The Signal FilesManaging the MachinesField Synthesis

Shadow AI just got a price tag

Unsanctioned AI showed up in 43 percent of breached organizations this year, more than double last year's share. The tools aren't the problem. The blindness is.

~1,700 WordsFour Cited SourcesStop Trying To Be Invisible

On July 29, 2026, IBM published the number that moves shadow AI from worry to line item. In its annual Cost of a Data Breach study, 43 percent of breached organizations reported security incidents involving shadow AI: models, tools, and agents running inside the business that nobody sanctioned, vetted, or in many cases even knew existed. One year earlier, the same study measured 20 percent. The figure more than doubled in a single reporting cycle. Shadow IT needed a decade to graduate from nuisance to board topic. Shadow AI has crossed from policy risk to a measured breach-cost item in a year.

IBM Newsroom, "IBM Study: One in Four Malicious Breaches Are AI-Enabled, Costing Companies $6 Million on Average," July 29, 2026.

Two honesty notes before the argument. This is a field synthesis: we read the primary material and assemble the through-line. And the figures that carry it come from a single vendor's study (IBM's, run with the Ponemon Institute), so we attribute them inline throughout, and bring in an independent measurement where one exists. Where the study stands alone, we say so.

Section OneThe number that doubled

First, be precise about the thing itself, because the name undersells it. Shadow IT was the file-sharing account a marketing team paid for without asking, the unofficial project tracker, the spreadsheet macro nobody documented. Unsanctioned, occasionally expensive, and passive. It sat still until a person used it. Shadow AI is unsanctioned software that acts: the chatbot an analyst pastes customer records into, the browser plugin wired into the company mailbox, the coding agent with API keys that keeps working after its owner goes home. The category didn't just grow. It changed state.

Note what IBM's study is measuring, because the narrowness is what makes the movement loud. This is not a sentiment survey about vague unease with AI adoption. It is the share of actually breached organizations whose security incidents involved shadow AI, and that share went from 20 percent to 43 percent between the 2025 and 2026 editions.

IBM, "Cost of a Data Breach Report 2026," July 29, 2026; prior-year figure from the 2025 edition.

The growth mechanism explains why governance was caught flat-footed. Shadow AI is employee-led. It does not arrive through procurement, where contracts get reviewed and vendors get vetted. It arrives through a browser tab and a personal login, brought in by people trying to work faster, often your best people. There is no purchase order to flag, no deployment to gate, no vendor to audit. By the time a traditional control could notice, the tool is already inside the work.

Why it mattersEvery classic security control watches a chokepoint: the procurement pipeline, the deployment process, the network perimeter. Employee-led AI crosses none of them. The controls aren't failing at their job. They are pointed at doors this software never walks through. That is why the incident share can double in a year while the org charts show nothing changed.

Shadow IT waited to be used. Shadow AI acts on its own.

Section TwoThe governance void

The reflexive answer is a policy. Here the study's second number lands: 68 percent of breached organizations had no AI governance policy at all. Not an inadequate one: none. And the void is widening, not closing: the 2025 edition measured 63 percent.

IBM, "Cost of a Data Breach Report 2026," July 29, 2026.

Hold the two curves side by side. Shadow-AI incidents doubled year over year; in the same window, the share of breached companies without even a written position on AI governance rose five points. The behavior is compounding faster than the paperwork, and the paperwork is losing ground. Whatever the average organization is doing about AI risk, it is not writing down what an approved tool is, who may run one, or what data may enter it.

One limitation in that number's shape deserves naming: the study surveys breached organizations, so it cannot tell us whether policy-less companies get breached more, or breached companies simply reflect a general vacuum. Either reading is bad. The generous one says most organizations are unpoliced; the harsh one says the unpoliced ones are the ones bleeding.

You can't govern what you can't see. Most haven't written down what seeing would even mean.

Section ThreeWhat invisibility costs

Now the money, each figure tied to its window. IBM's 2026 study puts the global average cost of a breach at $4.99 million, up 12 percent year over year. Breaches in which the attackers used AI (a separate category from shadow AI, and we keep them separate deliberately) averaged $6.0 million, roughly a million-dollar premium over that baseline; the study found one in four malicious breaches were AI-enabled.

IBM Newsroom, "IBM Study: One in Four Malicious Breaches Are AI-Enabled," July 29, 2026.

The shadow-AI-specific anatomy comes from the 2025 edition. Breaches involving shadow AI carried roughly $670,000 in added average cost. They compromised personally identifiable information in 65 percent of cases, against a 53 percent average. And they took longer to shut down: 247 days to detect and contain, against 241.

IBM, "Cost of a Data Breach 2025: Navigating AI," 2025.

None of this is mysterious once you accept the premise. An incident responder can only contain what is on the asset register. When the breach runs through a tool that is on no register, every hour of the response starts with discovery: what is this thing, who ran it, what could it touch. The premium is not a punishment for using AI. It is the price of the blindness.

