Shadow AI Turned Up in 43% of AI Breaches This Year.

Shadow AI Turned Up in 43% of AI Breaches This Year. That number doubled in 12 Months

IBM published its 2026 Cost of a Data Breach Report on 29 July 2026. It is based on 602 organisations that suffered a AI breach between March 2025 and February 2026, spanning 17 industries and 16 countries. The single most striking figure in this report is the share of security incidents involving Shadow AI, meaning AI tools used inside the business without approval or oversight, more than doubled year over year to 43 percent.

The average breach now costs roughly $5 million globally, up 12 percent on the previous year. More than two thirds of the organisations IBM studied said they had no AI Governance process in place to limit Shadow AI, and that figure had ticked slightly upward, not down.

OWASP's 2026 Agentic Security Report, citing IBM data, puts the number of organisations with a policy to detect Shadow AI at just 37 percent.

Why this is an AI Governance failure and not a Technology failure

It would be easy to read those numbers as an argument for banning AI tools. That is the wrong conclusion, and the same report says so. Eighty-five percent of breached organisations told IBM they plan to spend more on security tools and AI Governance. Half of them are already using AI agents to hunt for threats, though fewer than one in five use agents for the task they are arguably best suited to, which is scanning for and managing vulnerabilities.

The gap is control, not adoption. Ninety-two percent of organisations that suffered attacks against their AI models had failed to properly control access to those tools, and only four in ten limited access to their AI systems at all.

IBM's researchers were blunt about it, writing that identity controls have failed to keep pace with AI's sprawl across corporate networks, and that the outcome is expanded attack paths and incidents driven by basic enforcement gaps that do not even require attacker sophistication.

The breaches are "not clever". They are "unattended".

The Regulatory Clock started on 2 August

On 2 August 2026, the European Commission's AI Office and national authorities began enforcing the EU AI Act, and new transparency obligations under Article 50 took effect the same day.

Chatbots now have to identify themselves as automated systems, deepfakes need a label, and machine-generated or machine-edited content must carry machine-readable marks so it can be detected automatically.

Companies that ignore these obligations risk fines of up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher.

Not everything moved at once. The AI Omnibus package pushed the rules for high-risk AI systems out to 2 December 2027, and high-risk systems built into regulated products to 2 August 2028.

From 2 December 2026 the Act bans AI systems that generate non-consensual sexually explicit content or child sexual abuse material. Alongside enforcement, the Commission published a first list of more than 180 organisations that have signed a voluntary Code of Practice on transparency of AI-generated content, which gives providers a documented way to demonstrate compliance with obligations that apply either way.

If you are a Canadian or US company reading this and thinking it does not apply, check where your users are. The obligation attaches to systems placed on the EU market or whose output is used there, not to where your office is.

What this actually costs a Small Businesses?

For a 20-50-person small business the exposure is rarely a regulator's fine in year one. It is more mundane and more immediate. It is the enterprise buyer whose security questionnaire now includes a section on AI Governance, usage and data handling, and the two weeks your team loses trying to answer it honestly.

It is the customer contract with a data processing clause you may already be breaching because an engineer connected a third-party assistant to a production database. It is the insurance renewal where the underwriter wants evidence of an AI acceptable-use policy.

And it is the incident where you cannot tell a customer what left, because nobody was logging the tool that took it.

Five (5) Practical Steps

1. Run a discovery, and lead with amnesty rather than audit. Ask every team, in writing, which AI tools they use and what data they put into them. You will get a far more accurate picture from a no-blame question than from a network scan, and you need the accurate picture first.

2. Publish a one-page AI Acceptable Use Standard. Name the approved tools, name the data categories and classifications that must never be pasted into anything unapproved AI Tool, and say who to ask for an exception. One page that people read beats a twelve-page policy that they do not read.

3. Put access controls around the AI you do sanction. Given that 92 percent of organisations were breached through their AI models had not controlled access to them, this is the single highest-yield fix available. Treat an AI system or agent with data access controls (Least Privilege Principle) exactly as you would treat a new employee with the same access.

4. Map your obligations to a framework once, then reuse the answer. ISO/IEC 42001 and the NIST AI Risk Management Frameworks both give you a defensible structure, and the artefacts they produce are the same artefacts that answer customer security questionnaires. Do the work once, sell with it repeatedly.

5. Put two numbers on the board agenda every quarter:

  • How many AI tools are in use across the business?

  • How many AI-related incidents or near misses occurred?

If nobody can produce these insights, that is itself the finding and you need to engage an AI-Native Virtual / Fractional CISO to provide these insights for you.

Keep Reading

Related Articles

Our Industry Certifications

Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.

Copyright © 2026 IRM Consulting & Advisory. All Rights Reserved.