Quick Facts

  • 93% of employees are putting company data into unauthorized AI tools, with nearly one-third sharing confidential client information
  • Shadow AI incidents add an average of $670K to breach costs, with 20% of organizations experiencing breaches linked to unsanctioned AI tools
  • Small businesses face the highest risk, averaging 269 shadow AI tools per 1,000 employees while lacking security resources to monitor them

Employees are feeding sensitive company data to unauthorized AI tools at alarming rates, creating massive security risks that most organizations cannot see or control.

New research shows 93% of workers are putting company data into unsanctioned AI tools. Nearly one-third admit to sharing confidential client information through these platforms. The practice has spread far beyond early adopters, with 78% of AI users bringing their own tools to work.

The financial impact is severe. Shadow AI incidents add an average of $670,000 to breach costs. One in five organizations has experienced breaches linked to shadow AI tools that lack IT oversight.

“Shadow AI is a fatal flaw for most organizations,” said Sathish Sagayaraj Joseph, regional technical head at ManageEngine. “IT teams can’t manage risk they can’t see.”

Small businesses face the greatest exposure. Companies with 11-50 employees see 27% of workers using unsanctioned AI tools. These organizations average 269 shadow AI tools per 1,000 employees while lacking security resources to monitor the sprawling attack surface.

The data exposure follows predictable patterns. Among breached organizations, 53% reported compromised customer information. In shadow AI breaches, that figure jumps to 65%. Companies average 223 monthly incidents of users sending sensitive data to AI applications.

Business leaders remain disconnected from the reality on the ground. While 52% of C-level executives report being very familiar with generative AI uses across their companies, only 11% of employees share that understanding.

“We’re facing a full-blown governance crisis,” said Dan Adika, CEO of WalkMe. “When nearly 80% of employees are using shadow AI tools, organizations are not just losing money – they’re losing control.”

The security landscape continues evolving rapidly. Phishing attacks now account for 77% of all incidents, up from 60% in 2024. Security experts attribute the spike to rapid AI adoption among threat actors.

Enterprise cybersecurity budgets are responding to the threat. Seventy-eight percent of business and technology executives plan to increase cyber spending in 2026, according to a survey of 3,887 leaders conducted between May and July 2025.

Organizations that experienced AI-related breaches show consistent security gaps. Ninety-seven percent lacked proper access controls, highlighting fundamental governance failures.

Despite massive investments in formal AI initiatives, returns remain elusive. Companies have poured $30-40 billion into generative AI programs, yet 95% report zero impact on profit and loss statements.

Security teams must act quickly to establish baseline AI usage controls and comprehensive analytics. The alternative is continued exposure to threats they cannot see or manage.

Read more: Your employees are using AI, whether you like it or not – but are they using AI securely?

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.