Shadow AI, meaning staff using unapproved AI tools, showed up in 43 percent of security incidents in IBM’s Cost of a Data Breach Report 2026, up from 20 percent the year before, Forbes reported on August 17. The study covered 602 organizations breached between March 2025 and February 2026.
IBM’s July 29 newsroom release led with AI-enabled attacks and a record global average breach cost of $4.99 million. The 43 percent shadow AI figure sits in the report itself, Forbes noted, rather than in IBM’s announcement. Among shadow AI incidents in the sample, average cost was $5.39 million, up from $4.63 million a year earlier. About 49 percent of those incidents involved data loss or compromise, 42 percent disrupted operations, and 68 percent of the breached organizations lacked AI governance policies, according to the Buildtelligence write-up of the same IBM numbers.
Those percentages describe already-breached organizations, not every company. They still put unapproved tool use inside the breach record that boards, carriers, and auditors already read. IBM also found that 92 percent of organizations with an AI-related breach had failed to control access to the tools involved, Forbes reported.
Buildtelligence published its operating read of the wave at buildtelligence.com/news/shadow-ai-risk after the Forbes piece: inventory what is actually in use, finish a short acceptable-use policy, and get basic visibility before trying to price the risk.
This is a visibility story. Companies cannot price the AI risk they have not mapped.
Sources
Forbes: forbes.com
IBM Newsroom: newsroom.ibm.com
Buildtelligence: buildtelligence.com/news/shadow-ai-risk