What is shadow AI?
Shadow AI is employees using AI tools their employer hasn't approved or doesn't know about — pasting work data into a personal chatbot account. IBM's Cost of a Data Breach 2025 report (July 30, 2025) found one in five organizations reported a breach due to shadow AI, and organizations with high shadow AI usage faced $670,000 higher breach costs.
Why — the first-principles explanation
Shadow AI is the newest branch of an old pattern called shadow IT: staff routing around approved tools because the approved tools are worse. The mechanism is always the same and it's rarely malicious — the sanctioned option is slower than the unsanctioned one, and people have deadlines. Someone facing a 40-page contract at 6 p.m. pastes it into a personal chatbot account and goes home on time. From their seat, that's initiative. From the security team's seat, a confidential contract just left the building through a door nobody knew existed.
What makes AI different from earlier shadow IT is where the data lands. Unapproved file-sharing at least put your document in a folder somewhere. Text pasted into a consumer AI account goes to a third party under that account's terms — which, on free consumer tiers, has often included using submitted content to improve models. The company never signed that agreement. It has no contract, no data-processing terms, no deletion rights, and frequently no idea the transfer happened. The data isn't stolen so much as volunteered by a well-meaning employee into a system with no paper trail.
The measured cost is real, and here's where nearly every article gets it wrong. IBM's July 30, 2025 report found that one in five organizations reported a breach due to shadow AI, and that organizations with high shadow AI usage saw $670,000 in higher breach costs than those with low or no shadow AI. That is a difference, not a total. Many summaries state a flat "$4.63 million average shadow AI breach" — that figure is a secondary construction, not IBM's own framing. The number to quote is the $670,000 delta against a global average breach cost that fell to $4.44 million, its first decline in five years.
The governance picture explains why the delta exists. Among organizations that suffered an AI-related breach, 97% reported not having AI access controls in place, and 63% of breached organizations either had no AI governance policy or were still developing one. Shadow AI breaches also skewed toward the most damaging data: 65% involved personally identifiable information versus a 53% global average, and 40% involved intellectual property versus 33%. The reason is intuitive — people don't paste boring data into a chatbot. They paste the hard thing they're stuck on, which is usually the sensitive thing.
One honest caveat: this is vendor-published research, from a company that sells security products. The study is large and methodologically transparent, and it's the best data available on this specific question, but it isn't peer-reviewed and the sponsor has a commercial interest in the finding. Weigh it accordingly — and note that the correlation between shadow AI and cost doesn't by itself prove shadow AI caused all of the gap; organizations lax enough to have ungoverned AI are often lax elsewhere too.
An example that makes it click
Picture an office with a shredder for confidential paperwork, and a rule that everything sensitive goes in it.
One day the shredder starts jamming. It takes ten minutes a document. So people improvise: there's a recycling bin out back that's faster, and honestly, who's going through the recycling? Nobody's being reckless. They're being efficient with a broken shredder.
That's shadow AI. The approved tool is slow, so the confidential contract goes into a personal chatbot instead, and everyone goes home on time. Two things follow. First, management genuinely doesn't know — that's the “shadow” part; there's no record the document ever left. Second, the recycling bin isn't yours. It belongs to a company down the street, operating under rules you never read and never signed.
And here's the sting: nobody puts the cafeteria menu in the recycling bin. They put the thing they were stuck on at 6 p.m. — which is almost always the sensitive thing. That's why IBM found shadow AI incidents hit personal data and trade secrets harder than average breaches do.
How to do it
- Find out what's already in use before writing policy — anonymous surveys and network/expense data usually reveal AI tools the security team didn't know about.
- Fix the reason it's happening: shadow AI is a symptom of the approved tool being slower or absent. Banning it without providing a fast sanctioned alternative moves it further underground.
- Provide an enterprise-tier AI tool with contractual terms that exclude your data from model training, plus logging and access controls.
