Workers using unapproved AI tools figured in 43% of security incidents in IBM 2026 breach study, more than double the year before. Close to seven in ten breached organizations had no AI governance policy at all. The instinct is to ban the tools. The evidence says a ban mostly relocates the problem.
The numbers first, because they are unusually clear this year. IBM 2026 Cost of a Data Breach Report puts the global average breach at $4.99 million, with US organizations at more than twice that figure. One in four malicious breaches were AI-enabled, a 56% jump year over year, and those cost about $6 million on average (IBM newsroom).
The part that matters more for a company of a few hundred people is quieter. Unapproved AI tool use by employees figured in 43% of security incidents, roughly double the prior year. Those incidents produced actual data loss or compromise about half the time, and around one in five drew a regulatory fine. Ninety-two percent of the organizations involved were missing basic access controls on their AI use, and mean time to identify and contain a breach rose to 247 days (Help Net Security reporting the IBM study).
Prohibiting the tools is a reasonable instinct. It is fast, it is free, and it puts a clear line in writing. It also runs into three things.
The employee was solving a real problem. Nobody pastes a contract into a chatbot for entertainment. They do it because a proposal is due, the summary would take ninety minutes, and the tool does it in four. Removing the tool does not remove the deadline. It removes the fastest route to the deadline, which is not the same thing.
A ban you cannot see is a ban you cannot enforce. Most companies have no telemetry on which browser tabs staff use on which devices. The policy exists, compliance is assumed, and the assumption is doing all the work.
Worst of all, it pushes use onto personal accounts and personal devices. That is a strictly worse outcome than the original problem. Company data still leaves, but now there is no log, no retention setting, no enterprise agreement covering training use, and no way to answer a customer or a regulator asking what happened. A ban converts a visible risk into an invisible one and calls it progress.
The pattern that works is not permissive and it is not prohibitionist. It is a sanctioned route that beats the workaround on speed, plus a very short list of absolutes.
Close to seven in ten breached organizations had no AI governance policy at all, which means the bar to being materially better prepared than the field is still low. That will not stay true. Customer security addenda are already asking about AI use, insurers are moving the same direction, and Texas law now offers a documented safe harbor for companies that align to a recognised framework and can show it. Written this quarter, this is a short document and an afternoon of configuration. Written after an incident, it is an exhibit.
The reframe worth holding onto is that shadow AI is not primarily a discipline problem. It is a demand signal. Forty-three percent of incidents involving unapproved tools is also the clearest possible evidence that people across the business have found work AI genuinely helps with. That is useful information about where the value is, and it is being handed over for free.
What to do about tools staff are already using covers the immediate version, and the policy question is shorter than most people expect. If it would be faster to have the ground rules drafted with the leadership team in the room, that is what the workshops are for.