Security

Shadow AI Drove 43% of Security Incidents in 2025, IBM Reports

Unapproved employee tools now represent the majority of AI risk exposure, yet most breached companies had no governance policies in place.

Omega Editorial· August 17, 2026· 4 min read

Shadow AI incidents doubled in one year

Unapproved AI tools used by employees without organizational oversight contributed to 43 percent of security incidents in 2025, roughly double the share from the previous year, according to IBM's Cost of a Data Breach Report 2026. The report, published July 29 and based on data from 602 organizations breached between March 2025 and February 2026, revealed that 68 percent of breached companies had no policy governing AI use at all.

The findings underscore a fundamental visibility problem: companies cannot manage risks they cannot see. Four days after IBM released its report, Article 50 of the EU AI Act took effect, requiring organizations to disclose when users interact with AI systems. Compliance requires knowing which systems exist—precisely the inventory most organizations lack.

Usage risk outweighs model risk by wide margin

Yakir Golan, chief executive of risk quantification firm Kovrr, estimates that 70 to 75 percent of AI risk stems from how employees and software agents actually use tools, rather than from inherent model flaws. He advises companies to manage as if the split were even more extreme—90 to 95 percent usage risk versus 5 to 10 percent model risk.

"Top models get heavy scrutiny; internal enterprise use is neglected," Golan said, noting his assessment comes from years of client engagements rather than formal measurement.

IBM's data supports this distribution. Incidents involving an organization's own AI models and applications rose to 21 percent from 13 percent year over year. Among companies whose AI systems were attacked, 92 percent had failed to implement proper access controls—a usage failure often miscategorized as a model problem.

The top three usage risks Golan identifies are data leakage, improper permissions, and third-party vendor exposure. None are visible to organizations that map only approved systems.

Why it matters

The shadow AI problem creates a dangerous disconnect between perceived and actual risk exposure. While risk committees have focused on model behavior—hallucination, bias, poisoning—the data shows the real exposure sits in how staff actually deploy these tools. This gap has immediate financial consequences: the global average breach cost reached just under $5 million in 2025, up 12 percent and the highest IBM has recorded, with AI-involved breaches running about $1 million above that figure.

Insurers responded before regulators. ISO, the Verisk-owned standards bureau, circulated a generative AI exclusion for commercial general liability policies in January 2026, removing protection for injury and damage "arising out of, or attributable to, generative artificial intelligence." Affirmative AI coverage exists but remains specialized and expensive.

The inventory problem blocks compliance and pricing

A November 2025 UpGuard survey of 500 security leaders and 1,000 employees found that 81 percent of employees and 88 percent of security leaders reported using AI tools their employer had not approved. Forty-five percent of workers said they find workarounds when applications are blocked.

Golan describes visibility as the prerequisite for quantification. Kovrr pulls telemetry from browsers, endpoints, network traffic, identity systems, and third-party model activity, then separates approved assets from shadow ones before modeling begins. One large manufacturer used this mapping to support an assessment under the EU's NIS2 directive, then prioritized remediation across 2026 by financial weight.

Golan estimates mass-market AI insurance will take about two years to scale. "Underwriters need confident visibility first," he said. Without it, insurers price unmapped AI estates at worst-case assumptions.

The National Security Telecommunications Advisory Committee warned in March 2024 that security risk quantification suffers from weak "metrics literacy" and applies mathematical operations to subjective judgments. The critique applies with greater force to AI, which has far less loss history than cyber risk. A model built on a partial inventory understates exposure while manufacturing false confidence.

Details were first reported by Güney Yıldız in Forbes.

#shadow ai#ai governance#cybersecurity#eu ai act#risk management#data breach

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

AI chatbots now claim broader rights to your personal data

As conversational AI becomes more personalized, companies are expanding what they can do with the intimate details users share.

Via AI Watch · Aug 17, 2026
Security· 4 min read

AI Watermarks Break in Hours but Regulators Don't Care

Major AI companies are embedding watermarks to comply with EU law, even though free tools strip them instantly—and that's the point.

Via AI Watch · Aug 17, 2026
Security· 4 min read

AI Chatbot Logs Become Evidence in Israeli Criminal Cases

Two investigations reveal how conversations with ChatGPT and Gemini served as digital trails, even after users believed they had covered their tracks.

Via AI Watch · Aug 16, 2026