Breaches involving shadow AI cost organizations about $670,000 more than standard incidents, according to an analysis of IBM's Cost of a Data Breach research. Shadow AI refers to unauthorized AI tools and applications that employees use without approval or oversight from their information technology teams.
The prevalence is significant. One in five organizations reported a breach tied to shadow AI, yet only 37 percent had policies in place to manage AI use or detect unauthorized tools. That gap leaves many companies unaware of which AI applications employees are using and what data those tools can reach.
Shadow AI incidents also tended to expose more sensitive information. These breaches compromised customer personal data in 65 percent of cases, compared with a 53 percent global average, and carried a higher cost per record at $166 versus $160. The pattern suggests that unsanctioned AI tools often handle data the organization did not intend to route through them.
The figures sit against a broader backdrop of breach costs. The global average cost of a data breach was $4.44 million, down 9 percent from the prior year, while incidents involving heavy shadow AI use ran closer to $4.63 million. The data points to unmanaged AI adoption as a measurable driver of breach severity, and to governance and monitoring as the controls that limit the added exposure.
Source: Kiteworks - https://www.kiteworks.com/cybersecurity-risk-management/ibm-2025-data-breach-report-ai-risks/
![[Data] Shadow AI adds $670,000 to the average breach cost](https://cdn.sanity.io/images/cbhtovty/production/35078801c61558680f4038acf02407dcb60dc107-1200x628.jpg)