IBM just created a new breach category. Shadow AI. For the first time in its Cost of a Data Breach Report 2025, IBM included unauthorized AI use as a formal cost factor. We have been tracking this shift since generative AI became a corporate habit without governance — and the number IBM brought confirms what we saw in the field: the problem is no longer a lack of security skills, it is excess access without governance.
The new category IBM created
Shadow AI is the use of unauthorized AI tools by employees to process corporate data. It is not an external attack. It is the employee who pastes a customer database into ChatGPT, asks Claude to summarize a confidential contract, or trains a model on a personal platform with financial data. IBM recognized that this behavior started having a measurable impact on incident cost — and created a formal category for it.
According to IBM, Shadow AI displaced the lack of security skills as one of the three most costly breach factors. The problem became excess access without governance. It is no longer a team capability problem — it is an access control and visibility problem.
The numbers: $670K additional and 247 days
The numbers from IBM's Cost of a Data Breach Report 2025 are what define the severity. An incident involving Shadow AI costs $670K more than the average. The average breach cost with Shadow AI: $4.63 million. The lifecycle of a Shadow AI incident: 247 days — a week more than the global average. Extra detection days because nobody knows the tool exists.
The detection delay is structural. When an employee uses a tool that security does not know about, there is no monitoring rule, no correlated log, no alert. The incident is only discovered once the data has already leaked — or when a third party reports it. Every extra detection day is an extra exfiltration day.
89% invisible: the largest data exfiltration channel today
According to IBM, 80% of employees use unauthorized AI. 34% entered customer data. 31% entered financial or confidential data. 66% knew it was not allowed. 60% think the risk is worth it. Awareness of the risk exists — perception of consequence does not.
IBM found 97% of organizations that suffered AI incidents lacked adequate access controls. Only 37% of companies have an AI governance policy. 18.5% of employees know it exists. A policy that 81.5% of employees are unaware of is equivalent to having no policy.
According to IBM, 89% of enterprise AI use is invisible to security. 32% of all corporate data movement to personal accounts goes through generative AI. It is the largest data exfiltration channel today. Larger than personal email. Larger than personal cloud. The employee pastes the database into ChatGPT and the data leaves through a channel that security does not monitor — because the domain is legitimate and the traffic looks like productivity.
LGPD: when pasting into ChatGPT becomes a reportable incident
In Brazil, LGPD Art. 46 requires security measures for personal data. ANPD can fine up to 2% of revenue, capped at R$50 million per infraction. When an employee pastes a customer database into ChatGPT, that is a reportable security incident within 3 business days, according to LGPD.
The DPO must be notified, the incident must be documented, and ANPD must be informed within the deadline. Not reporting aggravates the sanction. And the incident does not need to be a sophisticated attack — it just takes an employee using an unsanctioned tool to process personal data. Shadow AI turns a common human error into a legal reporting obligation.
Banning AI doesn't work — but this does
Banning AI doesn't work. When companies provide sanctioned tools, unauthorized use drops 89%, according to IBM. Prohibition without an alternative creates shadow IT — it always has. With generative AI, the effect is amplified because the tool is free, browser-accessible, and delivers immediate value. Blocking AI domains at the firewall does not solve it: the employee uses a phone, a personal network, a colleague's API key.
What works is governance combined with sanctioned tools. We implement five layers with our clients:
- AI-SPM. Shadow AI monitoring with prompt sanitization before prompts reach the LLM. Intercepts sensitive data before it is sent.
- Behavioral EDR at the endpoint. Detects exfiltration to AI even when the domain is legitimate. Analyzes the send pattern, not domain reputation.
- SOC 24/7. The Shadow AI signal gets lost in the noise without a human correlating alerts. Anomalous volume, atypical hours, token spikes — in isolation they look like noise.
- Acceptable AI use policy. Without it, you cannot define what is unauthorized. 37% of companies have one; 18.5% of employees know it exists.
- Awareness. Shadow AI is the same human error pattern as phishing. 66% knew it was not allowed. Generic training does not work — it must show real cases and the cost of a reportable incident.
Conclusion
IBM said Shadow AI displaced the lack of security skills as one of the three most costly breach factors. The problem became excess access without governance. The solution is not less AI — it is governed AI. Banning doesn't work, providing sanctioned tools cuts unauthorized use by 89%, and the five layers above turn a common human error into a detectable event before the ANPD report. At Tech86, we help companies build this governance before the first Shadow AI incident becomes a $4.63 million breach.