The biggest data breaches at many companies didn't come from an attack: they came from a €20 monthly subscription paid for with a corporate credit card. It's called *shadow AI*: artificial intelligence tools contracted and used by departments with no knowledge of the technology, security, or data protection officer.
It's not a discipline problem. It's the predictable consequence of these tools being cheap, immediately useful, and requiring no installation.
When a report came from a spreadsheet, someone looked at it with suspicion. When it comes from an AI system, it's discussed in a meeting.
IBM's 2025 Cost of a Data Breach report, in its twentieth edition and prepared with Ponemon on some 600 organizations, offers figures that put an end to any internal debate:
That last piece of information explains the other three. When there is no authorized and reasonable way to do it, people solve their problems with whatever they can find.
The instinctive reaction of many committees is to issue a circular prohibiting the use of external AI tools. This produces three effects, none of which are the desired ones:
The use doesn't disappear: it just hides. Switch from the corporate laptop to the personal phone, where there is no visibility.
Useful information is lost. Knowing what tools people use indicates what real unresolved problems the organization has.
Those who try to do a better job are penalized. The cultural cost is high and long-lasting.
The alternative that works is inconvenient because it requires effort: offer an authorized route that is at least as convenient. If the approved option is slower than the corporate card option, the policy loses.
Risk | How it materializes | Effective control |
Information leak | A contract, payroll, or proprietary code is pasted into a public tool. | Authorized channel with data processing agreement |
Non-traceable decision | Someone decides with an answer that no one can reconstruct | Registration and obligation to cite source |
Regulatory non-compliance | Personal data processed outside the declared framework | Inventory and classification by use case |
Invisible dependency | A process then becomes dependent on a tool that no one approved | Inventory and periodic review |
The fourth one is the least discussed and the one that gives the most surprises. A department sets up a workflow around a tool, the tool changes price or disappears, and suddenly an operational process stops without anyone in technology knowing that dependency existed.
A complex deployment is not necessary. Four routes cover most of it:
The result of these four approaches is an inventory, which is the starting point for any governance policy. Without an inventory, policy is merely a document about an unknown reality, as we explained when discussing The obligations of the AI Act and where to begin
An authorized, good and fast route. One or two approved tools, with a data processing agreement, easy access and no bureaucratic friction to start using them.
An understandable data rule. Not a twenty-page document. Three lines: what information never leaves internal systems, what requires approval, and what is unrestricted. If it doesn't fit on a card, it won't be followed.
Brief and specific training. Ten minutes about what really happens when you paste information into an external tool. Most people don't do it by accident, but because they don't understand how it works.
A channel for requesting tools. With responses in days, not quarters. The speed of this channel determines the organization's level of shadow AI better than any standard.
Quarterly inventory review. Short. What was added, what was discontinued, what access needs to be revoked.
This issue is poorly defended when presented as a security problem, because it competes with other priorities. It is well defended when presented with two numbers.
The first one is IBM's: $670,000 average cost overrun when unauthorized AI is involved in a breach. The second is our own: how many AI subscriptions appear in last quarter's expenses that no one in technology knew about.
That second number, obtained in an afternoon, usually ends the discussion.
This refers to the use of artificial intelligence tools contracted or used by departments without the knowledge or approval of technology, security, or the data protection officer. It typically occurs through low-value subscriptions paid for with a corporate credit card.
According to IBM's 2025 Cost of a Data Breach report, 20% of the breaches analyzed involved unauthorized AI, and those incidents added an average of $670,000 to the cost, on top of an average breach cost of $4.44 million.
Because usage doesn't disappear, it simply moves to personal devices where there's no visibility; valuable information about unresolved organizational problems is lost; and those trying to improve are penalized. The effective alternative is to offer an equally convenient, authorized channel.
Through four avenues: review of corporate card subscriptions and expense reports, analysis of network traffic and logins with corporate accounts, an internal survey with explicit amnesty, and review of third-party integrations with access to email, storage, or CRM.
A three-line data rule—what information never leaves the systems themselves, what requires approval, and what is free—, one or two authorized tools with a data processing contract, a channel to request new tools with a response in days, and a quarterly inventory review.
Yes. Any regulatory obligation stems from knowing what AI systems exist within the organization, what data they contain, and who is responsible for each one. Systems not inventoried are excluded from risk classification and, therefore, from any compliance measures.
Do you know what AI tools are used in your company today? We took the actual inventory, classified the risk by use case, and designed the authorized route so that people don't have to avoid it. Let's talk → |