Tech
Shadow AI and the Enterprise Discovery Gap: What Security Teams Are Missing
| Key Takeaways
• 60% of IT teams are unaware of employee interactions with generative AI tools, according to Cisco’s 2025 Cybersecurity Readiness Index. • Organizations with high levels of shadow AI saw an average of $670,000 in higher breach costs than those with minimal or no shadow AI usage, per IBM research. • Only 37% of organizations currently have policies in place to manage or detect shadow AI. • Discovery has to precede detection, enforcement, and governance, since none of those controls can work against AI usage a security team doesn’t know exists. |
What exactly is shadow AI, and how is it different from shadow IT?
Shadow AI is when employees use AI tools, applications, or services without IT oversight, approval, or a formal security review, the same underlying pattern as shadow IT applied specifically to AI. The key difference is how it spreads: shadow IT usually requires installing software or requesting access, while using an AI tool rarely involves a purchase order or an IT ticket at all, since most SaaS applications now integrate AI capabilities by default and employees can start using an AI feature simply by clicking into a menu that already exists inside a tool they were approved to use. An in-depth look at the AI discovery gap facing most enterprises today describes this as a phenomenon that “spreads fast, hides easily,” leaving most enterprises without a clear picture of how widespread their own AI usage actually is, since teams experiment independently, developers integrate coding assistants into their own workflows, and individual employees turn to personal AI accounts on corporate devices, often without any of it being visible to the same security team at the same time.
Why can’t most enterprises see all the AI tools employees are already using?
Because AI usage doesn’t follow the acquisition patterns security tooling was built to monitor, and the visibility gap this creates is larger than most security teams assume. recent global cybersecurity readiness research from Cisco found that 60% of IT teams are unaware of employee interactions with generative AI tools, and 22% of employees have unrestricted access to public GenAI platforms even where some AI governance exists. The same research found that 60% of organizations lack confidence in their ability to detect unregulated AI deployments across their environment, which means the gap isn’t just about individual tool sprawl but about a structural inability to know when new AI usage starts, since traditional discovery methods built for procured software simply don’t capture usage that never went through procurement in the first place.
60% of IT teams report being unaware of employee interactions with generative AI tools, according to Cisco’s 2025 Cybersecurity Readiness Index.
Does shadow AI actually increase the cost of a data breach?
Yes, measurably. IBM’s newly released breach-cost research found that organizations with high levels of shadow AI experienced an average of $670,000 in higher breach costs compared to organizations with minimal or no shadow AI usage, and that one in five organizations experienced a breach stemming specifically from shadow AI. Despite that cost gap, only 37% of organizations currently have policies in place to manage or detect shadow AI at all, which helps explain why the exposure keeps compounding: the tools driving up breach costs are frequently the same ones without any formal detection policy covering them. Shadow AI-related incidents were also found to compromise personally identifiable information at a higher rate than the global average across all breach types, and intellectual property exposure followed a similar pattern, underscoring that this isn’t a theoretical governance gap but one already showing up in real incident data with real financial consequences.
What specific risks does the AI discovery gap actually create once it exists?
Several distinct risks tend to stack on top of each other once an organization can’t see its own AI usage clearly. These include data leaking into public models through ordinary employee use, prompt injection attacks targeting whichever tools are in use, AI agents operating with more autonomy than anyone approved, and missing audit trails that make it difficult to reconstruct what happened if an incident needs to be investigated after the fact. Each of these compounds the others: a missing audit trail doesn’t just slow down incident response, it also means a security team often can’t say with confidence whether a given exposure was a one-time event or part of an ongoing pattern, which in turn makes it harder to brief leadership on the organization’s actual risk posture with any precision.
Why is this considered a compliance risk as well as a security risk?
Because shadow AI usage tends to sit outside the systems and data flows that a compliance program was built to track, and regulations like the EU AI Act, GDPR, and HIPAA generally assume an organization can name the systems processing regulated data. When an employee pastes customer records or protected health information into an AI tool nobody inventoried, that activity typically also has no audit trail, which becomes a serious problem if an incident later needs to be investigated or reported to a regulator on a deadline. This is one reason enterprise AI governance conversations increasingly involve legal and compliance stakeholders alongside security, since closing the discovery gap serves both functions at once rather than being purely a security team’s problem to solve on its own.
What’s the first step toward closing the AI discovery gap?
Discovery itself has to come before detection, enforcement, or governance, since none of those controls can function against AI usage a security team doesn’t know exists. Controls for the public AI tools employees adopt on their own are typically the starting point, since public, consumer-facing AI tools are where most undocumented usage originates before any internal AI governance program gets involved. From there, most organizations move toward the kind of structured, evaluation-stage resources that turn discovery into an actual program, and a set of downloadable briefs covering common enterprise AI governance scenarios can give security and risk teams a starting framework for that next stage. The Cisco findings cited above are a useful benchmark for organizations trying to gauge how their own AI visibility compares to peers, given how few organizations worldwide currently rate their own readiness as mature.
Is closing the AI discovery gap a one-time project or an ongoing effort?
It’s ongoing, since new AI capabilities keep arriving through channels an inventory can’t fully anticipate in advance. A SaaS vendor can add a generative AI feature to an already-approved product overnight, a new personal AI account can appear on a corporate device the same afternoon, and neither event necessarily triggers any of the review processes built for traditional software procurement. That’s part of why organizations with minimal or no shadow AI tend to treat discovery as a continuous function rather than a project with a defined end date, revisiting their inventory on a regular cadence instead of assuming a single audit closes the gap for good.
How does closing the discovery gap change an organization’s overall security posture?
It shifts the posture from reactive to proactive, since most of the AI-related controls that actually reduce risk, policy enforcement, access restrictions, monitoring, depend on already knowing which tools and workflows they need to apply to. Without discovery, security teams are effectively responding to AI-related incidents after the fact, often learning about a given tool’s use for the first time during that investigation rather than beforehand. With it, the same team can prioritize the highest-risk usage first, focus governance resources where they matter most, and give leadership a realistic picture of AI exposure instead of one built only on what was formally approved.
Frequently Asked Questions
What is shadow AI?
Shadow AI is the use of AI tools, applications, or services by employees without IT oversight, approval, or a formal security review, similar to shadow IT but applied specifically to AI usage.
How common is it for IT teams to be unaware of employee AI usage?
Cisco’s 2025 Cybersecurity Readiness Index found that 60% of IT teams are unaware of employee interactions with generative AI tools.
Does shadow AI make data breaches more expensive?
Yes. IBM’s 2025 research found organizations with high levels of shadow AI saw an average of $670,000 in higher breach costs compared to organizations with minimal or no shadow AI usage.
What should an organization do first to address shadow AI?
Discovery comes first. A security team needs visibility into which AI tools are actually in use before it can apply detection, enforcement, or governance controls to that usage.