Regulation3 min read

Shadow AI Is Now a Boardroom Risk, Not Just an IT Problem

June 2, 2026Synthesized from 1 source: MarkTechPost

Employees across every industry are using personal AI accounts to handle client data, internal documents, and proprietary information without company oversight, and the financial and regulatory consequences are now large enough to appear on board agendas.

There is a simple reason shadow AI exists: employees are trying to do their jobs better, and the tools available on their personal accounts are often better than what their employer provides. An IBM study found that nearly 40 percent of workers prefer external AI tools specifically because of better features. The company banned the tool; the employee found another one. That is the entire story.

The data behind this is striking. IBM's 2025 Cost of a Data Breach Report, based on real incidents from 600 organizations across the world, found that one in five data breaches now involves employees using AI tools without company approval. Breaches of this kind cost an average of $4.63 million, versus $3.96 million for a standard breach. That extra $670,000 per incident is what ungoverned AI use adds to the bill. For the first time in 20 years of tracking, shadow AI displaced security skills shortages from the top three most expensive breach factors.

The types of data moving through these personal accounts are not trivial. Source code is the single most common category, followed by regulated customer data, internal strategy documents, and financial projections. In healthcare, 89 percent of AI-related data violations involve regulated patient information. In any law firm where associates are drafting client communications using personal ChatGPT accounts, that data has left the building entirely, with no enterprise control layer.

Netskope, which monitors cloud traffic across thousands of enterprise clients, found that data policy violations tied to AI tools more than doubled in a single year. The average company is now recording 223 such violations per month. Among the busiest 25 percent of organizations, that figure rises to 2,100 incidents every month. The volume of data being sent to AI services grew six times over the same period.

Blocking specific tools does not solve this. Netskope found that roughly 90 percent of organizations block at least one AI application, yet violations keep rising. When a company blocks ChatGPT on its network, employees open it on a personal mobile connection or log into a personal account. The behavior does not stop; it just becomes invisible. This is exactly what happened at Samsung in 2023, the most documented example of shadow AI gone wrong. The company lifted a ChatGPT ban, gave employees a memo-based limit on how much text they could paste, and within 20 days had three separate incidents involving proprietary semiconductor code. Samsung then banned the tool entirely. Employees moved to other tools.

The more serious and less-discussed version of this problem is not individual employees pasting documents. It is employees building their own small automated systems. Using tools like Microsoft Copilot Studio, or direct connections to AI models via simple programming interfaces, non-technical staff are creating automated workflows that connect to company email, CRM systems, and calendars. These systems run on their own, continuously, with no IT review. Gartner forecasts that 40 percent of enterprise business software will include these self-operating AI features by the end of 2026, up from under 5 percent in 2025. That growth is already happening in most organizations, and most of it is not being tracked.

The regulatory dimension is the least appreciated part of this. The EU's AI law reaches its main enforcement phase on August 2, 2026. It covers AI used in employment decisions, credit assessments, education, and other consequential areas. The fines for non-compliance go up to 3 percent of global annual revenue for violations in high-risk categories. Crucially, the law presupposes that companies know exactly which AI systems they are running. Shadow AI, by definition, is not on any inventory. Over half of organizations currently have no systematic list of AI systems in use inside their business. That is not a compliance posture. It is an audit liability waiting to surface.

The Deloitte 2026 State of AI in the Enterprise report found that while employee access to AI rose by 50 percent in 2025 alone, only one in five companies has a mature governance model to oversee how that AI is actually being used. The gap is not closing. Leadership behavior makes it worse: a survey by security firm BlackFog found that 69 percent of C-suite and senior executives say they are comfortable with unsanctioned AI use, prioritizing speed over governance. A governance policy that leadership does not follow has no authority over anyone else.

The companies handling this best have made one practical shift. They stopped treating shadow AI as a security violation to stamp out, and started treating it as a signal about what their employees actually need. When approved enterprise tools are genuinely good enough for the tasks employees are trying to do, unauthorized usage drops sharply. When they are not, no policy document changes anything. The inventory comes first, the approved alternatives come second, and the controls follow both.

Stay informed

Get AI intelligence like this delivered to your inbox.


You May Also Find Valuable