The gap is widening, not closing
IBM's 2026 Cost of a Data Breach Report put a number on something CISOs have been warning about anecdotally for two years: shadow AI, meaning employees routing company data through AI tools their IT department never approved, more than doubled as a contributing factor in breaches, from 20% of breached organizations to 43%. A fresh explainer from Malwarebytes on October 1 reframed the same dynamic for a broader audience, citing Microsoft research that 71% of UK employees admit to using unapproved AI tools at work, and separate IBM findings that one in five organizations has already traced a breach to exactly that behavior.
What makes this uncomfortable for enterprise leaders is the direction of travel on the governance side. Only 32% of breached organizations report having an AI usage policy in place, down from 37% the year before. Adoption of AI tools inside the workforce is accelerating while formal policy coverage is shrinking. That is the opposite of how a maturing risk should behave, and it suggests most enterprise AI governance programs are still writing policy for last year's tool sprawl, not this year's.
The cost delta makes this a budget conversation, not just a security one
A breach tied to shadow AI costs an average of $5.39 million, up from $4.63 million the year prior, and that sits well above IBM's global average breach cost of $4.99 million itself already a record 12% higher than last year. In the United States specifically, the average breach runs $11.5 million, nearly double the global figure. Layer the shadow AI premium onto a US-based enterprise's exposure and the math gets serious quickly: 21% of shadow AI incidents in IBM's data resulted in regulatory fines on top of direct remediation cost, and 49% caused outright data loss or compromise.
IBM's analysts were blunt about where the fault actually sits. Root causes, they wrote, "were often structural: compromise of connected APIs, applications and cloud misconfigurations, indicating governance failures, not model risk." That distinction matters for how CIOs pitch budget internally. This is not a case for buying a better model or a more sophisticated AI platform. It is a case for fixing the access control and policy infrastructure wrapped around the tools you already have deployed.
Why the security and AI governance teams still are not talking
Perhaps the most damning figure in the report is that just 19% of organizations coordinate between their AI governance function and their security team. In most enterprises those two groups report up different chains, run different risk frameworks, and rarely share a common view of what tools are actually touching sensitive data. Shadow AI thrives precisely in that seam, because an AI governance committee approving a vendor tool for one department has no visibility into whether security has validated its data handling, and security teams scanning for unauthorized SaaS rarely have the AI-specific context to flag a browser extension or meeting bot as a material risk.
The UK's National Cyber Security Centre defines shadow AI simply as the use of AI technology that is not captured in an organization's approved systems and processes, and that simplicity is part of the problem. It is a definition broad enough to include everything from an employee pasting customer data into a personal ChatGPT account to a sanctioned vendor quietly shipping a new AI feature inside a tool that was never evaluated for that capability. Treating all of it as one governance problem with one committee is how 81% of organizations end up without coordinated oversight.
Where this collides with the ERP and core-systems governance debate
This data lands at the same moment enterprise application vendors are racing to embed agentic AI directly into ERP, CRM, and HR systems, which means the shadow AI exposure is no longer confined to employees freelancing with consumer chatbots. It increasingly means officially licensed enterprise software quietly gaining AI capability that was never part of the original procurement review. IBM's researchers flagged this directly as an emerging risk category: AI feature creep inside already-approved vendor tools, where oversight assumptions built at purchase time stop matching what the tool actually does six months later.
That should worry any CIO who treats a signed vendor contract and an annual security review as sufficient ongoing oversight. A platform that passed a SOC 2 review in January can ship an AI assistant with default-on data retention in June, and if your vendor risk process does not include a trigger for material feature changes, you will not know until the breach report names you. The annual renewal cycle most procurement teams run on was built for a slower software era, and it is now the weakest link in the governance chain.
The organizations getting this right look different
The report is not entirely grim. Organizations using security AI extensively, meaning AI deployed defensively to detect and contain incidents rather than offensively adopted by employees, cut their average breach cost to $4.00 million against $5.93 million for organizations with no security AI use. That is a savings of $1.93 million per breach, and those same organizations contained incidents 65 days faster on average. The lesson is not that AI itself is the risk. It is that ungoverned AI is the risk, and governed, defensively deployed AI is measurably an asset.
That reframing matters for how CIOs sell governance investment internally. A policy initiative pitched purely as risk avoidance competes poorly for budget against revenue-generating projects, and it usually loses that fight. A policy initiative pitched alongside the $1.93 million cost delta and the 65-day speed advantage of mature AI governance is a return-on-investment case a CFO can actually model, which is the version of this pitch that survives a budget cut cycle.
What to put in front of your board this quarter
Start with an honest inventory, not a policy document. Most enterprises cannot currently answer which SaaS tools in active use have gained AI functionality since procurement, let alone which employees are routing data through unsanctioned tools entirely. That inventory, uncomfortable as it will be, is the actual prerequisite for any policy that will hold up against the 43% incident rate IBM is now reporting, and skipping straight to a policy memo without it is how most AI governance programs end up as documents nobody can actually operationalize.
Then fix the coordination gap directly rather than writing around it. If AI governance and security sit in different reporting lines with a 19% coordination rate industrywide, that is an organizational design problem, not a training problem, and no amount of policy language fixes it until the two functions share a working review process for vendor tools and internal usage alike. Given the direction these numbers are moving, that restructuring is cheaper now than it will be after your own incident report, and it is a far easier conversation to have with a board before an incident than during the postmortem.



