For the last few years, the risk of employees pasting company data into public AI tools had been argued as a matter of principle. Someone in security wrote a memo, someone in legal nodded, and the tools stayed in a grey zone that nobody measured. That argument is over. IBM’s 2026 Cost of a Data Breach report attaches a figure to it: breaches that involve shadow AI cost an average of $670,000 more than breaches at organizations with little or none of it, and one in five companies surveyed traced an attack back to shadow AI in the first place.1
A number like that changes who has to care. A governance gap is a problem for the security team. A $670,000 line on top of an already expensive incident is a problem for whoever signs off on the budget. Shadow AI has crossed from the first category into the second, and most leadership teams have not updated their mental model to match.
What the number measures#
The premium is not a fine or a hypothetical. IBM built it from interviews with 600 breached organizations, comparing the total cost of incidents where unsanctioned AI use played a role against those where it did not. Shadow AI breaches also ran slower and dirtier. They took 247 days to identify and contain, six days longer than the baseline, and customer personal data turned up in 65 percent of them, against 53 percent across all breaches.2 More exposure, more time on the clock, more cost. The three move together because they share a cause: nobody was watching the tool, so nobody caught the leak early.
The report is blunt about why. Among organizations that suffered an AI-related breach, 97 percent lacked proper access controls on the AI tools involved, and 63 percent had no AI governance policy at all.3 These are the same access-control and inventory basics that security teams have preached for two decades, applied to a new class of tool that arrived faster than the controls did.
The adoption curve outran the policy#
The reason this is hard to contain is that shadow AI is not a fringe behavior. Verizon’s 2026 Data Breach Investigations Report found that employee use of unapproved AI tools jumped from 15 percent to 45 percent of staff in a single year, which made it the third most common non-malicious cause of data leakage the report tracks.4 Two out of three of those users reached the tools through personal accounts rather than anything the company provisioned.5
Browser-level telemetry sharpens the picture. Data from enterprise security vendor LayerX found that 77 percent of employees paste data into generative AI prompts, and 82 percent of that copy-paste activity flows through personal, unmanaged accounts. The same dataset estimates that organizations have no visibility into roughly 89 percent of the AI usage happening inside their own environment.6 Read those together and the governance problem becomes concrete. Nearly half your people are using these tools, most are doing it through accounts you cannot see or revoke, and the single most common data type they feed in is source code.6
That last detail matters more than it looks. When a marketing draft goes into a chatbot, you lose a paragraph. When source code goes in, you lose intellectual property, embedded credentials, and a map of how your systems are built.
The data leaving the building is often the most sensitive you hold.
Samsung was the warning, not the exception#
The canonical case is still Samsung’s, and it is worth remembering precisely because the company was not careless. In 2023, engineers in its semiconductor division were permitted to use ChatGPT to help with work. Within about a month there were three separate incidents: an engineer pasted in confidential source code to check for errors, another submitted code meant to identify defective equipment, and a third uploaded a recording of an internal meeting to generate minutes.7 None of it was malicious. All of it was gone the moment it hit a third party’s servers. Samsung responded by restricting generative AI on company devices and capping how much text staff could submit at once.7
The instructive part is that Samsung had already granted access on purpose and still could not see what was happening until the data was out. That is the shape of the problem in almost every organization now. The failure is that the tools people reach for sit outside anything the company can monitor, log, or switch off, and the sensitive material moves in seconds through a browser tab that leaves no trace on the corporate network.
The leadership gap underneath it#
It is tempting to frame shadow AI as an employee discipline issue and reach for an acceptable-use policy. The IBM data argues against that instinct. Fewer than half of organizations that had an AI governance policy actually ran an approval process for new AI deployments, and only 34 percent regularly checked their networks for unauthorized tools.3
A policy that no one enforces and no one measures is not a control. It is a document that shifts blame downward while the actual exposure sits with whoever chose not to fund detection.
There is also a demand signal underneath the behavior that leaders keep ignoring. People turn to unsanctioned tools because the sanctioned options are slow, restricted, or missing. When 45 percent of staff route around IT to get to AI, the honest reading is that the official toolset is not meeting the work.
Banning the tools without offering a real alternative simply pushes the same activity further out of view, onto personal phones and home laptops where you have no visibility at all.
What to do before the next audit#
The organizations that come out of this well are the ones that made the activity visible and gave it somewhere safe to happen. A practical sequence looks like this:
See it first. You cannot govern what you cannot measure. Get real telemetry on AI usage through browser controls, network monitoring, or a cloud access broker, and accept that the true footprint will be larger than anyone estimated. The 89 percent blind spot is the number to attack.
Sanction a genuinely useful tool. Give staff an enterprise-grade option with data protection terms that keep prompts out of training sets, and make it good enough that the free alternative is not worth the risk. Adoption of the safe path is your best defense against the unsafe one.
Put access controls on the AI itself. Treat AI tools like any other system that touches sensitive data: identity-based access, logging, and the ability to revoke. The 97 percent who lacked this are the cautionary group, not a peer set to match.
Classify what can and cannot go in. Not all data carries equal risk. A clear, short rule that source code, customer records, and unreleased financials never enter external models is easier to follow than a blanket prohibition everyone quietly ignores.
Extend DLP to the prompt. Data loss prevention that inspects email and file transfers but ignores the text box in a browser is now looking in the wrong place. The leak has moved to the paste.
Write the number into the risk register. Put the $670,000 premium in front of the board next to your current AI exposure. Budget conversations move faster when the risk has a price attached.
Whether to allow AI at work is no longer the strategic question for the next 12 months. That decision has already been made by your staff, at scale, whether or not it was ever approved. What remains open is whether you will be able to see it. Every organization now runs an AI program. The only variable is whether it is one you manage or one that manages itself in the dark, at a cost that IBM has already put on the record.
“‘Shadow AI’ increases cost of data breaches, report finds,” Cybersecurity Dive, on IBM’s 2026 Cost of a Data Breach Report. https://www.cybersecuritydive.com/news/artificial-intelligence-security-shadow-ai-ibm-report/754009/ ↩︎
“The True Cost of a Shadow AI Breach: $670K On Top, 247 Days to Detect, 65% PII Exposure,” DeepInspect, summarizing IBM’s 2026 report. https://www.deepinspect.ai/blog/shadow-ai-breach-cost ↩︎
IBM 2026 Cost of a Data Breach Report findings on AI access controls, governance policy, and network monitoring gaps, as reported by Cybersecurity Dive. https://www.cybersecuritydive.com/news/artificial-intelligence-security-shadow-ai-ibm-report/754009/ ↩︎ ↩︎
Verizon 2026 Data Breach Investigations Report, Verizon Newsroom. https://www.verizon.com/about/news/breach-industry-wide-dbir-finds ↩︎
“2026 DBIR Shadow AI Findings,” LayerX, on the Verizon DBIR figures for personal-account AI use. https://layerxsecurity.com/learn/dbir-2026-shadow-ai/ ↩︎
LayerX enterprise browser telemetry on copy-paste into GenAI, unmanaged accounts, visibility gaps, and most-submitted data types. https://layerxsecurity.com/learn/dbir-2026-shadow-ai/ ↩︎ ↩︎
“A Case Study on Samsung’s ChatGPT Incident,” HumanFirewall. https://humanfirewall.io/case-study-on-samsungs-chatgpt-incident/ ↩︎ ↩︎
