Unsanctioned use of AI tools inside organizations, often called shadow AI, has emerged as a measurable driver of security breaches, according to data drawn from industry research. Shadow AI was linked to 20 percent of breaches in 2025 and added about 670,000 dollars in cost to each affected incident. The pattern reflects employees adopting AI applications outside formal approval, which creates blind spots for security teams.

The underlying gaps are stark. Among organizations that suffered a breach of an AI model or application, 97 percent lacked proper AI access controls, and 63 percent reported having no AI governance policy or only a developing one. Broader figures show the scale of exposure. A large share of businesses reported an AI related security incident, with some studies placing the average cost of such incidents in the millions of dollars per event.

The data points to a governance lag, in which adoption of AI tools has outpaced the controls needed to secure them. Analysts note that shadow AI is difficult to eliminate because the tools are easy to access and often boost productivity, which encourages informal use. The figures suggest that closing the gap depends on visibility and policy, identifying where AI is used, applying access controls, and establishing governance before an incident occurs rather than after.

Source: Shattered.io - https://shattered.io/shadow-ai-breaches-670k/