Facebook
Cart $ 0.00
0
Subtotal: $ 0.00
No products in the cart.
Cart $ 0.00
0
Subtotal: $ 0.00
No products in the cart.
AI Use Risks

The Employee Down the Hall Is Already Using AI You Don’t Know About

A lot of organizations still think unsanctioned AI use is mostly a policy issue. The bigger problem is that it’s already happening, and often at a surprising scale. Multiple 2026 industry surveys put unauthorized AI tool use among employees at 60 to 90 percent, depending on how it’s measured. Most of it isn’t malicious, but it poses risks. Someone pastes a client contract into a free chatbot to summarize it. A developer runs code through an AI assistant to debug faster. A manager uploads pricing data for a quick analysis. No bad intent, and often no real understanding that the data just left the building.

The exposure is starting to show up in breach numbers. IBM’s 2026 Cost of a Data Breach Report found that shadow-AI-linked incidents more than doubled as a share of AI-related breaches year over year, and Netwrix’s 2026 Data and Identity Security Report found organizations where AI significantly expanded data access saw breach rates nearly four times higher than organizations where it hadn’t. Meanwhile, Mimecast’s State of Human Risk 2026 report found that while most security leaders are worried about the problem, a majority still have no specific strategy to address it.

People know the risk is there, but they don’t always have a plan for it. Nobody has to mean harm for shadow AI to become the first line of your next breach disclosure. And once that happens, “how did this happen?” becomes just as hard to answer as “why didn’t you tell us sooner?”

Tips for readers:

  • Find out what AI tools your teams are already using before a breach notice tells you. A short, non-punitive survey usually surfaces more than a policy memo.
  • Offer an approved, secure AI tool before banning the unapproved ones. Blocking access without a sanctioned alternative just pushes the activity onto personal devices, where you have zero visibility.
  • Add “was AI involved” as a standing question in your breach and incident intake process, the same way you’d ask about third-party vendors.
Picture of Deb Hileman, SCMP FCSCE CCMC

Deb Hileman, SCMP FCSCE CCMC

President and CEO, Institute for Crisis Management®