
Unapproved AI tools appeared in 43% of security incidents in IBM's latest breach study.
getty
Shadow AI, meaning the tools staff adopt without approval, turned up in 43 percent of security incidents last year, roughly double the share the year before, and 68 percent of the companies that were breached had no policy governing AI use at all. Those figures come from IBM's Cost of a Data Breach Report 2026, published on July 29 and drawn from 602 organizations breached between March 2025 and February 2026, with the shadow AI share sitting in the report itself rather than in IBM's announcement of it. Four days later, Article 50 of the EU AI Act, its transparency provision, became binding and required companies to disclose when a person is dealing with a machine. That is the easy half of the law, satisfiable with a line of text on a chat window. Writing the line means knowing which systems need it, which is where the 68 percent starts to matter.
The Scrutiny Went To The Vendors And The Shadow AI Risk Stayed Home
Risk committees have spent two years on model behavior: hallucination, bias, poisoning, misalignment. The work is real, and it is aimed at the part of the problem that already has the most eyes on it. Three to five large vendors supply the models that most enterprise tools run on, those vendors absorb the regulatory scrutiny and the guardrail spending, and a large share of the AI products sold into enterprises are wrappers around the same handful of systems. The exposure nobody is watching sits a layer down, in how staff and software agents actually use the things.
Yakir Golan, chief executive and co-founder of Kovrr, a risk quantification company that built its business converting cyber exposure into the financial language boards already speak and is now pointing the same probabilistic machinery at AI, has a figure for the split. He was careful to say he had not measured it, and that it is a read taken off years of client calls rather than off any dataset. "70 to 75% usage risk and 25% model risk... but companies should manage as if it were 90 to 95% usage risk and 5 to 10% model risk. Top models get heavy scrutiny; internal enterprise use is neglected."
The percentages are a practitioner's read on where attention has gone, and the reasoning underneath them is easier to test. It puts the marginal risk in permissions, data flows and vendor connections inside the buyer's own network, which is roughly where IBM found it. Incidents involving an organization's own AI models and applications rose to 21 percent from 13 percent year over year, and among the companies whose AI systems came under attack, 92 percent had failed to control access to those tools properly. Those are figures from companies that had already been breached, so they describe failure rather than the wider economy. Access control is still a usage failure that gets filed under model risk, and it is the same failure that surfaces when an agent keeps standing permissions on a mailbox or a code repository long after the person who set it up has changed teams.
Disclosure Presumes An Inventory
The Digital Omnibus on AI became Regulation (EU) 2026/1744, published in the Official Journal on July 24 and in force from July 27, and it pushed the standalone high-risk obligations under Annex III out to December 2027 and high-risk AI embedded in regulated products to August 2028. Article 50 was not touched. Since August 2, providers have had to tell people when they are interacting with an AI system and mark synthetic content so machines can detect it as artificially generated, while deployers must disclose emotion recognition, biometric categorization and published deepfakes, with no deferral on the deployer side at all. The single concession delays the machine-readable marking requirement to December 2026, and only for systems already on the European market before August 2. None of it can be done by a company that has never cataloged what it runs.
MORE FOR YOU
The evidence on what companies have cataloged points one way. UpGuard's State of Shadow AI survey, published in November 2025 from 500 security leaders and 1,000 employees, found 81 percent of employees and 88 percent of security leaders reporting use of AI tools their employer had not approved, and 45 percent of workers saying they find workarounds when an application is blocked. The numbers are self-reported and UpGuard sells tooling in the category, so treat them as direction rather than measurement. What survives that discount is a gap between the AI a company has approved and the AI its staff are using, and the second estate rarely shows up as a line anyone signed off in the accounts.
