Enterprise Adoption2 min read

Barracuda CIO Builds AI Council to Curb Shadow AI Use

By , Senior AI ConsultantPublished

Barracuda's CIO Siroui Mushegian set up a cross-company AI governance council to control which AI tools staff use, warning that surprise token based billing and unauthorized tool use are two of the biggest risks facing companies adopting AI fast.

Barracuda's chief information officer, Siroui Mushegian, has a problem that almost every company with more than a handful of employees now shares. Staff are using AI tools on their own, without asking IT first, and nobody has a full picture of what data those tools are touching.

This is not a small or unusual issue. Research on this exact problem shows the scale of it: most office workers admit they use AI tools without getting approval from their IT department, and a meaningful share of businesses have already had data leaks tied to unapproved AI use. Separate research from Gartner found that most organizations suspect or have proof that employees are using AI tools that were never cleared for use.

Mushegian's answer was to build an AI council inside Barracuda, which she chairs herself, with separate working groups for sales and marketing, for product and engineering, and for legal and compliance. The goal is not to slow people down. It is to know what tools exist, who can access them, and what data they touch, so that a new AI tool does not quietly show up in one department without anyone else knowing.

The money risk she flags deserves attention from anyone who signs off on software budgets. AI tools used to work like most software: you pay a license fee and that is the cost. Now many run on a pay per use model, where the price depends on how much text or work the AI processes, measured in units called tokens. The bill only shows up after the fact, and it can move fast. Reporting this year found that a large share of IT leaders have already been hit with charges they did not expect from this kind of pricing, and some companies have watched their AI spending triple within a year without a matching increase in output.

This is exactly the situation Mushegian is trying to head off. Her fix is simple in concept: show the cost of an AI task to the manager approving it, before the work runs, not after. That is a basic budgeting habit that most software never needed because the price was fixed in advance. AI breaks that assumption, and companies that do not adjust their approval process will keep getting billing surprises.

Her broader worry, regulation, is also worth taking seriously. The largest AI companies spend heavily on lobbying and meet with government officials at a high rate, and researchers tracking this have raised concern that the companies shaping the rules are the same ones the rules are supposed to govern. If regulation ends up written mostly by the biggest AI firms, it may protect their market position more than it protects the businesses buying their tools.

Barracuda itself is owned by the investment firm KKR, after a prior sale from Thoma Bravo, so this is a private, profit focused company managing AI risk under its own judgment rather than under public market pressure. That makes Mushegian's approach a useful template: not a ban on AI, not a free for all, but a standing group that tracks tools, flags cost before it happens, and stays ready to change the rules as the technology and the regulatory picture keep shifting. Any company without something like this in place is likely already carrying more shadow AI risk than it realizes.


STAY INFORMED

Get AI intelligence like this delivered to your inbox.

Free forever · Unsubscribe anytime


You May Also Find Valuable