Quick Facts
- More than 80% of workers use unapproved AI tools, and one in five organizations has experienced a breach linked to unsanctioned AI, according to IBM’s 2025 Cost of Data Breach Report.
- 67% of enterprise AI usage runs through unmanaged personal accounts on corporate-licensed platforms like Microsoft 365, according to Teramind research.
- AI-associated breaches now cost organizations more than $650,000 per incident, with insider risk driven by AI negligence costing $10.3 million annually.
Shadow AI is growing faster than most security teams realize, and the biggest threat is not rogue apps. It is the AI baked into software companies already pay for.
Leeron Walter, VP of Strategy at Teramind, told TechRadar that shadow AI covers any AI usage operating outside organizational visibility, whether through banned apps, personal accounts, or AI features embedded in licensed tools. “Your licensed Microsoft 365, your PDF reader, your CRM — they all have AI features now,” Walter said.
The Numbers Are Getting Worse
Teramind’s 2026 Shadow AI Behavior Report found 485% year-over-year growth in corporate data sent to AI tools. Forty percent of generative AI file uploads contain regulated PII or PCI data.
The Verizon 2026 Data Breach Investigations Report shows the pace of adoption inside enterprises nearly tripled in one year. In the 2025 dataset, 15% of employees were classified as regular AI users on corporate devices. By 2026, that figure reached 45%.
The average enterprise now experiences 223 data policy violations per month related to AI usage, according to Netskope’s 2026 data. GenAI traffic surged more than 890% in 2024. Menlo Security reported a 68% surge in shadow generative AI usage across enterprises in 2025.
Leadership Is Part of the Problem
Teramind’s Shadow AI Behavior Report, based on research from 300 C-level security executives, found that 69% of C-suite leaders prioritize speed over security when using AI tools. Only 37% of frontline employees said the same.
Gal Perl, Chief Product Officer at Teramind, said the problem starts at the top. “When leadership teams prioritize speed over security, it becomes significantly harder to build a culture of accountability around AI use,” Perl said.
Eighty-six percent of organizations lack visibility into how data moves to and from AI tools, per Teramind’s research. Forty-five percent of U.S. workers have used AI at work without disclosing it. Forty percent said they would knowingly violate company policy if it meant completing a task faster.
The Enforcement Gap
Banning AI tools has not worked. Teramind’s research found that 48% of employees said they would use AI even if it were explicitly banned. One-third have already shared proprietary data with unsanctioned platforms. Forty-nine percent actively hide their AI use from IT.
Walter’s recommended fix is not more restrictions. “You fix it by making the secure option just as fast and frictionless as the risky one, and removing the tradeoff entirely,” Walter said.
The financial case for acting is direct. Shadow AI adds $670,000 to average breach costs. Spending on AI-native applications is rising 108% in 2025, averaging $1.2 million per organization. Seventy-eight percent of IT leaders reported unexpected SaaS charges tied to AI pricing models, up from 65% in 2024.
What Governance Actually Looks Like
Perl said the companies winning at AI governance are not the ones with the strictest policies. “They’re the ones with the clearest understanding of how AI is actually being used across their workforce,” Perl said.
Isaac Kohen, also a Chief Product Officer at Teramind, framed the issue plainly. “This isn’t a technology gap — it’s a governance gap. The answer isn’t less AI. It’s governed AI,” Kohen said.
For software and technology executives, the immediate priority is visibility. Companies cannot set policy around AI behavior they cannot see, and the data shows that behavior is already well underway inside tools already deployed across their organizations.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
