Twenty percent of breached organizations were compromised through shadow AI, defined as unsanctioned generative AI tools adopted by employees without security review, according to the IBM Cost of a Data Breach research. Those incidents carried approximately $670,000 in additional cost above the baseline average.
The global average cost of a data breach fell to $4.44 million, a 9 percent decline from $4.88 million in the prior reporting cycle. Shadow AI incidents ran counter to that improvement.
Exposure severity differs by incident type. Customer personally identifiable information appeared in 65 percent of shadow AI breaches against 53 percent across all breaches. Detection took 247 days in shadow AI cases, six days longer than the standard breach timeline, and longer dwell time correlates directly with higher total cost.
Governance gaps explain much of the pattern. Sixty-three percent of breached organizations in the study lacked any AI governance policy, and only 37 percent had approval processes or oversight mechanisms covering AI tool adoption. Among organizations reporting AI-related breaches specifically, 97 percent said they lacked proper access controls on the AI systems involved.
The 97 percent access control figure points to deployment moving ahead of the identity and permission work that normally accompanies a new data-handling system.
Source: IBM - https://www.ibm.com/reports/data-breach