Finance, HR and marketing departments are building software. Small AI tools that do one piece of a job on their own, made by the person who wanted them, with no ticket raised and nobody reviewing the result.
Take a clerk in accounts payable with a backlog of supplier invoices. She describes the job in ordinary sentences and gets back a working script: open the shared mailbox, read each invoice, match it against the purchase order, write the figures into the ledger. It runs every morning after that, under her login, and it keeps running after she moves to another team.
IBM's breach data attributes a bigger share of costly breaches to tools built this way than it did a year ago. Counting them does not require reading any code. Each one can be listed by what it can open: the mailbox, the customer records, the payment file, and the login it uses to get in.
In IBM's Cost of a Data Breach report, one in five organizations reported a breach involving staff use of unapproved AI tools, and those breaches cost about $670,000 more than the average. Of the breached organizations that had an AI-related incident, 97% said they lacked access controls around AI. Of the 600 organizations the Ponemon Institute surveyed for the same report, 63% had no policy on AI use at all.