Shadow AI: what unauthorized AI costs
The average cost of a data breach fell for the first time in five years. The exception is organizations where AI arrived without access controls or a governance policy.
Executive summary
The global average cost of a data breach fell to USD 4.44 million, 9% below the previous year. It is the first decline in five years and is explained mostly by faster detection.
Thirteen percent of organizations suffered a breach involving their AI models or applications. Of that group, 97% had no access controls specific to AI in place at the time.
Sixty-three percent of organizations have no AI governance policy at all. Where unauthorized AI was involved, the breach cost USD 670,000 more than the overall average.
In the European Union the stated blocker for not adopting AI is not price: 70.9% point to a lack of in-house expertise and 52.5% to uncertainty about the legal consequences.
Context
Artificial intelligence enters organizations through two doors. One is the approved project, with a budget, a vendor and an owner. The other is any employee's browser, pasting a document into a free tool.
The second door appears in no inventory and does not close with a written policy nobody read. It closes with an authorized alternative that actually works and with access control at the point of use.
Figure 1 · Stated blockers to AI adoption in the European Union
% of enterprises that considered it and did not adoptTable 1 · Where the extra cost concentrates
data breaches, 2025| Indicator | Value | Reading |
|---|---|---|
| Global average cost of a breach | USD 4.44M | 9% below the USD 4.88M of 2024 |
| Extra cost with unauthorized AI | +USD 670,000 | Above the average, where shadow AI was involved |
| Organizations with an AI-related breach | 13% | Of those, 97% had no access control |
| No AI governance policy | 63% | Almost two thirds of the surveyed base |
| Time to identify and contain | 241 days | The lowest figure in the last nine years |
Business implications
Inventory actual usage before writing the policy. The vendor register does not show what gets pasted into a browser. Network and endpoint telemetry does.
Put access control where the usage happens. 97% of AI-related breaches occurred in organizations without it. It is the highest return per unit of effort available.
Offer an authorized alternative before you block. Blocking without a substitute moves the usage onto personal devices, where no record of anything is possible.
Methodology & data
Two public sources with declared methodology: IBM Security's Cost of a Data Breach Report 2025, produced with the Ponemon Institute on a base of 600 organizations that suffered a breach; and Eurostat's EU ICT usage survey of enterprises with 10 or more employees.
Breach figures are global; the adoption-blocker figures cover the European Union only.
References
IBM Security and Ponemon Institute (2025). Cost of a Data Breach Report 2025. · Eurostat (2025). Use of artificial intelligence in enterprises, Statistics Explained. · Eurostat (11 December 2025). News release on the use of AI in EU enterprises.