Most organisations have an AI policy problem before they have an AI attack problem. Staff already use chatbots, browser extensions and AI features inside their everyday software, often without anyone in IT or risk knowing. That is shadow AI, and the 2026 breach data suggests it is no longer a footnote.
IBM's Cost of a Data Breach Report 2026, produced with the Ponemon Institute and published on 29 July 2026, studied 602 organisations breached between March 2025 and February 2026. The global average breach cost reached US$4.99 million. According to IBM's announcement, one in four malicious breaches were AI-enabled, a 56% increase, at an average cost of about US$6 million. IBM also reported that more than 20% of organisations had experienced a breach targeting their AI models or applications.
Those headline figures concern attackers using AI and attacks aimed at AI systems. The shadow AI numbers come from coverage of the same report, and they matter just as much to a board. This article sets out what shadow AI looks like in an Australian workplace, why it raises the cost of an incident, a roadmap that moves from discovery to policy, and seven questions directors can put to management.
What the report says about unapproved AI use
Help Net Security's summary of the report, published on 30 July 2026, states that workers using unapproved AI tools figured in 43% of security incidents, more than double the share in the previous year. Those incidents ended in data loss or compromise roughly half the time, and about one in five drew regulatory penalties. These figures come from Help Net Security's summary and do not appear in IBM's public announcement.
The same summary reports two governance gaps. Among organisations that suffered AI security incidents, 92% lacked role-based access, multi-factor authentication or similar controls on their AI models and applications. And close to seven in ten breached organisations had no governance policy for managing AI or detecting unapproved deployments. Fewer than one in five coordinated their AI governance teams with their security teams.
For Australian readers, SecurityBrief's coverage of the 2026 report puts the average Australian breach cost at AUD 4.22 million. That is a country figure from a secondary source, so treat it as a rough local benchmark and not a forecast for your organisation.
What shadow AI looks like in an Australian workplace
Shadow AI is rarely malicious. It is usually a capable employee trying to finish a task faster. The common patterns are worth naming, because each one needs a different control.
- Customer or client data pasted into public chatbots. A staff member summarises a complaint, a contract or a client email in a free consumer tool. The data leaves your environment, and you may have no record that it happened.
- Browser extensions and add-ins. AI writing assistants, meeting recorders and summarisers can read page content, email and calendar data once a user grants permission.
- AI features switched on inside existing SaaS. Your CRM, helpdesk, document platform or video conferencing tool may have added AI features that process your data under terms nobody reviewed.
- Unsanctioned agents and automations. A team connects an AI agent to a mailbox, a shared drive or an accounting system using a personal account, creating a non-human identity that security has never seen.
For an Australian organisation, the exposure is practical. Personal information sent to an overseas AI service raises Privacy Act questions. Client confidentiality obligations do not pause because a tool was convenient. A board should assume some of this is already happening and ask how much.
Why shadow AI raises the cost of an incident
Three mechanisms make an AI-related incident harder and more expensive to contain.
First, you cannot protect data you do not know has moved. When staff use unapproved tools, security teams lack logs, contracts and data flow maps, so scoping the incident takes longer and notification decisions rest on incomplete facts.
Second, AI tools tend to sit outside normal access control. The Help Net Security summary describes most affected organisations as missing basic controls such as role-based access and multi-factor authentication on AI systems. An agent with a broad token and no owner is an attractive target.
Third, governance is often split. When the group that writes AI policy does not talk to the group that monitors the network, nobody owns detection. The gap between policy and enforcement is where the incidents sit.
None of this is an argument for banning AI. Bans push use out of sight, which makes the visibility problem worse. The stronger response is to make safe use easy and unsafe use visible.
A board-level roadmap from discovery to policy
1. Discover and inventory AI use
Start by finding out what is in use. Combine sources: network and proxy logs, identity provider records of third-party app sign-ins, browser extension inventories, expense and procurement data, and a short staff survey that promises no blame. The aim is an AI register that lists each tool, who uses it, what data it touches and who owns it. Expect the first version to be uncomfortable and incomplete. That is normal.
2. Set an acceptable use policy that people can follow
A workable policy is short. It classifies data (for example, public, internal, confidential, regulated), states which classes may go into which tools, and names what is prohibited outright, such as customer personal information in any unapproved service. It should say who approves new tools and how quickly. If approval takes three months, staff will not wait.
