Shadow AI is not a policy problem. It is a routing problem
Five of six AI governance controls fell in IBM's 2026 breach report, and 47% of genAI users are on personal accounts. Why policy loses, and what works.

TL;DR: A third of breached organizations are still drafting their AI policy, and five of the six controls that would enforce one got rarer this year. Netskope puts 47% of genAI users on personal accounts, which sit outside your identity provider and your admin logs. You can only enforce on traffic that runs through something you own.
An analyst has a board pack due at nine and a spreadsheet of customer records to summarize. The approved tool is slow, and getting access means a ticket IT will pick up on Monday. They paste the file into their own AI account instead, at eleven at night, from the office laptop. They finish by midnight and tell no one, because as far as they can see there is nothing to tell.
Multiply that by a few thousand employees and you have shadow AI. Most security teams answer it with a policy that says don’t. IBM now has a year of data on how that goes.
Companies start the policy and stall
IBM published its Cost of a Data Breach Report 2026 on 29 July, covering 602 organizations breached between March 2025 and February 2026. Fewer of them now have nothing: the share with no AI policy fell from 41% to 35%. Fewer had finished one, down from 37% to 32%, and the share reporting a policy “in development” rose from 22% to 33%. Each edition surveys a different set of breached companies, so this is the population shifting, not individual firms changing their minds. More are drafting. Fewer are done.
The controls that would enforce a policy went the same way, 2026 against 2025:
- Strict approval processes for AI deployments: 38%, down from 45%
- Use of AI governance technology: 33%, down from 39%
- Use of AI governance frameworks: 33%, down from 39%
- Employee training on AI risks: 30%, down from 36%
- Regular audits for unsanctioned AI: 29%, down from 34%
One moved the other way. Adversarial testing rose from 22% to 25%, the only technical check on the list.

One control slipping is noise. Five slipping together, in a year when AI adoption rose, is a pattern that wants explaining. Telling these companies they need an AI usage policy helps very little when someone there already has one open in a tab.
On cost, shadow AI turned up in 43% of security incidents, up from 20%, at $5.39 million each. Note the denominator: that is all security incidents, not the AI-related ones, which IBM counts separately at 21%. Our read of the full report has the breakdown.
Why the policy cannot reach
Netskope’s researchers measured the same behavior from the network side, across October 2024 to October 2025. 47% of genAI users reach these tools through personal, unmanaged accounts. Incidents of staff sending sensitive data to AI apps doubled that year, to 223 per organization each month.
Your company has no relationship with a personal account. It sits outside your identity provider, so it never shows up in an access review, and outside your data processing agreement, so consumer terms govern whatever your staff paste in.
That is what makes the audit number bite. 29% of organizations audit for unsanctioned AI, and auditors examine the systems you administer. For nearly half your genAI users, some of the work is happening somewhere else.
Blocking is the other lever. Zscaler logged 989.3 billion AI transactions across about 9,000 organizations during 2025 and found enterprises blocking 39% of access attempts, while data going to AI applications rose 93%, to 18,033 terabytes. Zscaler reports that block rate falling as teams move off blanket denial.
Two routes run out of your company, and a policy addresses both of them. You can enforce it on one.

OWASP puts the general problem in one line. Its State of Agentic AI Security and Governance v2.01 opens its runtime governance section with it: “Pre-deployment certification loses value the moment an agent begins, accumulates context, loads tools dynamically, or modifies its own configuration.” Approvals, questionnaires and training all happen before anything ships. Your analyst opens a personal AI account at eleven at night, and not one of those documents is in the room.
What to do instead
Three of these four cost nothing. The fourth is a line item, and usually a small one. The first two matter most.
- Count before you legislate. Pull the AI destinations out of your egress logs or web gateway for the last 90 days and rank them by volume and by distinct users. It takes an afternoon, and it tells you whether you have a two-tool problem or a forty-tool problem.
- Make the approved path the fast one. If your sanctioned tool needs a ticket and a personal account needs a browser tab, you know how that ends at eleven at night. Friction on the approved route is what sends people to the unapproved one.
- Buy the enterprise tenancy for what people already use. This is the one that costs money, and it is usually the cheapest thing on the list. Take the two or three tools that dominate your list, pay for the business tier, and put them behind your identity provider. The same work then happens inside a data processing agreement, with admin logs, and your staff carry on as before.
- Put a decision point on the traffic you control. Route the applications your company builds through something that reads the prompt and the response and acts on what it finds. Keep both halves: responses are where data your system retrieved, rather than data someone typed, will show up.
Steps 1 to 3 shrink the shadow path. Step 4 governs what is left on the path you own.
This pattern has a name
Step 4 describes a standard component: an inspection and enforcement point between your applications and the model providers they call, deciding per request whether to allow, mask or block, and recording both directions. The industry calls it an AI security gateway. It runs the policy whether or not anyone is watching.
It does not fix the shadow path. Someone on a personal account, on their home wifi, sits outside every system you administer, and no gateway touches that traffic. Vendors who sell shadow AI as solved mean managed devices only. Steps 1 to 3 address that half. The half running through your own applications is the one you can close today.
FAQ
We already have an AI usage policy. Isn’t that enough? You need one, and it will not enforce itself. Policies in place fell to 32% from 37% while adoption rose, and five of the six enforcement mechanisms around them fell too. Pair the policy with a checkpoint on the traffic and you have a control.
Should we just block AI tools at the firewall? Enterprises already blocked 39% of AI access attempts in 2025, the same year data volumes to AI apps rose 93%. Blanket blocking pushes usage onto personal devices, where you lose sight of it. Use it on specific high-risk destinations, not as a strategy.
How is shadow AI different from ordinary shadow IT? Shadow IT leaves company data sitting in an unapproved system. Shadow AI submits it as input to a third party whose retention and training terms your legal team never saw. IBM’s 2026 figures put a regulatory fine on about one in five of those incidents.
The traffic half should be a decision rather than a request. Zerberus AI Security is the enforcement point for it: change one base URL and every prompt and response passes through four self-hosted detectors (attack rules, an ML injection classifier, PII and secret DLP, and a policy-reasoning content-safety model), enforced as fail-closed policy-as-code with a full audit trail. The detectors run in your own deployment, so the prompts you keep out of someone else’s logs stay out of ours too. Request a demo and start in monitor mode, which answers step one for the applications you already own.



