Ethics & Governance
Shadow AI: The Enterprise Security Crisis That No One Is Governing
IBM's 2026 breach report put unauthorised AI tools inside 43% of breached organizations, double the previous year, at a record $4.99 million average cost. The frameworks to govern them have existed since 2023.

Gabriele Masetti ·
The Breach That Named the Problem
In April 2023, engineers at Samsung's semiconductor division did what millions of knowledge workers were doing that spring: they opened ChatGPT to get help with their jobs. One pasted proprietary source code from a defect-detection program into the chatbot to check it for errors. Another fed it code tied to Samsung's semiconductor equipment. A third converted an internal meeting recording to text and asked ChatGPT to turn it into clean minutes.
None of the three thought they were doing anything wrong. All three had, in effect, exported confidential Samsung data to a third-party server they had no contract with, no audit rights over, and no ability to delete data from. By May 2023, Samsung had banned ChatGPT, Google Bard, and Bing Chat for employees and began building an internal alternative, the Gauss model, specifically so staff would stop routing sensitive work through public tools. Samsung didn't have a rogue-employee problem. It had a governance vacuum, and its employees filled it with the most convenient tool available.
That incident is now the reference case for a phenomenon security teams have started calling shadow AI, and it deserves the attention it gets, not because it was unusual, but because it was completely ordinary. Nearly every organization with white-collar employees and a browser has some version of the Samsung story unfolding right now, just without the headline.
Shadow IT's Faster, Harder Sequel
"Shadow IT" has described unsanctioned technology use since the early 2000s: the unauthorized SaaS subscription, the personal Dropbox folder, the department that stood up its own project-management tool because the official one was too slow to provision. IT security spent the 2010s building an entire control layer — cloud access security brokers, SSO-gated app catalogs, network-level SaaS discovery — to bring that behavior into view.
Shadow AI is shadow IT with the friction removed. There is no procurement cycle, no invoice, no admin console to request access to. An employee opens a browser tab, and within seconds is pasting a customer contract into a chat box to get a summary, or a chunk of proprietary code into a coding assistant to debug it, or a spreadsheet of employee data into a tool that promises to build a pivot table.
The action leaves almost no trace that legacy security tooling was built to catch: no file attachment, no email, no download. It is a text box on an HTTPS connection to a domain that, from a firewall's perspective, looks exactly like ordinary web traffic. That is the structural reason shadow AI is a harder problem than shadow IT ever was, and why the old playbook of "block the domain and move on" barely dents it.
The Numbers Nobody Can Un-See
The scale is no longer speculative. Netskope's Cloud and Threat Report on generative AI found that 94% of organizations were using genAI apps by the report period, up from 81% a year earlier, with the average organization now running 9.6 distinct genAI applications, up from 7.6. Adoption, in other words, has become close to universal in a little over a year.
| Metric | Year-ago figure | Current figure |
|---|---|---|
| Orgs using genAI apps | 81% | 94% |
| Avg genAI apps per org | 7.6 | 9.6 |
| AI use via personal/unmanaged accounts | 78% | 47% |
| AI use via company-approved accounts | 25% | 62% |
The more revealing number is who controls that adoption. A separate Netskope analysis of cloud security telemetry from October 2024 through October 2025, reported by Cybersecurity Dive, found that 47% of people using generative AI platforms were doing so through personal accounts their employer wasn't overseeing.
That is actually an improvement — the year before, 78% of genAI usage ran through personal, unmanaged accounts, while company-approved account use rose from 25% to 62% — but it means that even after a year of visible security effort, security teams are still blind to roughly half of the AI activity happening on their own networks. The same data found organizations averaging 223 incidents per month involving sensitive data being sent to AI apps.
Cyberhaven's analysis of roughly 1.6 million knowledge workers, covering the period from ChatGPT's public launch through mid-2023, put a number on what that exposure looks like in practice: 8.6% of employees had pasted company data into ChatGPT, and of everything employees pasted into it, 11% was confidential business information, with 4.7% of workers having pasted sensitive data at least once. Those figures are now more than two years old and adoption has only grown since, but they were among the first to demonstrate, at scale, that "sensitive data ends up in consumer AI tools" is not a hypothetical risk, it is a routine one.
ISACA's ongoing AI Pulse Poll, which surveys thousands of digital trust and audit professionals, tracks the governance side of that gap directly. The share of organizations with a formal, comprehensive AI policy rose from 15% in 2024 to 28% in 2025 to 38% in 2026 — real progress, but it means that as recently as this year, roughly six in ten organizations still had no comprehensive policy governing how employees use AI, even as adoption approached universal.

Why DLP Can't See It
The technical reason enterprise security has struggled to catch up is that data loss prevention tooling was built for a different set of channels. Classic DLP watches email attachments, USB transfers, and file uploads to recognized cloud storage services; it pattern-matches on file types, metadata, and known egress points. A prompt typed into a chat window is none of these things.
It is unstructured text, submitted over an encrypted connection to a domain that may not even be on a DLP vendor's watchlist, generating no file event and no attachment for a scanner to inspect. Even organizations with mature DLP programs built over a decade for the email-and-USB threat model find that architecture simply doesn't have eyes on the browser tab where the actual exposure is happening.
Closing that gap requires a different layer entirely — prompt-level inspection, browser-based controls, and enterprise gateways that mediate access to model APIs — which most organizations have not yet built, because the tooling category itself is only a few years old.
The Price of Not Governing
This is not an abstract compliance concern; it shows up on the balance sheet. IBM's 2026 Cost of a Data Breach Report, published on 29 July 2026, put the global average breach cost at $4.99 million, a 12% rise in a year and a record for the series. Inside that number the shadow-AI share more than doubled: unauthorised AI tools were involved in 43% of breached organizations, against 20% in the 2025 edition.
