentation to widespread access—copilots, models, APIs and increasingly agents—but the discipline around managing cost versus value has not kept pace. The biggest disconnect is perhaps between measuring adoption and measuring outcomes. A high number of users,prompts or deployed pilots may demonstrate activity, but it does not necessarily demonstrate business impact.
For example, an organisation might deploy a premium copilot across thousands of employees and celebrate strong activation. The more important questions are: Is it reducing cycle time? Improving quality? Eliminating manual work? Reducing risk? And is that benefit greater than the total cost of delivering it?
More often than not, newly empowered individuals develop and run their own bespoke AI solutions, creating redundancy and wastage.
That is why the conversation needs to move from “Who has AI?” to “What is AI delivering, and is the value sustainable?”
AI should earn the right to scale.
You cannot govern what you cannot see—and that applies equally to AI risk and AI costs.
CISO Forum: CIOs are under pressure to demonstrate AI ROI, but the cost side is often poorly understood. Where do you see enterprises wasting the most money in their current AI deployments?
Maya Ramchandran: The biggest AI cost problem is often not price, but mismatch.
Enterprises can risk wasting money when the capability they buy is significantly more sophisticated, or more widely distributed, than the workload requires.
There are several recurring examples: inactive licences that become shelfware, multiple overlapping AI tools serving the same users, and premium models becoming the default for routine tasks.
Imagine using a frontier model for every employee query when a smaller model could handle the majority of routine summarisation or classification tasks. The individual transaction may appear inexpensive, but at enterprise scale, the mismatch compounds.
AI waste is also architectural. Poorly designed vectorisation and retrieval can repeatedly embed, store or retrieve far more data than a use case needs. Inefficient applications can generate unnecessary API calls, oversized context windows and repeated model invocations. Duplicate agents may independently perform the same searches, reasoning and tool calls.
The expensive part is often not the model—it is everything we unnecessarily ask the model and its surrounding architecture to do.
The answer is not indiscriminate cost-cutting. It is intelligent routing—matching users, workloads, models and commercial arrangements to the value being created.
Don’t cut AI that creates value; cut the waste around it.
CISO Forum: You have talked about visibility and control as critical to managing AI risk. Should the same principle apply to AI economics—should enterprises have visibility into the cost of every model call, inference and AI interaction? You have highlighted shadow AI as a security and data-risk concern. Could uncontrolled employee use of AI also become an invisible cost problem for CIOs, with enterprises paying for AI usage they don’t even realise is happening?
Maya Ramchandran: You cannot govern what you cannot see—and that applies to all technology costs, whether software, hardware, cloud, services or AI.
Similarly, you cannot manage the risks associated with AI if you do not know where it is being used, what data it is accessing, which models and agents are operating, what actions they are taking, and who is accountable for them. Visibility is the foundation of both financial discipline and effective risk management.
That does not necessarily mean a CIO needs to inspect every individual prompt. In fact, metadata-level telemetry is often preferable. But organisations should increasingly understand run rate, active licence utilisation, premium-model consumption, high-cost users or workflows, agent activity, and the relationship between cost and business outcomes.
Shadow AI makes this particularly important. Employees may use overlapping subscriptions, expense-card tools or embedded AI capabilities outside centrally managed platforms. The result can be both an information-security blind spot and an economic blind spot.
The principle is simple: discover the estate, establish a baseline and attribute consumption.
The maturity test is not how many AI initiatives you launch. It is how you decide what deserves the next dollar.
CISO Forum: As organisations move from copilots to AI agents, does greater autonomy make the business case for AI stronger, or does it make the risk of AI tokenism and uncontrolled cost even greater?
Maya Ramchandran: Agents raise the ceiling on AI value—but they also remove some of the natural brakes on AI consumption.
A copilot typically responds when someone asks it to do something. An agent can plan, retrieve information, call tools, retry tasks and continue executing with considerably less human intervention.
That autonomy can strengthen the business case enormously where an agent genuinely removes end-to-end work rather than simply assisting with one step. But it also changes the economics. Agentic costs can include model inference, retrieval, memory, tool calls, compute and repeated attempts—not simply one visible interaction.
For example, an agent that autonomously resolves routine service requests could create significant value. An inadequately designed agent repeatedly searching, reasoning and retrying a failed task could simply “automate” expenditure.
We have already seen how quickly autonomy and consumption can change AI economics. In one reported case, an organisation’s planned 2026 spend on AI coding tools was fully utilised within four months as usage accelerated across its engineering workforce. Importantly, this was not simply people “misusing” AI; the tools were being used for legitimate activities such as coding, testing, refactoring and running multiple agents. The challenge was that consumption scaled much faster than the economics had been modelled.
Greater autonomy needs greater observability: budgets per workflow, limits on retries and runtime, appropriate model routing and clear escalation points.
Autonomy without accountability is not transformation; it is amplification.
CISO Forum: EY works with enterprises across technology and risk. What are you seeing the most mature organisations do differently when they decide which AI initiatives to scale, optimise or kill?
Maya Ramchandran: Mature organisations treat AI as a portfolio of investments, not a collection of exciting experiments. The difference is discipline.
EY has helped organisations start by defining the business outcome and the evidence that would demonstrate success. We help establish telemetry and baselines, identify unused licences and duplicated capabilities, and examine whether the architecture and model are appropriate for the workload.
Organisations need to align consumption and cost with measures such as cycle-time improvement, work completed, quality, adoption or risk reduction.
We help organisations establish the governance and frameworks to be comfortable making three decisions: scale something that demonstrably creates value; optimise something valuable whose economics are wrong; or stop something that cannot justify continued investment.
A lot of these processes and frameworks need to be incorporated into standard Software Asset Management processes, with data analysis and reporting automated across technology ecosystems.
The maturity test is not how many AI initiatives you launch. It is how you decide what deserves the next dollar.
CISO Forum: If you were sitting with a CIO and CISO today and they told you, “We have dozens of AI initiatives, but we aren’t sure which ones are truly delivering value,” what would you ask them first?
Maya Ramchandran:My first question would be: “What business outcome was each initiative intended to change, and what evidence do you have that it is changing it?”
That immediately shifts the conversation from AI activity to AI accountability. I would then connect four things: ownership, consumption, cost and outcome. Who owns it? Who is using it? What is the true cost, including licences, models, infrastructure, API calls and agent activity? And what measurable difference is it making?
Take an AI coding initiative. Telling me, “We have 2,000 licences,” measures deployment, not value. I would want to understand meaningful active usage, overlapping tools, the impact on development or review cycle times, and ultimately what we are paying for those outcomes.
But this cannot be a one-time exercise. Enterprises need an ongoing process to inventory AI initiatives, establish baselines, assign accountable owners, measure cost and value, and periodically decide whether to scale, optimise, consolidate or stop them.
As AI evolves, those decisions need to become part of the operating rhythm, not an annual clean-up exercise.
Not every experiment needs an immediate financial return, but every initiative should have a clear hypothesis, success measure, owner and decision point.
AI value is not something you measure once, it is something you continuously manage.
