Shadow AI: Unauthorised AI Use Emerges as New Cybersecurity Threat

Sunday, Aug 3, 2025 2:07 pm ET1min read

According to IBM's annual 'Cost of Data Breach' report, global data breach costs declined to $4.44 million in 2025 due to containment by AI-powered defenses. In India, breach costs increased to $2.51 million. Shadow AI, unauthorized AI use, is emerging as a new threat, with 63% of organizations lacking AI governance policies or still developing them.

According to IBM's annual 'Cost of Data Breach' report, global data breach costs declined to $4.44 million in 2025 due to containment by AI-powered defenses. However, in India, breach costs increased to $2.51 million. The report also highlights the emerging threat of Shadow AI, which refers to the unauthorized use of artificial intelligence tools, models, or platforms within organizations. This practice is becoming increasingly prevalent, with 63% of organizations lacking AI governance policies or still developing them.

The report indicates that Shadow AI can significantly exacerbate data breach costs. IBM found that breaches involving Shadow AI cost $670,000 more on average than those without AI involvement [2]. This underscores the critical need for robust AI governance policies and proper access controls.

Moreover, the report reveals that 97% of companies with Shadow AI incidents lacked any AI-specific access controls [1]. This lack of oversight can lead to serious security vulnerabilities, as AI tools can confidently produce false or biased results that shape critical decisions.

To mitigate these risks, organizations must adopt a comprehensive approach to AI governance. This includes building clear, role-specific policies, discovering and mapping unauthorized AI use, and engaging employees as partners. Technical guardrails, such as AI security platforms, should also be deployed to enforce data boundaries and monitor AI activities.

The rise of Shadow AI presents a significant challenge, but it also offers an opportunity for organizations to leverage AI more effectively and securely. By addressing these issues proactively, companies can turn potential risks into strategic advantages.

References:
[1] https://www.stocktitan.net/news/IBM/ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-gwazifdblzrp.html
[2] https://medium.com/@sonal.sareen/the-threat-of-shadow-ai-the-invisible-force-inside-your-business-d44c9dcfa56f

Shadow AI: Unauthorised AI Use Emerges as New Cybersecurity Threat

Comments



Add a public comment...
No comments

No comments yet