The governance picture behind it moved backwards. Of organizations that suffered an AI-related security incident, 92% were missing role-based access, multifactor authentication or comparable controls on their AI models and applications. Close to seven in ten breached organizations had no governance policy for managing AI systems or identifying unapproved tools, and fewer than one in five coordinated their AI governance and security functions at all. Shadow-AI incidents disrupted operations in roughly four cases in ten and drew a regulatory fine in about one in five.
The attacker side moved the same way. IBM found that one in four malicious breaches is now AI-enabled — deepfake impersonation and AI-generated malware are the common forms — a 56% rise in a year, at an average cost of about $6 million, roughly $1 million above the global average. Breaches involving an organization's own AI models or applications rose from 13% to 21%.
The pattern is consistent across every data source available: it is not the existence of AI in the enterprise that drives cost and risk, it is the absence of governance around it. Sanctioned, monitored AI use is measurably safer and cheaper to clean up after than the unmonitored version of the exact same activity.
| Metric | 2026 figure | Change |
|---|---|---|
| Global average breach cost | $4.99 million | +12% in a year |
| Breached orgs with shadow AI involved | 43% | up from 20% |
| Breaches involving the org's own AI models | 21% | up from 13% |
| AI incidents with inadequate AI access controls | 92% | — |
| Malicious breaches that were AI-enabled | 25% | +56% in a year |
| Average cost of an AI-enabled breach | ~$6 million | ~$1M above average |
Frameworks Exist. Adoption Doesn't.
What makes this crisis particularly indefensible is that it is not a problem of missing standards. The tools to govern AI formally already exist and are mature enough to operate on. NIST published its AI Risk Management Framework in January 2023, organized around four functions — Govern, Map, Measure, and Manage — designed to be voluntary, sector-agnostic, and usable by an organization of any size to structure how it identifies and manages AI risk, including exactly the kind of unmanaged, unmonitored use that defines shadow AI.
ISO/IEC 42001, published the same year, went further: it is the world's first certifiable management-system standard for AI, built on the same audit logic as ISO 27001 for information security, meaning an organization can be independently assessed and certified against it, with an initial certification cycle of three years and annual surveillance audits in between. This is no longer theoretical infrastructure.
AWS became the first major cloud provider to earn accredited ISO 42001 certification in November 2024; Anthropic followed in January 2025 as one of the first frontier AI labs to certify; Microsoft has certified products including GitHub Copilot and Microsoft 365 Copilot against it. The standard exists, the certification bodies exist, and major AI vendors are already submitting to the audit. What is missing, on the enterprise customer side, is the corresponding discipline of actually building an AI management system rather than publishing a policy PDF and calling the problem solved.
What Certification Actually Buys
The value of standards like NIST AI RMF and ISO 42001 is not the document itself but what building toward it forces an organization to do: inventory every AI system and vendor touching company data, assign an accountable owner to each one, define what data classes may never leave the perimeter through a model prompt, and log enough activity that an auditor — internal or external — can reconstruct what happened after an incident rather than guessing.
ISO 42001's three-year certification cycle, with annual surveillance audits, is specifically designed to keep that inventory current as new tools and vendors are added, which matters enormously in a category where the average organization added roughly two new genAI applications to its footprint in a single year. A framework followed loosely produces exactly the gap ISACA is measuring: high adoption, low formal governance.
A framework followed as an operating discipline produces an auditable trail that shows up favorably the moment a regulator, insurer, or acquirer asks for it.
Governance Has to Live in the Traffic, Not the Policy Binder
The clearest lesson from the data is that both of the obvious responses to shadow AI fail, and enterprises need to stop treating them as a real choice. Banning doesn't work: Samsung banned ChatGPT outright and still had to build its own internal LLM within months, because the underlying demand from employees for AI assistance didn't disappear when the sanctioned tool did — it simply meant the company had to build something to replace what people were already relying on. A ban without a sanctioned, equally convenient alternative just pushes the same behavior further underground, onto personal devices and personal accounts security has even less visibility into than before.
Policy alone doesn't work either. A comprehensive written AI policy, sitting in an intranet folder, does nothing to stop an employee from pasting a customer's PII into a browser tab at 4 p.m. on a Friday, because a document is not a control. The ISACA numbers make the failure mode explicit: even organizations that formally permit generative AI at rates close to universal have, for years, had formal policies in a minority of cases, and having a policy at all is a distinct and much weaker thing than having an enforced one.
The only approach the evidence supports is treating AI access the way mature organizations learned, over the last decade, to treat shadow IT and cloud access generally: as an identity and access-management problem that requires technical enforcement, not a communications problem that requires a memo. That means standing up sanctioned, enterprise-grade AI tools that are genuinely as convenient as the consumer versions, so there is no productivity gap driving employees back to personal accounts.
It means routing AI traffic through gateways and browser-level controls capable of inspecting prompts the way DLP inspects attachments, closing the exact blind spot legacy tooling has. And it means operationalizing NIST AI RMF and ISO 42001 as actual management systems with named owners, logged decisions, and periodic audits, not as documents cited in a board deck once a year. The frameworks are not the bottleneck. The willingness to fund and enforce them, at the same priority level organizations already give to a firewall or an email gateway, is.
Enterprises that keep treating shadow AI as a policy problem will keep paying the IBM premium for it, on an exposure that doubled in a single reporting cycle, while enterprises that treat it as an access-control problem, with the same rigor once reserved for the corporate network perimeter, will be the ones still standing when their insurers, auditors, and regulators start asking not whether they have an AI policy, but whether they can prove it works.