Why “One AI Tool per Department” Becomes a Problem

It usually happens without a decision being made. Marketing signs up for a writing tool. Support trials a chatbot. Someone in finance is using a document reader. Each is inexpensive, each solves a real problem, and each was adopted sensibly by people trying to do their job well.

Two years later, the company has a problem that nobody chose.

Nobody can answer where the data went

The first symptom appears when a customer asks a straightforward question: has our information been processed by any AI service, and where?

Answering requires knowing which tools are in use, what was put into them, where each provider processes data, whether a processing agreement exists, and whether inputs are used for model training. If tools were adopted independently, this information does not exist anywhere in the company. Assembling it retroactively means interviewing everyone and hoping they remember.

Under GDPR, you are expected to know this about your processors. "Several departments signed up for things" is not a defensible position.

You pay several times for the same capability

Four departments with four subscriptions to broadly similar capabilities pay four per-seat prices, four minimum commitments, and four sets of administrative overhead. The individual costs stay under the threshold that triggers scrutiny, which is precisely why it persists.

Knowledge does not accumulate

This is the cost that hurts most in the long run and shows up least in any budget.

When each department has its own tool, whatever is learned — which prompts work, how to structure a document, what the system is bad at — stays inside that department. The same discoveries get made independently four times. Worse, the useful configuration lives in individual accounts, so when someone leaves, it leaves with them.

Security posture becomes uneven

One tool is connected to company identity with multi-factor authentication. Another is a personal account with a shared password. When someone leaves the company, IT can revoke the first and does not know about the second.

Your security is set by the weakest of these, and you do not have an inventory of them.

The answer is not banning things

The instinct is to prohibit unapproved tools. This reliably fails, because the underlying need is real. People adopted these tools because they helped. A ban without an alternative produces the same usage, now hidden.

The workable answer is to provide a sanctioned capability that is genuinely good enough, under contracts you control, reachable through your own identity system — and then to make the sanctioned route the easiest one.

What consolidation actually gives you

One place where access is granted and revoked with employment. One processing agreement rather than an unknown number. One answer to the customer question. One place where the useful patterns are shared instead of rediscovered.

And, in practice, a much better negotiating position, because you are buying one thing deliberately rather than several by accident.

If it has already happened

Start with an inventory rather than a policy. Ask each team, without blame, what they use and what it does for them. You will find tools nobody knew about, and you will find at least one that is genuinely worth keeping. Then decide what the sanctioned route is, and migrate the useful cases to it before switching anything off.

All Articles
Let’s Talk

about the process
AI should run.