Two years ago, "shadow AI" was a footnote in security reports: an anecdote about employees pasting things into ChatGPT. In the 2026 Cost of a Data Breach study from IBM and the Ponemon Institute, unsanctioned AI use is involved in 43% of AI-related security incidents, up from 20% a year earlier. A breach that involves it costs $5.39 million on average.
The problem is not that companies use AI. The problem is AI that nobody is tracking: personal chatbot accounts, browser extensions, a free tier someone signed up for in 2024 and never told anyone about. This page collects the figures that actually measure that problem, from the four datasets that measure it well, and explains what each number does and does not tell you. Every figure links to its source. We update it quarterly, and the date at the top of the page is the date of the last review.
Shadow AI in 2026: the key figures
- 43% of AI-related security incidents involved shadow AI in 2026, up from 20% in 2025 (IBM, 2026).
- $5.39 million is the average cost of a breach involving shadow AI, against a global average of $4.99 million (IBM, 2026).
- 68% of breached organisations had no AI governance policy in place, worse than the 63% recorded a year earlier (IBM, 2026).
- 47% of employees who use generative AI at work still do so through personal, unmanaged accounts, down from 78% a year earlier (Netskope, 2026).
- 39.7% of all data movements into AI tools involve sensitive data (Cyberhaven, 2026).
- 223 generative-AI data-policy violations per month is now the average for a single organisation, double the previous year (Netskope, 2026).
- 1 in 5 AI-related breach incidents resulted in a regulatory fine (IBM, 2026).
Shadow AI is not an edge case. It is how a large share of AI work happens
Start with the most reliable usage figure. Netskope's Cloud and Threat Report 2026, built on network telemetry across its customer base rather than on a questionnaire, found that 47% of generative-AI users at work access tools through personal accounts, either exclusively or alongside a sanctioned one. The same figure was 78% a year earlier. That is real progress, and it is also nearly half of all users still operating outside any control the company can see.
Cyberhaven's 2026 AI Adoption & Risk Report, which observes AI use at the browser and endpoint level, puts the share of employees using personal accounts at roughly one third. Its per-tool breakdown is the more useful number: 32.3% of ChatGPT usage and 24.9% of Gemini usage ran through personal accounts, while for Claude the share was 58.2% and for Perplexity 60.9%. The pattern is simple. The tools with mature enterprise contracts get used through corporate identities; the newer tools get used through whatever account the employee already had.
Verizon's 2025 Data Breach Investigations Report adds the identity angle: 15% of employees were routinely accessing generative-AI systems on corporate devices, and 72% of those did so with a non-corporate email address, which means the interaction was invisible to single sign-on, logging and retention policies alike.
One caveat applies to every number in this section. No statistics office measures shadow AI. All of the figures above come from vendors observing their own customers, and those customers are, by definition, organisations that bought monitoring. In a company with no monitoring at all, the true share is unknown and probably higher.
What actually leaks
The volume of AI use matters less than what goes into the prompt. According to Cyberhaven's 2026 report, 39.7% of all data movements into AI tools involve sensitive data, and the average employee enters sensitive data into an AI tool roughly once every three days. The trend line is steeper than the level. In Cyberhaven's 2025 edition, 34.8% of corporate data entering AI tools was classified as sensitive, up from 27.4% the year before and 10.7% two years before that. The sensitive share more than tripled in two years.
Netskope measures the same phenomenon from the network side. Generative-AI data-policy violations doubled year over year, and the average organisation now sees 223 such incidents per month. Regulated data, meaning personal, financial and health information, was the largest category of what was sent, ahead of source code, intellectual property and credentials. Personal cloud application instances were involved in 60% of the insider-threat incidents Netskope recorded.
Where the data lands is the other half of the risk. Cyberhaven rated 82% of the 100 most-used generative-AI SaaS applications as medium, high or critical risk on data handling, model security, compliance and access control. A prompt into a free consumer tier is not just a governance gap; in many cases it is a licence for the provider to retain and train on the content.
What it costs when it goes wrong
IBM's 2026 study interviewed 602 organisations that suffered a breach between March 2025 and February 2026, across 16 countries and 17 industries. The global average cost of a data breach reached $4.99 million, up 12% in a year and the highest in the 21 editions of the study. The United States averaged $11.5 million.
AI now shapes both sides of that number. More than one in four malicious breaches were AI-enabled, a 56% increase on the previous year, with deepfake impersonation the most common technique at 45%. An AI-driven attack cost $6.04 million on average against $5.03 million for a malicious breach without AI, a premium of roughly $1 million. Most of those attacks, 62%, targeted critical-infrastructure sectors, where financial-services breaches averaged $6.3 million and energy breaches $5.2 million.
Shadow AI has its own line in the data. Breaches involving unsanctioned AI averaged $5.39 million in 2026, and about one in five AI-related incidents drew a regulatory fine. The 2025 edition had already isolated the premium: organisations with high levels of shadow AI paid $670,000 more per breach than those with little or none, exposed customer personal data in 65% of cases against a 53% average, exposed intellectual property in 40% against 33%, and took 247 days to identify the breach against 241 for the average incident.
The same study contains the one encouraging cost figure. Organisations that used AI and automation extensively in their security operations cut breach costs by almost $2 million. One in four had not adopted those tools at all.
The governance gap is widening, not closing
The number that should worry boards is not the breach cost but the direction of travel on controls. In IBM's 2026 sample, 68% of breached organisations had no AI governance policy: 35% had none at all and 33% said one was in development. A year earlier the figure was 63%. Of the organisations that suffered an AI-related breach, 92% lacked proper AI access controls, an improvement of only five points on the 97% recorded in 2025.
