Data

Your employees are the data breach, one prompt at a time

Sixty-three percent of employees have pasted source code, client data, or financial records into a personal chatbot account. No attacker was involved. The leak was a feature request typed into the wrong box.

Twenty percent of breached organizations were compromised through shadow AI, and those incidents added roughly $670,000 to the average cost of a breach. No attacker broke in. An employee pasted the wrong thing into the right-looking tool.

The scale is larger than most governance plans assume

Between 45% and 66% of the workforce is using AI tools their employer has not sanctioned, and some estimates put it as high as 80%. Sixty-three percent of employees have already pasted sensitive information — source code, customer records, financial data, internal strategy documents — directly into a personal chatbot account. Once that data enters an unsanctioned model, it is, for practical purposes, outside the company's control permanently: there is no recall button, and the organization frequently cannot even confirm what left or where it went.

Why this keeps happening despite the warnings

This is not a discipline problem in the way it is usually described. Employees are not defying a policy they understand. Most are solving a real, immediate task — draft this email, summarize this contract, debug this function — with the best tool available to them, which is frequently a personal account because the sanctioned enterprise tool is slower, more restricted, or simply not provisioned for their role yet. The Moltbook breach earlier this year is the cautionary extreme of the same instinct: a platform built quickly without basic security controls exposed 1.5 million API keys and 35,000 emails, because speed was prioritized over the unglamorous work of access control.

Policy without provisioning is not a control

A memo telling employees not to use unsanctioned AI tools does nothing if the sanctioned alternative cannot do the job the employee actually needs done. The organizations bringing the 45-to-66% number down are the ones treating provisioning as the actual control: giving employees a fast, capable, sanctioned tool for the tasks they are already doing in the shadow version, so the workaround stops being necessary rather than merely being prohibited.

Measure shadow AI use as a signal about your own provisioning gap, not primarily as an employee compliance failure. The $670,000 premium on a shadow-AI breach is the cost of pretending a policy substitutes for a tool that actually works.

What this reacts to

The daily brief

CIOReview, in your inbox before standup

The headlines technology leaders are reading, synthesized and source-linked. One email each morning. No filler.