Somewhere in your organisation, right now, someone is using an AI tool you’ve never heard of, on an account you didn’t set up, to do a piece of their job faster.
I don’t say that to alarm anyone. I say it because in nearly every client environment I’ve worked in over the past couple of years, it’s simply true. Someone in finance is summarising a supplier contract in ChatGPT. Someone in marketing is running customer feedback through a free sentiment tool. Someone in HR is drafting a sensitive email with help from an AI assistant on their phone, because the sanctioned tool is slower or doesn’t do what they need.
None of this comes from bad intent. It comes from people trying to do good work quickly, in organisations that haven’t yet given them an approved way to do it. The industry has a name for the pattern: shadow AI. It’s the AI-era version of the shadow IT problem that’s existed for twenty years, except this version moves data out of the building far more easily, and far less visibly, than a rogue spreadsheet ever did.
What it actually costs
IBM’s Cost of a Data Breach Report, published at the end of July, is the most rigorous attempt yet to put a number on this. Drawing on around 600 breached organisations across 16 countries, it found that breaches involving a high level of shadow AI cost an average of $670,000 more than breaches where it wasn’t a factor. Shadow AI was present in one in five of all the breaches studied.
That’s a striking number on its own, but the detail underneath it is more useful than the headline. 97% of organisations that suffered an AI-related security incident had no proper AI access controls in place. 63% had no AI governance policy at all, not a weak one, none. Nearly two-thirds of affected organisations hadn’t even attempted to write the rules down.
Of the organisations that suffered an AI-related incident, then, the failure sits in oversight far more than in the technology itself. And separate telemetry from Netskope’s most recent Cloud and Threat Report backs up how fast this has grown. Generative AI users across the organisations it monitors grew 200% year on year, and the volume of prompts sent to these tools grew roughly sixfold. Nearly half of users were still accessing these tools through personal, unmanaged accounts, the exact pattern IBM’s breach data flags as the highest-risk one.
Why banning it doesn’t work
The instinctive response, block the tools, feels sensible and almost never survives contact with reality. I’ve watched organisations try it. Staff don’t stop needing to summarise a document or draft a difficult email quickly. They just switch to their phones, off the corporate network entirely, and now you’ve lost the small amount of visibility you had.
The more durable fix is less dramatic and more useful: know what’s actually being used, and give people a properly governed alternative that’s good enough that they’d rather use it than the free version on their own account. That’s a governance and change-management problem as much as a technical one, and it’s exactly the kind of problem that gets solved by someone actually asking the question, out loud, in a leadership meeting, rather than assuming IT already has it covered.
Three questions worth asking this week
If you’re a CTO, CIO or CISO reading this, here are three questions I’d genuinely put in front of your next leadership meeting, in this order.
First: what AI tools have our staff actually used for work in the last month, whether we approved them or not. If nobody can answer this with any confidence, that’s the finding, not a gap in the question.
Second: if someone pasted client data into a free AI tool tonight, would we ever find out. Be honest about the answer.
Third: do we have one sanctioned AI tool that’s genuinely good enough that people would choose it over the free alternative. If the honest answer is no, that’s usually where the actual investment needs to go, not in more restrictive policy.
None of this requires a large programme or a six-figure budget to start. It requires someone willing to ask an uncomfortable question in a room where the polite assumption is that everything’s under control. In my experience, that’s usually the person who ends up owning the fix, whether or not it was ever formally their job.
Sources:
IBM, Cost of a Data Breach Report 2025 (with Ponemon Institute; ~600 organisations; breaches March 2024–February 2025; published 30 July 2025).
Netskope, Cloud and Threat Report: 2026.

