Unapproved AI tools—commonly termed shadow AI—surfaced in 43 percent of security incidents last year, roughly double the prior year’s share, while 68 percent of breached organizations lacked any policy governing AI use. The findings come from IBM’s Cost of a Data Breach Report 2026, released July 29 and based on 602 organizations compromised between March 2025 and February 2026; the shadow-AI statistic appears in the full report rather than in IBM’s press summary. Four days later, Article 50 of the EU AI Act took effect, requiring companies to disclose when individuals interact with an AI system. That transparency mandate is straightforward to satisfy with a simple notice in a chat interface. The difficulty lies in knowing which systems require that notice—a challenge that brings the 68-percent policy gap into sharp focus.

Scrutiny Focused on Vendors While Shadow AI Risk Remained Overlooked

Risk committees have spent two years examining model behavior: hallucination, bias, poisoning, misalignment. That work is necessary, yet it targets the portion of the problem already under the closest watch. Three to five large vendors supply the models powering most enterprise tools; those vendors absorb regulatory scrutiny and invest heavily in guardrails. A significant share of AI products sold to enterprises are essentially wrappers around the same handful of systems. The unmonitored exposure sits a layer down, in how employees and software agents actually use the technology.

Yakir Golan, chief executive and co-founder of risk-quantification firm Kovrr, offers a practitioner’s estimate of the split. He emphasizes the figure is drawn from years of client conversations, not a formal dataset. “70 to 75% usage risk and 25% model risk… but companies should manage as if it were 90 to 95% usage risk and 5 to 10% model risk. Top models get heavy scrutiny; internal enterprise use is neglected.”

The reasoning behind those percentages aligns with where IBM found the failures. Incidents involving an organization’s own AI models and applications rose to 21 percent from 13 percent year over year, and among companies whose AI systems came under attack, 92 percent had failed to control access properly. These figures describe breached organizations, so they reflect failure rather than the broader economy. Access-control lapses remain a usage failure often miscategorized as model risk—the same failure that surfaces when an agent retains standing permissions on a mailbox or code repository long after the person who configured it has moved teams.

Disclosure Presumes an Inventory

The EU’s Digital Omnibus on AI became Regulation (EU) 2026/1744, published in the Official Journal on July 24 and effective July 27. It deferred standalone high-risk obligations under Annex III to December 2027 and high-risk AI embedded in regulated products to August 2028. Article 50 was untouched. Since August 2, providers must inform people when they are interacting with an AI system and mark synthetic content for machine detection, while deployers must disclose emotion recognition, biometric categorization, and published deepfakes—with no deferral on the deployer side. The sole concession delays the machine-readable marking requirement to December 2026, and only for systems already on the European market before August 2. None of these obligations can be met by a company that has never cataloged what it runs.

Evidence on what companies have cataloged points in one direction. UpGuard’s State of Shadow AI survey, published November 2025 from 500 security leaders and 1,000 employees, found 81 percent of employees and 88 percent of security leaders reporting use of unapproved AI tools, with 45 percent of workers saying they find workarounds when an application is blocked. The numbers are self-reported and UpGuard sells tooling in the category, so they should be treated as directional rather than precise. What survives that discount is a gap between the AI a company has approved and the AI its staff actually use—and the latter rarely appears as a line item anyone signed off in the accounts.

Golan sees the same gap from the demand side, in what clients request. “Although people came to us and asked for what’s the exposure and how to prioritize remediation… there is a big gap on visibility as well, which is directly tied to quantification. You need to know in close to real time what’s going on… visibility is the key now.” His top three usage risks are data leakage, bad permissions, and third-party vendor exposure—none visible to a company mapping only approved assets. Kovrr’s approach pulls telemetry from browsers and secure browser extensions, endpoints, network traffic, identity and data-governance systems, and third-party model activity, then separates approved assets from shadow ones before any modeling begins. One large manufacturer, anonymized in his account, mapped its AI assets, used the output to support an assessment under NIS2—the EU’s network and information security directive—then sequenced remediation across the first half of 2026 by financial weight.

Underwriters Arrived Before Regulators

Insurers moved earlier and more quietly, and the cost data in the IBM report explains why. The global average breach cost reached just under $5 million last year, up 12 percent and the highest IBM has recorded, while breaches involving attacker use of AI ran about $1 million above that. ISO, the Verisk-owned bureau that drafts standard policy wording for U.S. insurers, has circulated a generative AI exclusion for commercial general liability coverage, form CG 40 47 01 26, with a January 2026 edition date. It removes protection for injury and damage “arising out of, or attributable to, generative artificial intelligence,” applies to both liability coverages, and triggers whether the insured used the technology directly or through a vendor. Carriers decide individually whether to attach it, so the accurate reading is that a standard route to exclude now exists and is appearing on policies as carriers choose to adopt it—not that every business has quietly lost coverage.

Affirmative coverage exists on the other side of the market, though it remains small and bespoke. Munich Re’s aiSure line covers contractual performance warranties, discrimination and intellectual property claims, hallucinations, regulatory fines, and financial loss from AI errors; the company says it has insured AI products and services since 2018. Armilla, backed by Lloyd’s syndicates, began writing coverage in May 2025 for losses caused by AI errors including hallucinations, paying damages and legal costs.

Underwriters price an unmapped AI estate the way a surveyor prices a building with no floor plan: at the worst case the missing drawings allow. But a surveyor can walk the building and draw the plan; nobody can walk an AI estate, because it changes between the browser tabs open on Monday and those open on Friday. Asked how long before coverage becomes standard, Golan offered a timeline. “Mass-market off-the-shelf AI insurance scaling will take about two years… underwriters need confident visibility first.”

The Number Is Only As Honest As the Map

The strongest objection to this quantification effort comes from within the discipline that pioneered it. In March 2024, the National Security Telecommunications Advisory Committee (NSTAC), which advises the U.S. president on communications and cyber policy, reported that the security industry suffers from weak “metrics literacy” and runs mathematical operations on subjective qualitative judgments as though they were hard data. “Subjective measurements, combined with bad math, lead to ineffective decision-making,” the committee concluded. Presenters to the committee—rather than the committee itself—said their own quantitative frameworks accounted for only 10 to 15 percent of the variance in breaches.

The critique targeted cyber risk, which has two decades of loss history. AI quantification has a fraction of that, so the objection lands harder here. A model built on a partial inventory understates exposure and manufactures confidence simultaneously—the second failure being the more expensive, because it reaches the board as a decision.

Golan’s own sequencing concedes the dependency. “The quantification is the layer on top of asset mapping and usage monitoring… to power solid board reporting and prioritize compliance gaps with financial weighting.” Committee and practitioner agree that quantification is worth no more than the visibility underneath it, and diverge on what follows. The committee’s finding implies the output deserves suspicion even once the inventory is complete, while Golan’s clients pay him to make it trustworthy. The NSTAC findings were not put to him in the interview.

Golan believes regulators are not moving fast enough, and his read on boards is that investor pressure to adopt AI still outweighs any pressure to govern it. One client installed a secure browser extension to monitor where staff sent corporate data, then repurposed the same extension to block traffic headed for Chinese models. No regulator asked for that and no underwriter required it. It happened because someone could finally see the traffic. Every other company will face the same question eventually—from a carrier’s questionnaire or a regulator’s notice—and will answer with whatever it happened to install before anyone thought to ask.

Source link

Exit mobile version