A new research report from Bithost looks at how small IT companies are quietly shifting the cost of AI tools onto their own employees.
Download The Full Report

Most small software companies today want their teams to work faster. They have heard the productivity promises around AI. Some have started telling their developers to "use AI" on projects. What they have not always done is pay for it.
So who is paying?
The developers are.
We spent several weeks researching this question properly, across India, the UK, Singapore, and the US. We pulled data from actual surveys, government reports, and published research. We looked at pricing, legal implications, security risks, and real incident cases. The result is a 26-page report we are publishing today.
Here is what we found.
Most developers use AI. Most companies have not officially provided it.
According to the Stack Overflow Developer Survey 2025, which covered over 49,000 developers worldwide, 84% of developers either already use AI tools or plan to start using them. That number keeps climbing.
But here is the gap: most small companies have not formally decided which AI tools to provide, or paid for a company account.
What happens in that gap? Developers sort it out themselves. They sign up with their personal email. They pay out of their own pocket. They use whatever tool they are already familiar with on their personal devices. And they get the work done.
78% of employees using AI at work are using their own personal accounts.
That figure comes from Microsoft and LinkedIn's Work Trend Index 2024, which surveyed 31,000 people across 31 countries. Among small businesses specifically, that number is 80%.
This practice even has an official name in research circles. It is called BYOAI, which stands for Bring Your Own AI.
The company gets the output. The employee pays the subscription fee. Nobody talks about it.
This creates real problems that most people are not thinking about.
The data problem. Consumer AI accounts like free ChatGPT or a personal Claude subscription are not the same as business accounts. When an employee pastes code or client information into a personal AI tool, that data may be used to train future AI models. The company has no control over this. Research published in 2025 found that 43% of employees have pasted sensitive or confidential data into an unapproved AI tool.
The security problem. IBM's research found that when Shadow AI contributes to a data breach, it adds an average of $670,000 to the total cost. And only 18% of companies currently have any written AI security policy at all.
The legal problem. In several places, including California in the US, employers are legally required to reimburse employees for necessary work expenses. If a developer's personal ChatGPT Plus subscription is genuinely required to do their job, that could be a reimbursable expense that the company has not been paying.
The pressure problem. Managers have noticed that AI tools exist and some have quietly raised delivery expectations. But 77% of employees in a 2024 to 2025 industry tracking study said AI tools have actually increased their workload and stress, not reduced it.
The good news: this is fixable, and it does not have to be expensive.
The report calculates four scenarios for a small company with 15 developers. The most expensive option, which is paying for proper business-tier AI subscriptions for the whole team, costs around 7,920peryear.Thatislessthan7,920peryear.Thatislessthan660 a month.
The cheapest-looking option, which is doing nothing and letting developers use their own tools, costs the company nothing on paper. But it carries the legal, security, and data risk described above. And it shifts around $4,800 per year in costs directly onto developers.
The middle options work well too. The report covers all four scenarios in detail.
What to do if you run a small IT company
You do not need to solve this overnight. The report lays out a practical starting point.
Write down which AI tools you are okay with your team using. Decide whether you will pay for subscriptions or reimburse people who do. Tell your team that client code and client data should never go into a personal AI account. That one rule alone closes a significant part of the risk.