Two numbers from this year, moving in opposite directions.
Regular use of AI on corporate devices went from 15% of employees to 45% in twelve months, according to Verizon’s breach data. Over the same period, among the organisations IBM studied after a breach, the share requiring IT approval before deploying AI fell from 45% to 38%, and the share with no AI governance in place — none at all, or still drafting one — rose from 63% to 68%.
The two figures come from different studies, so read them as direction rather than arithmetic. Adoption is accelerating. Governance is fading.
I wrote recently about four patterns that keep recurring in AI programmes, and argued they form a chain rather than a list. The third link — access arriving without passing through anyone — is where most of the damage currently sits, and it deserves more room than that article could give it.
Do you know what actually leaves the building?
Verizon’s 2026 breach report analysed 858,440 data-loss events involving generative AI tools. Two-thirds of employees using AI on corporate devices are signing in with non-corporate accounts. Shadow AI is now the third most common non-malicious insider action detected in data-loss datasets, with detections up fourfold year on year.
The most frequently submitted data type, by a wide margin, is source code.
More than 15% of corporate users are running unauthorised AI browser extensions that collect and retain browsing context — including sessions on internal systems. Nobody approved the extension. Nobody scoped what it can reach. It reads whatever is on screen, which in a regulated firm is client data more often than not.
IBM’s 2026 breach study found shadow AI involved in 43% of breached organisations, up from 20% a year earlier. Those breaches averaged $5.39 million against a $4.99 million global baseline, and in 21% of cases the organisation paid a regulatory fine.
Most organisations respond by banning it.
The instinct is prohibition, and it has now been tried widely enough to judge. Where a ban arrives without a workable alternative, the tools do not disappear. They move to phones, to home machines, to accounts the organisation has no relationship with — and the residual visibility that existed before the ban is lost along with them.
The Verizon data explains why. The leading motive behind insider misuse is convenience, at 60%, well ahead of financial gain. Convenience is not a compliance problem and it does not yield to instruction. It yields to friction, and a ban adds friction only to the sanctioned route.
A ban does not reduce usage. It moves usage somewhere the organisation cannot see, which is a worse position than the one it started from.
So the objective is not elimination. It is migration to visibility. Everything below serves that.
Start with discovery, because it depends on nothing.
The reflex is to write an acceptable-use policy. But a policy only tells people what the rules are. It cannot tell you who is already outside them. You need to know that first.
Start instead with the cheapest instrument available, which is not a security tool at all. Ask finance to pull every expense claim from the last quarter containing an AI subscription nobody budgeted for. No procurement, no project, no central AI function — and it produces a named list of people, tools and amounts within days.
The technical instruments matter too, and most organisations already own them: single sign-on logs show which AI services staff have authenticated to, browser telemetry shows what is installed, and egress monitoring shows where data is going. None of this requires new investment.
It requires someone being made responsible for looking. Among organisations IBM studied after a breach, only 29% ran any regular audit for unsanctioned AI use.
The constraint is not capability. It is ownership.
Discovery is also the only part of this that depends on nothing else — no strategy, no central function, no budget. Everything that follows does. Which is why so many programmes get this far and then stop.
A sanctioned path requires a function that can actually run one.
If people have no safe option, they will find an unsafe one. Provisioning is a control, not a benefit.
But a sanctioned path has to be provisioned, supported, kept current as models change every few months, and explained to people who did not ask for it. That requires a central capability that genuinely functions — the second pattern, reappearing as a constraint on solving the third. An organisation whose centre of excellence exists mainly as a steering committee will deliver a sanctioned tool that is worse than what its people are already using. At which point the ban dynamic returns, now with a procurement trail attached to it.
And the control point is identity, not policy.
This is the part I would push hardest on with a board.
AI tools are not a category of software sitting outside the estate waiting to be blocked. They are embedded in browsers, productivity suites, collaboration platforms, and increasingly in the applications people already have open. There is no perimeter to defend. The control point is access and entitlement — who and what can reach which data — not the text of a policy.
IBM found that 92% of organisations suffering an AI-related breach lacked adequate access controls around AI. Not weak controls. Absent ones.
Deciding what those entitlements should be, though, means deciding what is worth protecting and at what operational cost. That is a strategy question, which returns to the first pattern. The chain closes.
What this means for a supervised entity.
An acceptable-use policy is not a compliance artefact. It is a statement of intent.
An organisation that cannot enumerate the AI actually in use cannot complete a data protection impact assessment for systems it does not know exist. It cannot produce an AI Act inventory that reflects reality. It cannot answer a supervisor asking what its exposure to third-party AI providers is, because a material part of that exposure is being incurred through personal accounts on terms nobody at the organisation reviewed.
Discovery is not a security exercise that compliance can wait on. It is the precondition for every AI governance artefact the organisation will be asked to produce over the next eighteen months.
Shadow AI is the only one of the four patterns you can begin addressing immediately, because finding out what is happening requires no strategy, no central function, and no budget.
It is also the one you cannot finish addressing without both.
That is not an argument for waiting. It is an argument for starting with discovery, and for being honest about what the results will demand next — because the list will contain things that no security programme can fix on its own.
So: if you asked your finance function to flag every unbudgeted AI subscription from the last quarter, how long would that list be — and who would you send it to?
For most organisations the second question is the harder one. The answer is usually nobody, and that is the second pattern arriving without having to be named.
Alexandre Castaing is Managing Director of Axon Advisory & Consulting, working with supervised financial entities in Luxembourg on digital resilience, AI governance and regulatory compliance.
#ShadowAI #AIGovernance #AIStrategy #DORA #AIAct #Leadership #EnterpriseAI #Luxembourg