Quick Facts
- 63.6% of vendors advertising AI capabilities don’t disclose third-party AI subprocessors in legal documents
- Organizations with shadow AI face average breach costs of $4.63 million, $670,000 higher than those without
- 42% of companies abandoned AI initiatives in 2025 due to data privacy concerns
Most companies purchasing AI-enabled software unknowingly expose customer data to artificial intelligence models they never approved or reviewed, according to new research from DataGrail.
The privacy management platform analyzed 2,400 popular business software providers and found that 63.6% of vendors prominently advertising AI capabilities fail to disclose third-party AI subprocessors in their legal documentation.
“All software vendors are trying to move to become AI vendors, which makes sense, but the technologies are moving faster than AI governance can actually keep up,” DataGrail CEO Daniel Barber told VentureBeat.
Hidden AI Creates Major Risk
Among AI systems that do disclose capabilities, 32.8% also engage in other high-risk activities like processing sensitive personal information or powering automated decision-making. The breakdown shows 47.1% process personal data, 20.7% enable automated decisions, 16.5% handle sensitive health or financial data, and 7.5% process biometric information.
The financial impact proves substantial. Organizations with high levels of shadow AI experience average breach costs of $4.63 million — $670,000 more than those with minimal or no shadow AI, according to IBM’s 2025 Cost of Data Breach Report.
Privacy Enforcement Accelerates
Regulatory pressure continues mounting as nearly half of U.S. states now enforce comprehensive privacy laws alongside over 160 AI-specific regulations. California alone reported $4.3 million in CCPA consent settlements, while 2025 saw over 1,400 class action wiretapping suits targeting tracking pixels and session replay software.
Data brokers face the heaviest burden with deletion requests up 398% compared to 2024, averaging over 2,000 monthly requests. The cost of handling consumer privacy requests manually has increased sixfold since 2021.
Future Outlook
DataGrail predicts over 80% of software will include AI capabilities by year-end as vendors race to add AI features faster than legal and privacy teams can review them. Gartner forecasts 40% of enterprise applications will feature task-specific AI agents by end of 2026, up from under 5% in 2025.
“The companies that survive the next chapter will not be the ones with the biggest compliance teams,” Barber said. “They will be the ones that accept a disorienting new reality: in 2026, the contracts you signed may not describe the AI that is already processing your customers’ data.”
Read more: DataGrail report finds your vendor may be sending data to AI models you never approved
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
