Shadow AI by Developers Fuels Data Breaches, Costing Firms $670K Extra
Developers are increasingly using personal AI accounts for work tasks involving sensitive data, a practice known as shadow AI, which security experts say poses serious organisational risks. Verizon's 2026 DBIR found AI use on corporate devices tripled in one year, with 67% running through personal accounts invisible to employers. IBM's 2026 Cost of a Data Breach report linked shadow AI incidents to 43% of breached organisations, adding roughly $670,000 to average breach costs. In May 2025, CB Financial Services filed an SEC disclosure after an employee processed customer Social Security numbers through an unauthorised AI tool — believed to be the first such regulatory filing. Security experts argue that outright bans drive usage further underground, and recommend instead that organisations establish clear AI policies, provide approved enterprise tools, and train employees on safe data-handling habits.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in