Back to Insights
DI-2026-02Technology & data · Data governance

Shadow AI: what unauthorized AI costs

The average cost of a data breach fell for the first time in five years. The exception is organizations where AI arrived without access controls or a governance policy.

PublishedApril 13, 2026
Version1.0 · English
AuthorsAnalytics Unit
Reading time5 min read
Download as PDF

Executive summary

01

The global average cost of a data breach fell to USD 4.44 million, 9% below the previous year. It is the first decline in five years and is explained mostly by faster detection.

02

Thirteen percent of organizations suffered a breach involving their AI models or applications. Of that group, 97% had no access controls specific to AI in place at the time.

03

Sixty-three percent of organizations have no AI governance policy at all. Where unauthorized AI was involved, the breach cost USD 670,000 more than the overall average.

04

In the European Union the stated blocker for not adopting AI is not price: 70.9% point to a lack of in-house expertise and 52.5% to uncertainty about the legal consequences.

Headline figureUSD 670,000is the average extra cost of a breach when unauthorized artificial intelligence was involved.
USD 4.44Mglobal average cost of a breach, down 9%
13%of organizations had an AI-related breach
97%of those lacked AI access controls
241 daysto identify and contain, the lowest in nine years

Context

Artificial intelligence enters organizations through two doors. One is the approved project, with a budget, a vendor and an owner. The other is any employee's browser, pasting a document into a free tool.

The second door appears in no inventory and does not close with a written policy nobody read. It closes with an authorized alternative that actually works and with access control at the point of use.

Banning without offering an alternative does not reduce risk: it hides it.. When the authorized tool is worse than the one the team finds on its own, usage does not disappear; it stops being visible. A policy that works starts by giving people an option they prefer.

Figure 1 · Stated blockers to AI adoption in the European Union

% of enterprises that considered it and did not adopt
Lack of expertise
71%
Legal consequences
53%
Data protection
49%
Not useful for the firm
21%
Source: Eurostat, "Use of artificial intelligence in enterprises", data extracted December 2025. EU ICT usage survey of enterprises with 10 or more employees; sample of about 157,000 out of 1.53 million firms. Exact values: 70.89%; 52.52%; 48.83%; 20.68%.

Table 1 · Where the extra cost concentrates

data breaches, 2025
IndicatorValueReading
Global average cost of a breachUSD 4.44M9% below the USD 4.88M of 2024
Extra cost with unauthorized AI+USD 670,000Above the average, where shadow AI was involved
Organizations with an AI-related breach13%Of those, 97% had no access control
No AI governance policy63%Almost two thirds of the surveyed base
Time to identify and contain241 daysThe lowest figure in the last nine years
Source: IBM Security and Ponemon Institute, Cost of a Data Breach Report 2025. Base of 600 organizations that suffered a data breach; figures are global means, not medians.

Business implications

Inventory actual usage before writing the policy. The vendor register does not show what gets pasted into a browser. Network and endpoint telemetry does.

Put access control where the usage happens. 97% of AI-related breaches occurred in organizations without it. It is the highest return per unit of effort available.

Offer an authorized alternative before you block. Blocking without a substitute moves the usage onto personal devices, where no record of anything is possible.

Methodology & data

Two public sources with declared methodology: IBM Security's Cost of a Data Breach Report 2025, produced with the Ponemon Institute on a base of 600 organizations that suffered a breach; and Eurostat's EU ICT usage survey of enterprises with 10 or more employees.

Breach figures are global; the adoption-blocker figures cover the European Union only.

References

IBM Security and Ponemon Institute (2025). Cost of a Data Breach Report 2025. · Eurostat (2025). Use of artificial intelligence in enterprises, Statistics Explained. · Eurostat (11 December 2025). News release on the use of AI in EU enterprises.

Next stepLet's put your data architecture in order before scaling.Data · Automation · Custom software
contacto@grupodatametrica.comdatametricgroup.comSuggested citation: Datametric Group (2026). Shadow AI: what unauthorized AI costs. Datametric Insights, DI-2026-02.

More publications

DI-2026-10From adoption to results: why EBIT is not movingSep 02, 2026 · 6 min readDI-2026-09Seventy years of productivity: the gap that will not closeAug 31, 2026 · 6 min readDI-2026-08Venezuela: when the figures disagree, the method is the storyAug 24, 2026 · 6 min read