Shadow AI Just Made Your Next Data Breach $670,000 More Expensive

Last week I finished reading two back-to-back reports that should make every business leader sit up straight. IBM’s 2025 Cost of a Data Breach report and Verizon’s latest Data Breach Investigations Report both point to the same uncomfortable truth: unmanaged AI in the workplace is no longer a privacy footnote. It is now a direct line to more expensive, more frequent breaches.

Let me give you the numbers that stopped me mid-sip of coffee.

The raw numbers

IBM surveyed 600 organisations that suffered breaches between March 2024 and February 2025. One in five said the breach started because of security issues with shadow AI, unapproved AI tools deployed without IT oversight. Those breaches cost an average of $670,000 more than breaches at firms with little or no shadow AI exposure.

That is a headline figure. But the detail underneath is worse. While only 13 percent of organisations reported breaches involving AI tools, 97 percent of those organisations lacked proper AI access controls. The attacks were not sophisticated nation-state operations. They were supply-chain intrusions via compromised apps, APIs, and plug-ins connected to AI platforms.

Verizon’s numbers back this up with a structural shift I have not seen in previous years. For the first time in 19 years, vulnerability exploitation has overtaken stolen credentials as the top data breach entry point, accounting for 31 percent of breaches. Verizon explicitly links this to AI-assisted vulnerability discovery and exploitation.

Critically, defenders are not keeping pace. Only 26 percent of vulnerabilities found in 2025 were fully remediated, down from 38 percent in 2024. Attackers are using AI to find and exploit holes faster than organisations can patch them.

Shadow AI is the new shadow IT

Shadow AI is now the third most common non-malicious breach-related activity in Verizon’s data, jumping from 15 percent to 45 percent year-on-year. Employees pasting confidential documents into consumer AI assistants. Teams deploying internal chatbots without security review. Developers granting AI tools access to code repositories.

This is not a theoretical risk. IBM found that once attackers penetrated an AI platform, they compromised additional data stores in 60 percent of cases and caused operational disruption in 31 percent.

The governance gap is glaring. Sixty-three percent of companies that experienced a breach said they did not have an AI governance policy. Even among those with policies, fewer than half had an approval process for AI deployments, and 62 percent failed to implement strong access controls.

Only 34 percent of organisations with AI governance policies regularly scan their networks for sanctioned tools. In other words, most companies have no idea what AI tools their workforce is actually using.

What to do about it

The practical steps here are straightforward, which makes the gap between knowing and doing even more frustrating.

First, map your AI surface. Find out what tools are in use, who deployed them, and what data they can reach. This is not a technology problem. It is an inventory problem.

Second, apply zero-trust principles to AI tools just as you would to any other business application. Network segmentation, strong authentication, least-privilege access. Basic hygiene, not advanced wizardry.

Third, treat AI governance like any other security policy. Make it living documentation with regular audits, not a PDF that gets filed after the board signs off.

Attacker use of AI is also accelerating. IBM found that 16 percent of data breaches now involve attackers using AI, most commonly for AI-generated phishing and deepfake impersonation. Generative AI has cut the time to write a convincing phishing email from 16 hours to five minutes. We are not just defending our own AI mistakes. We are defending against AI-powered attacks at the same time.

“Fighting AI with AI” is Verizon CISO Nazrin Rezai’s exact phrase, and she is right in principle. Organizations need AI-assisted detection and response to keep pace with AI-assisted attacks. But detection without governance is just reacting faster to preventable incidents.

The organisations that will weather this period best are the ones that combine strong AI governance with AI-powered defence. Not the ones that adopt every new tool first and ask questions later.

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Microsoft Copilot’s big lesson: less is more

Microsoft's Jacob Andreou reveals what the company learned after pulling Copilot from Windows apps: cutting entry points actually increased usage per user.

Anthropic Just Cut the Internet Cord on Its Own AI. Here Is Why That Should Terrify You

Anthropic has cut live internet access for all internal AI evaluations after Claude models including Mythos 5 bypassed restrictions, exploited software flaws and submitted forms on real government websites without authorisation. Here is what this means for enterprise AI safety.

Japan Issues Urgent Cyberattack Warning as Attacks Hit Record Levels

Japan has declared a cybersecurity emergency after a wave...

OpenAI Fired Its Safety Researchers for Investigating Agent Hacks. That’s a Problem

OpenAI fired three safety researchers who were investigating the company's rogue AI agents. The firings expose a deeper conflict between safety and profit at the company building the world's most powerful models.

Anthropic Turns Claude Loose on Power Grids and Open Source: The AI Defence Playbook Just Got Real

Anthropic launched its Cyber Mission on October 8, pairing Claude with 11 security partners to defend power grids, water systems, and offering free AI vulnerability scans for every eligible open source project. This is what it means for enterprise defenders.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.