Adoption of specific controls fell too. Of the six AI-governance controls measured in both years, five lost ground. Strict approval processes for AI deployments, the most common control, dropped from 45% to 38%. Only 19% of organisations reported any coordination between their governance and security teams, which is the practical reason policies exist on paper without changing anything in the network.
Netskope's data shows the same gap from the technical side: 23% of organisations have no real-time controls capable of detecting or blocking data leaving through personal cloud applications. It also shows that controls work where they are applied. The fall in personal-account use from 78% to 47% did not happen because employees lost interest; it happened because organisations provided managed alternatives and steered people to them.
The European angle: a GDPR and NIS2 problem, not an "AI problem"
When an employee pastes a customer list into a personal chatbot account, the security vocabulary calls it shadow AI. The legal vocabulary calls it a transfer of personal data to a third-party processor with no contract, no legal basis and no record. That is why one in five AI-related incidents in IBM's data ended in a fine.
The enforcement pattern in Romania illustrates the exposure. The data-protection authority, ANSPDCP, issued 105 fines in 2025 totalling about 2.57 million lei, roughly €511,000, up from 83 fines the year before, according to its 2025 activity report. The most common ground for sanction was the absence of adequate technical and organisational measures and of periodic testing, which is precisely the failure that unmonitored AI use creates. For the estimated 160,000 entities in scope of NIS2 across the EU, unsanctioned AI also lands under the supply-chain and data-governance obligations of Article 21, and the EU AI Act's transparency obligations that began applying on 2 August 2026 add a further layer. Romanian companies can check which obligations apply to them with our free GDPR and NIS2 obligations checker by CAEN code (in Romanian), and the wider compliance picture is covered in our NIS2 compliance statistics for 2026.
What the data says actually works
Four conclusions follow from the figures rather than from vendor marketing.
Blocking pushes use underground. Cyberhaven's own finding is that broad attempts to block AI rarely reduce risk; they move usage outside the controls that could see it. Netskope's 31-point drop in personal-account use came from organisations offering sanctioned tools, not from firewall rules.
Visibility has to sit where the paste happens. The distinguishing signal in every dataset above is the account, not the application: corporate identity versus personal identity in the same browser tab. Data-loss controls at the browser and endpoint layer are what make that distinction enforceable, and they belong inside a broader programme of network security and infrastructure hardening.
Some workloads should never leave your infrastructure. Source code, customer records and regulated data are the categories that dominate the leakage figures, and they are also the workloads where a self-hosted model on on-premises Linux infrastructure removes the third-party question entirely. Our self-hosted AI content moderation work follows that principle, and so does our approach to AI integration and automation.
Write the policy, then audit against it. IBM's 2025 data found that only 34% of organisations with an AI governance policy audited regularly for unsanctioned use. A policy nobody checks is indistinguishable from no policy, which is what the 68% figure is really measuring.
Common misreadings of the shadow AI numbers
- $670,000 is a premium, not an average. It is the additional cost of a breach at organisations with high shadow-AI use compared with those with little or none, from IBM's 2025 report. It is frequently misquoted as the average cost of a shadow-AI breach, and frequently attributed to the 2026 report, which reports a $5.39 million average instead.
- 43% is a share of AI-related incidents, not of all breaches. IBM's 2026 figure describes how often shadow AI featured within incidents that involved AI systems, up from 20% the prior year.
- "80 to 90% of employees use shadow AI" has no primary source. Figures in that range circulate widely, but the measured datasets put personal-account use at roughly a third to a half of AI users, and definitions differ from one study to the next. Quote a range and name the study.
- Telemetry and surveys are not interchangeable. Netskope and Cyberhaven observe behaviour; IBM and Ponemon interview breached organisations. When two figures disagree, that difference in method is usually the reason.
Methodology and sources
This page draws on four recurring datasets: the IBM and Ponemon Institute Cost of a Data Breach Report (2025 and 2026 editions; 600 and 602 breached organisations respectively, 16 countries), the Netskope Cloud and Threat Report 2026 (network telemetry, October 2024 to October 2025), the Cyberhaven AI Adoption & Risk Report (2025 and 2026 editions, browser and endpoint telemetry), and the Verizon 2025 Data Breach Investigations Report. Romanian enforcement data comes from ANSPDCP's 2025 activity report. Where a figure is available only in a press release, we link the release. We exclude figures we could not trace to a primary source. You are welcome to cite any statistic on this page with a link back; each one already carries its original attribution.
Frequently asked questions
What is shadow AI?
Shadow AI is the use of AI tools, models or agents inside an organisation without the knowledge, approval or oversight of the IT or security function. The most common form is an employee using a personal account on a public chatbot for work tasks, but it also covers unsanctioned browser extensions, API keys created outside procurement and departmental tools nobody registered.
How common is shadow AI in 2026?
Among employees who use generative AI at work, 47% still use personal accounts according to Netskope, and about one third according to Cyberhaven. Both figures come from organisations that monitor AI use; the share in unmonitored companies is unknown.
How much does a shadow AI breach cost?
IBM's 2026 study puts the average cost of a breach involving shadow AI at $5.39 million, against a $4.99 million global average. Its 2025 study measured a $670,000 premium for organisations with high shadow-AI use.
Is shadow AI a GDPR violation?
It can be. Entering personal data into a tool that has no processing agreement with your organisation is a transfer without a legal basis, and IBM found that about one in five AI-related incidents resulted in a regulatory fine. Whether a specific case is a violation depends on the data, the tool's terms and the organisation's own policies, which is a question for your data-protection officer or legal counsel.
