Quick answer: Shadow AI, meaning employees using AI applications without security approval, was involved in 43% of security incidents at breached organizations this year, more than double the 20% recorded a year earlier, according to IBM's Cost of a Data Breach Report 2026. Those incidents carried an average breach cost of $5.39M, up from $4.63M last year, and roughly one in five of them resulted in a regulatory fine. The same research found AI governance moving in the wrong direction. 68% of breached organizations had no governance in place to manage AI or detect shadow AI, worse than the 63% reported last year. Organizations are writing AI policies faster than they're building any way to apply them, and this year the difference was reflected in breach costs.
What IBM's 2026 report found about shadow AI
IBM's Cost of a Data Breach Report 2026, conducted by Ponemon Institute across 602 breached organizations in 16 countries and 17 industries, made shadow AI a headline finding for the first time rather than a mere footnote in the AI chapter.
Shadow AI is the use of AI applications, models, or agents by employees without the knowledge or approval of the security team. It differs from an AI-related breach in an important way; the AI system itself is not being attacked. Nobody is poisoning a model or inverting one to extract training data. An employee is simply using a tool the organization cannot see, and organizational data is going into it.
The distinction matters because both categories grew this year. IBM found AI-related breaches rose to 21% of organizations from 13%, while shadow AI involvement in security incidents jumped to 43% from 20%. Shadow AI is the larger of the two, and it's growing faster.
The consequences IBM recorded for shadow AI incidents were concentrated in data rather than downtime. Data loss or compromise appeared in 49% of them. Operational disruption followed at 42%, reputational damage at 35%, and increased security costs at 32%. New to this year's research, 21% of shadow AI incidents involved organizations paying a regulatory fine.
Why shadow AI incidents got more expensive, not just more common
Most coverage has focused on the volume increase. The cost increase deserves more attention than it's getting.
Average breach costs for shadow AI incidents rose to $5.39M from $4.63M. For context, IBM put the global average cost of a data breach this year at $4.99M, itself a 12% increase and an all-time high, working out to roughly $1,100 per hour. Shadow AI incidents sat above that average.
Two structural findings in the same report help explain why. First, IBM's analysis of thirty cost factors found that a lack of visibility into the number and location of applications added $201,165 to average breach costs, the third most expensive amplifying factor IBM measured. Second, non-compliance with regulations added $201,112. Shadow AI tends to produce both conditions at once. The applications can't be inventoried, and the data moving through them is usually regulated.
The data being lost compounds it. IBM found customer personally identifiable information (PII) was the most frequently compromised data type at 52% of breaches, costing an average of $192 per record, while intellectual property was the costliest category at $196 per record. These are precisely the categories that move through an AI prompt window or a file upload; customer records being summarized, source code being debugged, contracts being reviewed.
Why AI governance moved backwards in 2026
The most troubling finding in the report is not the shadow AI number itself. It is that oversight got thinner while exposure grew.
IBM found 68% of breached organizations lacked AI governance to manage AI or detect shadow AI, up from 63% the previous year. Organizations with policies actually in place fell to 32% from 37%. The share still developing a policy rose to 33% from 22%, which suggests plenty of activity without much control to show for it.
The specific controls declined across almost every category IBM measured. Strict approval processes for AI deployments fell to 38% from 45%. Use of AI governance technology fell to 33% from 39%. Employee training on AI risks fell to 30% from 36%. Regular audits for unsanctioned AI, the control aimed most directly at shadow AI, fell to 29% from 34%. And when IBM asked for the first time about coordination between governance and security teams, only 19% of organizations reported any.
"A policy no one can see being followed isn't a control, it's a hope. If you can't see the sensitive data moving in real time, you can't govern it — you're just documenting intent.," says Yair Cohen, Co-Founder and Chief Product Officer at Sentra. "That's the gap this year's research exposes: organizations are writing AI policies faster than they're building any way to apply them."
Why shadow AI is a data problem, not an application inventory problem
Faced with a 43% figure, most teams start by going after the applications: build the inventory, publish the approved list, block the rest.
That covers the visible half of the problem and leaves the expensive half intact. Approving an AI application is a decision about a tool, and it says nothing about the data going into it. The same customer record carries the same regulatory weight whether it lands in a sanctioned enterprise assistant or a consumer chatbot. An inventory can tell you where data might have gone. It can't tell you what actually went.
IBM's own recommendations point the same direction. In the report's guidance on AI sovereignty, IBM advises that monitoring how data enters, transforms within, and exits AI systems helps organizations proactively identify sensitive data exposure risk, strengthen governance and compliance, and scale AI adoption securely. It further frames establishing control as limiting unnecessary data movement and maintaining clear visibility across workloads. That's a prescription aimed at the data layer rather than the application list.
The economics in the report support it. Data security and protection software, the category IBM identifies with data security posture management, was associated with a USD 198,259 reduction in average breach costs. Set against the USD 201,165 that application visibility gaps added, the swing across that single axis comes to roughly USD 400,000.
"The reason shadow AI is a hard problem to govern is that you need to understand the data, and the risks involved with sending it out." says Ron Reiter, Co-Founder and CTO at Sentra. "One user might have a legitimate, governed session open with ChatGPT, whereas on another tab he might be sending out information to a non-governed, shadow session, which will later on take that piece of information and train models on. And being able to differentiate between sensitive and non-sensitive data in the age of AI, where AI rewrites each and every piece of data, is a very hard problem to solve."
What security teams should do about shadow AI in 2026
Three practical implications follow from the 2026 findings.
Treat discovery and enforcement as one program, not two. IBM's finding that only 19% of organizations coordinate governance and security teams suggests these are usually run by different people on different timelines. Knowing which AI applications employees use is worth little without some ability to act at the point of use. Enforcement on its own only ever covers the tools already on the list.
Classify before you enforce. Pattern matching can tell you whether content resembles something sensitive. Classification tells you what the content actually is. That difference drives both how much legitimate work gets blocked and how much regulated data slips through in paraphrased form. It's the case for treating continuous data discovery and classification as the foundation of an AI governance program rather than a parallel workstream, and for in-place scanning, where sensitive data never leaves the customer's environment while it's being classified.
Assume the regulator is now part of the equation. The 21% fine rate on shadow AI incidents is new to this year's research. The evidentiary standard is shifting from documented policy toward demonstrated enforcement.
The frontier context makes the timeline shorter. IBM opened this year's report by citing the April 2026 announcement of a frontier model capable of finding thousands of high-severity vulnerabilities, including in every major operating system and web browser, and referenced a UC Berkeley projection that AI will favor attackers over defenders by 31.7% within two years. Organizations responded: 85% told IBM they plan to increase security spending because of frontier AI model threats, up from 64% before they were aware of them. The budget is moving. Whether it reaches the data layer or stops at the model layer is still an open question.
An inventory can tell you where data might have gone. It can't tell you what actually went.
