Skip to content

Shadow AI Risk Companies Cannot Price

A new IBM breach study, plus insurance and disclosure pressure, leaves mid-sized companies without an AI function unable to inventory, govern, or price unapproved tool use.

Shadow AI, meaning the tools staff adopt without approval, showed up in 43 percent of security incidents in IBM’s Cost of a Data Breach Report 2026. That share more than doubled from 20 percent the year before, in a study of 602 organizations breached between March 2025 and February 2026.

For a mid-sized company with no internal AI function, that is an operating problem, not a future one. Leadership cannot price the risk if it cannot see which tools are in use, which data they touch, and who approved them. The business problem is unmanaged experimentation standing in for an operating model. The work that follows is AI Operating Control: knowing what AI is being used, where the work is going, what it costs, what data is exposed, and how usage is governed.

Shadow AI already sits inside the breach numbers

IBM reports that security incidents involving an organization’s shadow AI, where workers use unapproved AI, more than doubled to 43 percent this year from 20 percent last year. Those incidents carried a higher average cost, USD 5.39 million, than the year before (USD 4.63 million). Among them, 49 percent involved data loss or compromise, 42 percent disrupted operations, and about one in five drew a regulatory fine. The same study found that 68 percent of the breached organizations lacked AI governance policies in place.

Those figures describe organizations that had already been breached, not a census of every company. When unapproved tools are in the mix, cost and disruption still show up in the same places finance, operations, and IT already worry about.

The rest of IBM’s AI chapter points at usage. Incidents involving an organization’s own AI models and applications rose to 21 percent from 13 percent. Among organizations with an AI-related breach, 92 percent lacked proper access controls. IBM wrote that the root causes were often structural: compromised APIs, connected applications, and cloud misconfigurations. That is a governance failure, not a model-behavior failure.

The global average breach in the same study reached USD 4.99 million, up 12 percent and a record. IBM’s July 29 newsroom announcement led with AI-enabled attacks and that headline cost. It did not mention the 43 percent shadow AI figure. That number sits in the report itself, as Güney Yıldız noted in Forbes on August 17, 2026.

A company cannot price the exposure it has not mapped

Inventory table of AI tools in use with empty owner, data, and approval fields, showing those tools cannot be priced.

Yıldız’s argument is an operating one. Risk committees have spent two years on model behavior. The exposure that is not on the agenda sits one layer down, in how staff and software agents actually use the tools.

Yakir Golan, chief executive of Kovrr, told Forbes that 70 to 75 percent of AI risk is usage risk rather than model risk, and that companies should manage as if usage were even higher. He said he had not measured the split. It is a practitioner’s read, not a dataset. Data leakage, bad permissions, and third-party vendor exposure are still usage failures. None of them is visible to a company that maps only what it has approved.

Forbes reports that ISO has a generative AI exclusion in circulation for commercial general liability cover, form CG 40 47 01 26, January 2026 edition. It removes protection for injury and damage “arising out of, or attributable to, generative artificial intelligence,” whether used directly or through a vendor. Carriers decide whether to attach it. A standard route to exclude now exists. That is not the same as every business having already lost cover. Golan told Forbes that underwriters still need “confident visibility first.” This is not insurance advice. It is an operating observation. Questionnaires are arriving before many mid-sized companies have a list.

Experimentation is not an operating model

Comparison of ungoverned AI use, including personal chat and unapproved tools, with an approved path that names the tool, owner, and rule.

Mid-sized companies did not set out to run a shadow AI program. They set out to let people try tools. Finance uses one assistant to explain a variance. Operations uses another to draft a shift plan. Someone in sales pastes a pipeline summary into a consumer chatbot because it is faster than waiting for an approved option. (That last example is hypothetical, not a client case.)

Access is not the same as control. The first phase of AI adoption was about access. The next phase is about control. When every team chooses its own tools, every request can touch data nobody classified, and leadership cannot answer a simple question (what are we running?), experimentation has become the operating model by default.

Buildtelligence is not against AI vendors. Buildtelligence is against unmanaged dependence: the condition in which vendor defaults, unapproved tools, and informal workflows become the architecture because nobody named a better one. Buildtelligence helps companies use AI without losing control of cost, data, workflows, or vendor choice. That work does not require a Fortune-10 AI office. It does require treating inventory, policy, and visibility as operating work rather than as a later governance project.

Three moves for a company with no AI function

Three-step operator loop for AI Operating Control: Inventory, then Policy, then Visibility.

A company that cannot staff an AI center of excellence can still do three things that change the conversation with the board, the carrier, and the auditor.

Inventory. Write down what is actually in use, not what was approved. Browser extensions, personal assistant logins, department-bought copilots, embedded AI in existing SaaS, agents with standing permissions on mailboxes or code repositories. IBM found that 92 percent of organizations with an AI-related breach had failed to control access to those tools. You cannot control what you have not listed.

Policy. A short acceptable-use policy beats a 40-page charter that never leaves legal. IBM’s 2026 sample shows policies actually in place at only 32 percent of breached organizations, with 35 percent reporting none and 33 percent still “in development.” Finish something small: which data may not go into public tools, which work needs an approved environment, who can buy a new AI subscription, and what happens when a tool is blocked. Forbes cites an UpGuard survey in which many employees reported unapproved tools and workarounds, with the caveat that the numbers are self-reported and that UpGuard sells tooling in the category. A policy that only says no, without an approved path, will still be routed around.

Visibility. Policy without a way to see usage is a memo. Golan told Forbes that visibility is “the key now.” For a mid-market shop, that can start with SSO logs, expense reports for AI subscriptions, browser and network egress, and a quarterly conversation with department heads. It does not have to be a real-time risk model on day one. It does have to be honest about the gap between approved and actual.

Those three steps are not a security program, an insurance product, or a legal opinion. They are the minimum operating map. A model built on a partial inventory understates exposure and manufactures confidence at the same time. The second failure is the expensive one, because it reaches the board as a decision.

What this does not settle

No inventory makes a company unbreachable. IBM’s study is a nonstatistical sample of already-breached organizations. Ponemon’s methodology section is explicit that margins of error cannot be applied. The higher average cost attached to shadow AI incidents is an association, not proof that unapproved tools caused the extra dollars. Insurance wording varies by carrier.

Buildtelligence does not sell a guaranteed reduction in breach cost, a free audit, or a complete implementation blueprint. Engagements are scoped. Tooling, staffing, and timelines are not established as facts here.

The next question is operational

The IBM figure is already in the record: unapproved AI in 43 percent of security incidents in a 602-organization breach study, at a higher average cost than a year earlier. Forbes is right that a company cannot price the shadow AI risk it cannot see. The useful question for a mid-sized leadership team is not whether staff are using AI. They are. The question is whether the company can name the tools, the data, the owners, and the rules before an underwriter, a regulator, or an incident asks.

If the honest answer is no, the next move is inventory, policy, and visibility, in that order. Scale after the map exists.