Skip to main content

Shadow AI Is an Egress Path You Have No Record Of

MnemoShare Security TeamAugust 12, 20267 min readCompliance

One in five breaches involving shadow AI resulted in a regulatory fine.

That figure comes from IBM's 2026 Cost of a Data Breach Report, published July 29. The same report found shadow AI present in 43 percent of security incidents, more than double the 20 percent recorded a year earlier, with those breaches averaging $5.39 million against a global average of $4.99 million.

The cost is not the part that should worry a compliance officer. The fines are. A regulator does not fine you for an employee using a tool. They fine you because regulated data left your organization and you could not account for it.

What is shadow AI?

Shadow AI is the use of artificial intelligence tools by employees without approval, oversight, or visibility from IT and security.

That includes consumer chat assistants and browser extensions. It also includes AI features embedded in software the organization already licenses, and AI services individual teams have connected to internal systems.

It is the current form of a much older pattern. Shadow IT was employees using unapproved software. Shadow AI is the same behavior with two differences that matter: the tools ingest whatever is pasted into them, and the person using one is usually trying to do their job faster rather than trying to evade anything.

That second point is why prohibition tends not to work, and why the report frames the problem as governance rather than enforcement.

What did IBM actually find?

The study covered 602 organizations across 17 industries and 16 countries, drawing on 3,558 interviews about breaches occurring between March 2025 and February 2026.

FindingFigure
Global average breach cost$4.99 million, up 12 percent, highest in 21 editions
Incidents involving shadow AI43 percent, up from 20 percent
Average cost of a shadow AI breach$5.39 million
Shadow AI breaches resulting in a regulatory fineOne in five
Breached organizations with no AI governance policy68 percent, up from 63 percent
Organizations requiring IT approval before AI deployment38 percent, down from 45 percent
Organizations coordinating governance and security teams19 percent

Two of those numbers moved in the wrong direction. Governance policy coverage fell, and IT approval requirements fell. Adoption accelerated while oversight receded.

One thing to hold in view while reading any of it. IBM sponsored, analyzed, and published this report, and sells identity, encryption, and security automation products that its findings favor. Ponemon Institute conducted the research. That alignment does not make the data wrong, and 602 organizations across 21 editions is a serious dataset, but it belongs on the page the same way it would with any vendor-published benchmark.

Is shadow AI a reportable disclosure?

Often, yes, and that is why the fines follow.

A conventional breach involves someone getting in. Shadow AI involves regulated data going out, voluntarily, through a channel nobody is logging. There is no exploit to detect and usually no anomaly to alert on. An employee pastes a claims file, a client list, or a set of clinical notes into a tool to summarize it, and that content now sits with a third party the organization has no agreement with.

For a covered entity or a regulated financial institution, that is a disclosure to an unlisted party. Whether it meets a notification threshold depends on facts you would need a record to establish, and the record does not exist.

Which is why the regulator's question is never "why did an employee use that tool." It is "what left, when, and how do you know."

Why can't you see it?

Three reasons, and only one of them is about tooling.

The tools are ordinary web traffic. A browser-based assistant is indistinguishable from any other site unless you are inspecting content, not just destinations.

AI is now embedded in software you already approved. The report's framing of shadow AI includes features inside sanctioned products. The tool passed procurement. The feature did not exist when it did.

Nobody owns the question. Only 19 percent of organizations reported governance and security teams coordinating. When the two functions run separately, AI adoption is a governance topic and data egress is a security topic, and the gap between them is where this lives. That is the same structural failure we described in You Can't Buy Your Way Out of Vendor Sprawl: the risk is not inside a control, it is in the seam between two of them.

What can you actually control?

Not the tools. The record of what leaves through them.

You cannot realistically prevent every employee from finding an AI assistant, and the report is clear that prohibition is losing: IT approval requirements fell this year while adoption rose. What you can control is whether regulated data moving out of your organization produces an account of itself.

That means treating AI as one more destination rather than a separate category. The questions are the same ones you should already be able to answer about email, file transfer, and partner portals:

What content is leaving, not just where it is going. Destination-based controls fail here because the destination looks like normal web traffic. Content inspection at the point data leaves is what identifies protected health information or client data regardless of where it is headed.

Who authorized it. Not which account, which person, and under what permission.

Can you produce the record later. An access log that lives inside the system being questioned is not independent evidence. This is the same standard auditors apply to file transfer, covered in SOC 2 Audit Logging for File Transfers.

How many separate egress paths exist. Every additional tool that can move data outward is another place the answer to the first three questions has to be reconstructed from scratch.

Does a file exchange platform help with shadow AI?

Partly, and it is worth being precise about which part.

MnemoShare does not govern shadow AI. We do not sit in the browser, we do not inspect what an employee pastes into a consumer chat tool, and we are not a CASB or an AI governance platform. If the exposure you are worried about is someone pasting a spreadsheet into a chatbot, that is a different control layer and a different vendor.

What we do is the neighboring problem: file exchange with outside parties. Content inspection runs at the transfer boundary rather than relying on destination rules, so protected data is identified as it moves rather than after. At-rest scanning covers OneDrive, SharePoint, and Google Drive, which is where the files people feed into AI tools usually live before they get there. And every exchange produces a structured, append-only, tamper-evident audit event exported to storage you control. For healthcare organizations most of that outbound traffic is PHI exchange with covered entities and their business associates.

The connection to the IBM findings is narrow but real. The organizations that struggled were the ones who could not answer what left. Closing that gap on file exchange does not close it on browser-based AI. What it does is reduce the number of channels where you have no answer at all, from most of them to one.

More detail on content inspection and audit evidence.

The question to ask this quarter

Not "do we have an AI policy." Sixty-eight percent of breached organizations did not, and a policy is not a control.

Ask instead: if a regulator asked what regulated data left this organization in the past ninety days and through which channels, how long would it take to answer, and would the answer be a list or an estimate?

If it is an estimate, shadow AI is not your first problem. It is your newest one.

Request a demo

Sources

complianceshadow-aidata-governanceDLPaudit-evidencebreach-cost