Shadow AI Raises the Breach Bill
Coverage from Canadian Business, Matters.AI, and others

Organizations are confronting a dual AI security problem: attackers are using deepfakes, AI-generated malware, and automated social engineering, while employees and AI agents increasingly move sensitive data through tools that security teams may not have approved or monitored.
IBM and Ponemon Institute research places AI-related breaches among the costliest incidents, while other analyses highlight weak access controls, incomplete governance policies, limited visibility, and exposure through SaaS and API integrations. The pattern is pushing organizations toward unified identity-and-data controls, approved AI inventories, stronger runtime monitoring, and greater use of security automation.
The story shifts modestly toward operational response: beyond identifying AI-related exposure, it now emphasizes approved-tool inventories, response procedures, runtime monitoring, and security automation. The underlying finding that AI amplifies both attacks and data-governance risk is otherwise reinforced rather than materially changed.
The story is strengthened by quantified evidence that AI-enabled breach activity is accelerating and costs more than breaches overall. New research details the study scope and highlights healthcare as an especially costly sector, but the underlying risk narrative remains consistent.
The story now places more emphasis on AI-driven attack automation and on the need to unify identity and data security, rather than mainly describing AI as a broad exposure pathway. It also introduces additional source organizations and a clearer framing of AI agents, deepfakes, and machine identities as core risk drivers.
The story now has concrete breach-cost and incident-frequency data showing AI-related attacks are a major share of breaches, not just a governance concern. It also broadens from general shadow AI risk to specific control gaps across logging, non-human identity management, and cloud oversharing.
- AI-enabled attacks were about one-quarter of malicious breaches.
- Average global breach costs reached about $4.99 million.
- AI-enabled incidents averaged about $6 million in breach costs.
- Customer PII appeared in 52 percent of breaches.
- AI-assisted detection and response can reduce breach costs.
Organizations are expanding their use of generative AI, copilots, agents, and AI-enabled development tools faster than they can inventory, control, and audit them. Unmanaged AI accounts, exposed data flows, AI-generated applications, and prompt injection attacks are creating new paths to sensitive information and consequential actions. The same expansion is also increasing pressure on financial institutions to use biometrics and continuous verification against synthetic identity fraud, creating additional privacy and breach consequences.