Section FourThe corroboration, and the caveat

Everything above comes from one vendor's study. IBM's is the most-cited breach ledger in the industry, but single-vendor is single-vendor, and this series does not launder survey findings into laws of nature. So: does any independent measurement point the same direction?

One does, with a different instrument. Cyberhaven Labs' 2025 AI Adoption & Risk Report (built on usage telemetry from roughly seven million workers, not post-breach interviews) found that 34.8 percent of the data employees put into AI tools is sensitive, up from 10.7 percent two years earlier. The 2026 edition, on a smaller panel and a slightly different metric, puts sensitive material at 39.7 percent of all AI-tool interactions. Different metric, different method, same shape: the flow of material that can hurt you, into tools nobody cleared, is rising steeply.

Cyberhaven Labs, "2025 AI Adoption & Risk Report" (telemetry across ~7 million workers); "2026 AI Adoption & Risk Report" (222 companies).

The honest counterweightCyberhaven's telemetry corroborates the direction, not the dollars. It cannot confirm IBM's cost figures, and IBM's interviews cannot confirm the telemetry. What the two independently agree on is the trend line: more sensitive material, into more unsanctioned tools, year over year. We treat the direction as solid and each precise magnitude as one vendor's measurement.

Section FiveThe register: visibility, pointed inward

Our thesis, across everything we publish, is that visibility decides outcomes: the machines now choosing who gets shown can only recommend what has been made legible to them. Shadow AI is the same law running in the other direction. An unregistered agent is an illegible one: no owner, no scope, no written trace of what it may touch. The illegibility is not a paperwork defect that makes a breach somewhat worse. On this evidence, the illegibility is the risk.

We run this studio on an agent workforce, so this is not abstract for us. The working rule we hold ourselves to is a register: every agent and every AI tool gets a name, an owner, a defined scope, and a written trace of what it can read and touch. What is not registered does not run. Not because a register stops an employee from opening a chatbot in a browser tab, but because it converts the question what is running here? from an investigation into a lookup. IBM's 2025 numbers show what the alternative costs: six extra days of searching, twelve extra points of PII exposure, two-thirds of a million dollars.

If you run a ten-person company rather than a ten-thousand-person one, do not file this under enterprise problems. The mechanism scales down cleanly: the smaller the team, the more likely the whole operation runs through tools one person adopted on a Tuesday and never wrote down. A small business does not need an enterprise governance program to be legible to itself. It needs one page (what runs here, who owns it, what it touches), kept current. That single page is most of the distance between the 43 percent and the rest.

Notice what the fix is not. It is not banning the tools. The doubling happened in the era of bans, and employee-led adoption routes around prohibition the way water routes around a stone. The organizations that will read well in next year's edition are the ones that made sanctioned AI easier to reach than shadow AI, and made registration the path of least resistance rather than a compliance tax.

In ClosingLegibility cuts both ways

The through-line of everything we publish is one claim: machines can only act on what they can clearly read. Outside your company, that decides whether the models recommending brands can see yours at all. Inside your company, it now decides whether you can see the machines already doing your work. Same law, both directions. IBM's study measured 43 percent because, in nearly half of breached organizations, nobody had made the inside legible.

The companies that come through the next few years intact will not be the ones with the strictest bans or the longest policies. They will be the ones who can answer, at any moment and from a written record, one question: what is running here, and who can read it? Legibility inward, legibility outward. It was always the same discipline.

If you want to know how legible your own brand already is to the machines that decide who gets shown, the Signal Index measures it. Or write to us at /contact/.

Figure 01 · Year Over Year
The breach-share that doubled while nobody was watching
20%
2025 edition. Share of breached organizations reporting security incidents involving shadow AI, in IBM's Cost of a Data Breach study.
43%
2026 edition. The same measure one reporting cycle later: more than doubled, while 68% of breached orgs still had no AI governance policy.
Single-vendor measurement, attributed as such: IBM Cost of a Data Breach, 2025 and 2026 editions.
Stop trying to be invisible.

Sources

  1. IBM Newsroom, "IBM Study: One in Four Malicious Breaches Are AI-Enabled, Costing Companies $6 Million on Average," July 29, 2026. newsroom.ibm.com
  2. IBM, "Cost of a Data Breach Report 2026," July 29, 2026. ibm.com/reports/data-breach
  3. IBM, "Cost of a Data Breach 2025: Navigating AI," 2025. ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
  4. Cyberhaven Labs, "2025 AI Adoption & Risk Report" (usage telemetry across ~7 million workers) and "2026 AI Adoption & Risk Report" (222 companies); corroborate the trend, not IBM's dollar figures. cyberhaven.com

The Signal Index

How clearly can the AI era see you?

A free, transparent score of how AI and search find, understand and recommend you. Instant, from your domain.

Get your Signal Index →

The Signal Files

Field notes on visibility, in your inbox.

The research behind how brands get seen now. The Signal Files, the moment they publish. No noise.

Double opt-in. Unsubscribe anytime.