logo

Your data doesn't become good just because you connect AI to it.

September 10, 2026

The biggest data breaches at many companies didn't come from an attack: they came from a €20 monthly subscription paid for with a corporate credit card. It's called *shadow AI*: artificial intelligence tools contracted and used by departments with no knowledge of the technology, security, or data protection officer.

It's not a discipline problem. It's the predictable consequence of these tools being cheap, immediately useful, and requiring no installation.

When a report came from a spreadsheet, someone looked at it with suspicion. When it comes from an AI system, it's discussed in a meeting.

The cost has already been calculated.

IBM's 2025 Cost of a Data Breach report, in its twentieth edition and prepared with Ponemon on some 600 organizations, offers figures that put an end to any internal debate:

  • 20% of the analyzed gaps involved unauthorized AI within the organization.
  • Those incidents added on average $670,000 at cost, on an average gap cost of 4.44 million.
  • The 97% Many of the organizations that suffered an AI-related incident lacked adequate access controls.
  • The 63% It had no AI governance policy.

That last piece of information explains the other three. When there is no authorized and reasonable way to do it, people solve their problems with whatever they can find.

Why banning it doesn't work

The instinctive reaction of many committees is to issue a circular prohibiting the use of external AI tools. This produces three effects, none of which are the desired ones:

The use doesn't disappear: it just hides. Switch from the corporate laptop to the personal phone, where there is no visibility.

Useful information is lost. Knowing what tools people use indicates what real unresolved problems the organization has.

Those who try to do a better job are penalized. The cultural cost is high and long-lasting.

The alternative that works is inconvenient because it requires effort: offer an authorized route that is at least as convenient. If the approved option is slower than the corporate card option, the policy loses.

The four specific risks

Risk

How it materializes

Effective control

Information leak

A contract, payroll, or proprietary code is pasted into a public tool.

Authorized channel with data processing agreement

Non-traceable decision

Someone decides with an answer that no one can reconstruct

Registration and obligation to cite source

Regulatory non-compliance

Personal data processed outside the declared framework

Inventory and classification by use case

Invisible dependency

A process then becomes dependent on a tool that no one approved

Inventory and periodic review

The fourth one is the least discussed and the one that gives the most surprises. A department sets up a workflow around a tool, the tool changes price or disappears, and suddenly an operational process stops without anyone in technology knowing that dependency existed.

How do you detect what's there?

A complex deployment is not necessary. Four routes cover most of it:

  1. The expenses. Subscriptions appear on corporate credit cards and expense reports. It's the quickest source and the most overlooked.
  2. Network traffic and logins. Which domains are visited and with which corporate accounts access to third-party services has been created.
  3. Ask without penalizing. An internal survey with explicit amnesty yields surprisingly good results when people believe there will be no consequences.
  4. Authorized integrations. Which third-party applications have granted access to email, storage, or CRM? This often includes access granted months ago by someone who is no longer there.

The result of these four approaches is an inventory, which is the starting point for any governance policy. Without an inventory, policy is merely a document about an unknown reality, as we explained when discussing The obligations of the AI Act and where to begin

The program that does address the problem

An authorized, good and fast route. One or two approved tools, with a data processing agreement, easy access and no bureaucratic friction to start using them.

An understandable data rule. Not a twenty-page document. Three lines: what information never leaves internal systems, what requires approval, and what is unrestricted. If it doesn't fit on a card, it won't be followed.

Brief and specific training. Ten minutes about what really happens when you paste information into an external tool. Most people don't do it by accident, but because they don't understand how it works.

A channel for requesting tools. With responses in days, not quarters. The speed of this channel determines the organization's level of shadow AI better than any standard.

Quarterly inventory review. Short. What was added, what was discontinued, what access needs to be revoked.

The argument for the committee

This issue is poorly defended when presented as a security problem, because it competes with other priorities. It is well defended when presented with two numbers.

The first one is IBM's: $670,000 average cost overrun when unauthorized AI is involved in a breach. The second is our own: how many AI subscriptions appear in last quarter's expenses that no one in technology knew about.

That second number, obtained in an afternoon, usually ends the discussion.

Frequently Asked Questions

What is Shadow AI?

This refers to the use of artificial intelligence tools contracted or used by departments without the knowledge or approval of technology, security, or the data protection officer. It typically occurs through low-value subscriptions paid for with a corporate credit card.

According to IBM's 2025 Cost of a Data Breach report, 20% of the breaches analyzed involved unauthorized AI, and those incidents added an average of $670,000 to the cost, on top of an average breach cost of $4.44 million.

Because usage doesn't disappear, it simply moves to personal devices where there's no visibility; valuable information about unresolved organizational problems is lost; and those trying to improve are penalized. The effective alternative is to offer an equally convenient, authorized channel.

Through four avenues: review of corporate card subscriptions and expense reports, analysis of network traffic and logins with corporate accounts, an internal survey with explicit amnesty, and review of third-party integrations with access to email, storage, or CRM.

A three-line data rule—what information never leaves the systems themselves, what requires approval, and what is free—, one or two authorized tools with a data processing contract, a channel to request new tools with a response in days, and a quarterly inventory review.

Yes. Any regulatory obligation stems from knowing what AI systems exist within the organization, what data they contain, and who is responsible for each one. Systems not inventoried are excluded from risk classification and, therefore, from any compliance measures.

Do you know what AI tools are used in your company today? We took the actual inventory, classified the risk by use case, and designed the authorized route so that people don't have to avoid it. Let's talk →

Shadow AI and unauthorized use of Artificial Intelligence tools in companies
Management team analyzing risks of non-human identities and artificial intelligence agents in enterprise systems.