← Back to library
SecurityOpen4 min read · 1 exercise

Shadow AI Now Shows Up in 43% of AI Breaches: Give Your Team a Legal Way to Do the Job

IBM's 2026 breach report says unapproved AI tools now factor into 43% of AI-related incidents, more than double last year. Banning tools does not work. Here is the 20-minute exercise that closes the gap where shadow AI actually lives.


What shipped. IBM's Cost of a Data Breach 2026 landed, built on 602 organizations that were breached between March 2025 and February 2026. The AI numbers moved hard.

  • Incidents involving shadow AI, meaning tools nobody approved, hit 43%, up from 20% a year earlier.
  • Those shadow-AI incidents averaged $5.39 million.
  • Global average breach cost rose 12% to $4.99 million. The US average reached $11.5 million.
  • 68% of breached organizations had no policy governing AI use.
  • 92% of the organizations with an AI-related breach lacked real access controls on those tools.

Separately, Check Point reported that high-risk prompts to public AI tools doubled from 2% to 4% of traffic, and that the average organization touches about 10 different AI apps a month, most of them never approved by anyone.

The so-what for a 12-person company. Those dollar figures are enterprise averages. Your version does not cost $5 million. It costs one client relationship, one insurance carrier conversation, and a week you will never get back. The transferable finding is in the last two bullets: most companies that got burned had written something down and controlled nothing.

The deeper read is that shadow AI is a supply problem. Your bookkeeper pastes a client aging report into a free chatbot because that is the only tool on her machine that can read a spreadsheet. Blocking the site does not remove the task. It moves the paste to her phone, where you cannot see it at all.

The move: the sanctioned-path audit. Twenty minutes, this week, one page.

  1. Ask each team lead for the three tasks their people currently run through AI. Ask what tool, ask honestly, promise nobody gets in trouble. You are collecting reality, not confessions.
  2. Next to each task, write the sanctioned tool that can do it inside your paid business workspace.
  3. Circle every row where column two is blank. That blank is where shadow AI lives, and it will stay there until you buy a seat or approve a tool that does the job.
  4. Fill the blanks. A business-tier seat runs $25 to $60 a month per person and turns off training on your data by default.
  5. Post the one-pager. Approved tool per task, plus one line: sensitive client data stays in the business workspace.

Cost to run: twenty minutes and a few seats. Cost to skip: you keep paying for a policy that governs nothing.

Sources: IBM Cost of a Data Breach 2026 · Cybersecurity Dive summary · CNBC on 2026 breach volume