3. Provide sanctioned tools
People use shadow AI because it helps. If the organisation provides an approved assistant with appropriate contract terms, data handling and logging, most of the pressure to go elsewhere disappears. This is the step boards tend to underestimate. A policy without an approved alternative is a prohibition, and prohibitions leak.
4. Apply access controls and data loss prevention
Treat AI applications like any other system that holds sensitive data. Require single sign-on and multi-factor authentication, apply role-based access, and inventory the non-human identities that agents and integrations use. Use data loss prevention and web filtering to block or warn on sensitive data going to unapproved AI services, and restrict which browser extensions can be installed. These are the controls the Help Net Security summary found missing in most affected organisations.
5. Train staff on real scenarios
Generic awareness modules do little here. Use concrete examples from your own workflows: what can be pasted into the approved assistant, what cannot, and how to ask for a new tool. Give staff an easy way to report a mistake without penalty, because early reports shorten incident response.
6. Report AI risk to the board with a few clear metrics
Boards do not need a dashboard of forty measures. A handful is enough:
- the number of AI tools and features in the register, and how many are approved
- the proportion of staff using approved tools versus unapproved ones, as best it can be measured
- the number of blocked or flagged attempts to send sensitive data to unapproved AI services
- the share of AI applications with MFA and role-based access in place
- the number of AI-related incidents and near misses, and the time taken to contain them
Trends matter more than absolute numbers. A rising count of discovered tools usually means visibility is improving, not that risk is worsening.
Where ISO/IEC 42001 fits
ISO/IEC 42001:2023 is the international standard for AI management systems. ISO describes it as setting requirements for establishing, implementing, maintaining and continually improving a structured set of policies, processes and controls that govern how AI systems are designed, developed, deployed and used. It applies to organisations that develop, provide or use AI, including those that rely on third-party AI systems. That covers most Australian businesses.
The requirements include leadership and organisational context, an AI policy and objectives, AI risk management, data governance and lifecycle controls, performance evaluation and continual improvement. Certification is voluntary and is carried out by independent certification bodies, not by ISO. The standard does not replace law. It gives a management framework for meeting obligations consistently.
For shadow AI, the standard gives the roadmap above a home. The inventory becomes part of understanding where AI is used, the acceptable use policy becomes the AI policy, the metrics feed performance evaluation, and named owners answer the question of who is accountable. Many organisations use the standard's structure without pursuing certification, and that is a reasonable starting point.
Seven questions directors should ask management
- Where is AI being used in the organisation today, including tools nobody approved? Ask how the answer was obtained, and how recently.
- What data are staff allowed to put into which AI tools, and how is that enforced? A written rule with no technical control is a weak answer.
- What approved AI tools do staff have, and are they good enough that people will use them?
- Which AI applications and agents have access to our systems, and who owns each one? Include non-human identities and AI features embedded in existing software.
- Do our AI applications have MFA and role-based access, and do our AI and security teams work together?
- If sensitive data went into an unapproved AI service last week, would we know, and what would we do? Ask whether AI misuse is covered in the incident response plan and tested.
- Which framework are we using to structure AI governance, and what will the board see each quarter? Ask for the metrics, the owner and a date for the first report.
Key takeaways
- IBM's 2026 report found one in four malicious breaches were AI-enabled, and more than 20% of organisations reported a breach targeting AI models or applications.
- Help Net Security's summary of the report attributes 43% of incidents to workers using unapproved AI tools, more than double the prior share.
- Most affected organisations lacked basic controls such as MFA and role-based access on AI systems, and close to seven in ten lacked AI governance policies, per the same summary.
- Shadow AI includes pasted data, browser extensions, embedded SaaS features and unsanctioned agents. Each needs its own control.
- A ban is the weakest response. Discover, set a usable policy, provide approved tools, enforce access and data controls, train staff and report a few metrics to the board.
- ISO/IEC 42001 can give the programme structure, with or without certification.
CyberCorp's GRC specialists help Australian organisations find where AI is already in use, set practical governance and report it to the board. Schedule a GRC Assessment to start with an AI inventory and risk review, or learn more about our Secure AI Deployment service.