- Write an AI governance policy that names specific permitted tools and specific prohibited data categories — 63% of breached organizations lacked one or were still drafting.
- Implement AI access controls; 97% of organizations with an AI-related breach reported having none.
- Train staff on the concrete rule that matters most: never paste customer PII, credentials, or unreleased IP into a personal AI account, regardless of deadline pressure.
Key facts
- IBM's Cost of a Data Breach Report 2025 (published July 30, 2025) found one in five organizations — 20% of studied breaches — reported a breach due to shadow AI.
- Organizations with high shadow AI usage experienced $670,000 in higher breach costs than those with low or no shadow AI. This is a difference, not a total — the commonly cited '$4.63 million shadow AI breach' figure is a secondary construction, not IBM's own wording.
- The global average cost of a data breach fell to $4.44 million, the first decline in five years.
- 97% of organizations that reported an AI-related breach said they did not have AI access controls in place.
- 63% of breached organizations either had no AI governance policy or were still developing one.
- Shadow AI incidents disproportionately exposed sensitive data: 65% involved personally identifiable information (vs. 53% global average) and 40% involved intellectual property theft (vs. 33%).
- 13% of organizations reported breaches of AI models or applications themselves.
- NIST's AI Risk Management Framework (AI RMF 1.0, January 26, 2023) with its July 2024 generative AI profile (NIST-AI-600-1) is the main free U.S. government reference for building AI governance.
▶ The 60-second explainer (script)
Shadow AI is when employees use AI tools their company never approved — and usually doesn't know about. It's almost never malicious. Picture someone at 6 p.m. staring at a 40-page contract. They paste it into their personal chatbot account, get a summary, and go home. From their chair, that's initiative. From security's chair, a confidential contract just walked out a door nobody knew existed. What makes AI different from old-fashioned shadow IT is where the data lands. It goes to a third party, under terms of an account the company never signed — terms that on free consumer tiers have often allowed using your text to improve their models. No contract. No deletion rights. No record it happened. And it costs real money. IBM's Cost of a Data Breach report, published July 2025, found one in five organizations reported a breach due to shadow AI. Organizations with heavy shadow AI use faced six hundred seventy thousand dollars in higher breach costs. Now — be careful here. That's a difference, not a total. You'll see articles claiming a “$4.63 million shadow AI breach.” That's not IBM's number. The real figures: $670K extra, against a global average that actually fell to $4.44 million. Why so damaging? Because nobody pastes the cafeteria menu into a chatbot. They paste the hard thing they're stuck on — which is the sensitive thing. IBM found 65% of shadow AI incidents exposed personal data, versus 53% normally. And the fix isn't a ban. Shadow AI exists because the approved tool is slower. Ban it without a fast, sanctioned alternative and you don't remove it — you just stop being able to see it.
What authoritative sources say
People also ask
What counts as shadow AI?
Any AI use outside company approval or visibility: a personal chatbot account for work tasks, an unvetted AI browser extension, an AI meeting notetaker joining calls, or AI features inside an unapproved SaaS tool.
Why do employees do it?
Because the approved tool is slower, worse, or doesn't exist. Shadow AI is a symptom of a tooling gap, not usually of bad intent — which is why bans alone tend to push it further out of sight.
Is the $4.63 million shadow AI breach figure accurate?
That's not IBM's framing. IBM reported $670,000 in higher costs for organizations with high shadow AI usage, against a $4.44 million global average. The '$4.63M' number is a secondary calculation circulated by other sites.
How do you stop shadow AI?
Give people a sanctioned tool that's genuinely fast, with contract terms excluding your data from training. Then add AI access controls and a written governance policy naming permitted tools and prohibited data types.
Should I trust IBM's numbers given they sell security products?
Weigh them with that in mind. It's the largest study on this question and its methodology is published, but it's vendor-sponsored and not peer-reviewed — and correlation between shadow AI and cost doesn't fully establish causation.