Discovery shows you the scope rather than the logo. An application holding read access to every file in Drive is a different problem from one that reads a calendar, and you see who granted it, when, and what it has touched since.
That framing is the useful one. Shadow IT is usually framed as a spending problem. It is mostly an access problem.
The subscription is the visible part and generally the smaller one. The part that matters is that somebody clicked "Sign in with Google" and granted an application read access to all their mail, and that grant is still live 18 months later.

Apps in use that nobody told IT about, and what each one can reach.
Why it happens
Because it works. Somebody needed a transcription tool on a Tuesday, procurement takes 3 weeks, and the trial took 90 seconds.
Treating that as misconduct is both wrong and unhelpful. It is a signal that the sanctioned path is slower than the need.
What to actually look at
The scope, not the app. A tool with read access to all files is a different problem from one that reads a calendar, even if both are unsanctioned.
Who granted it. One person granting on their own behalf is a smaller blast radius than an admin granting domain-wide.
Whether anybody still uses it. Most of what discovery finds is abandoned, and abandoned-with-a-live-token is the worst combination.
Whether it holds company data. An app nobody uses that still has a copy of last year's customer list is a breach waiting for somebody else's incident.
What happens next
Three outcomes, and only one of them is shutting it off.
Sanction it, which means connecting it so it joins lifecycle and reviews like everything else. Replace it with whatever you already pay for that does the same job. Or revoke it, which for an OAuth grant means killing the token rather than cancelling a subscription.
What still needs a person
Deciding which bucket each app goes in. That is a judgement about how your company works, and it is worth having the conversation with the person who signed up rather than about them.