Golan sees the same gap from the demand side, in what clients ask for when they call. "Although people came to us and asked for what's the exposure and how to prioritize remediation... there is a big gap on visibility as well, which is directly tied to quantification. You need to know in close to real time what's going on... visibility is the key now." His top three usage risks are data leakage, bad permissions and third-party vendor exposure, and none of the three is visible to a company that maps only what it has approved. Kovrr's answer is to pull telemetry from browsers and secure browser extensions, endpoints, network traffic, identity and data governance systems, and third-party model activity, then separate approved assets from shadow ones before any modeling begins. One large manufacturer, anonymized in his account, mapped its AI assets, used the output to support an assessment under NIS2, the EU's network and information security directive, then sequenced remediation across the two halves of 2026 by financial weight.
Underwriters Arrived Before The Regulators
Insurers moved earlier and more quietly, and the cost side of the IBM report explains why. The global average breach reached just under $5 million last year, up 12 percent and the highest IBM has recorded, and breaches in which attackers used AI ran about a million dollars above that. ISO, the Verisk-owned bureau that drafts standard policy wording for American insurers, has a generative AI exclusion in circulation for commercial general liability cover, form CG 40 47 01 26, carrying a January 2026 edition date. It removes protection for injury and damage "arising out of, or attributable to, generative artificial intelligence," it reaches both liability coverages, and it bites whether the insured used the technology directly or through a vendor. Carriers decide for themselves whether to attach it, so the accurate reading is that a standard route to exclude now exists and is turning up on policies as carriers choose to use it, rather than that every business has quietly lost its cover.
Affirmative cover exists on the other side of the same market, and it is small and hand-built. Munich Re's aiSure line covers contractual performance warranties, discrimination and intellectual property claims, hallucinations, regulatory fines and financial loss from AI errors, and the company says it has insured AI products and services since 2018. Armilla, backed by Lloyd's syndicates, began writing cover in May 2025 for losses caused by AI errors including hallucinations, paying damages and legal costs.
Underwriters price an unmapped AI estate the way a surveyor prices a building with no floor plan, at the worst case the missing drawings allow. But a surveyor can walk the building and draw the plan himself, and nobody can walk an AI estate, because it changes between the browser tabs open on Monday and the ones open on Friday. Asked how long before cover becomes standard, Golan put a number on it. "Mass-market off-the-shelf AI insurance scaling will take about two years... underwriters need confident visibility first."
The Number Is Only As Honest As The Map
The strongest objection to any of this comes from inside the discipline that invented it. In March 2024 the National Security Telecommunications Advisory Committee, or NSTAC, which advises the U.S. president on communications and cyber policy, reported that the security industry suffers from weak "metrics literacy" and runs mathematical operations on subjective qualitative judgments as though they were hard data. "Subjective measurements, combined with bad math, lead to ineffective decision-making," the committee concluded. Presenters to the committee, rather than the committee itself, said their own quantitative framework accounted for only 10 to 15 percent of the variance in breaches.
The critique was aimed at cyber, which has two decades of loss history behind it. AI quantification has a fraction of that, so the objection lands harder here than where it was first made. A model built on a partial inventory understates exposure and manufactures confidence at the same time, and the second failure is the more expensive one, because it reaches the board as a decision.
Golan's own sequencing concedes the dependency. "The quantification is the layer on top of asset mapping and usage monitoring... to power solid board reporting and prioritize compliance gaps with financial weighting." Committee and practitioner agree that quantification is worth no more than the visibility underneath it, and disagree about what follows from that. The committee's finding implies the output deserves suspicion even once the inventory is complete, while Golan's clients pay him to make it trustworthy. The NSTAC findings were not put to him in the interview.
Golan does not think regulators are moving fast enough, and his read on boards is that investor pressure to adopt AI still outweighs any pressure to govern it. One of his clients installed a secure browser extension to watch where staff were sending corporate data, then turned the same extension into a block on traffic heading for Chinese models. No regulator asked for that and no underwriter required it. It happened because somebody could finally see the traffic. Every other company will be asked the same question eventually, by a carrier's questionnaire or a regulator's notice, and will answer it with whatever it happened to install before anyone thought to ask.
>> Home