While AI-powered defenses are cutting data breach costs, a new IBM report highlights the escalating risk of “ungoverned AI” and “shadow AI.” Lacking proper oversight, these hidden systems are leading to more costly breaches and compromising sensitive data.

The digital landscape, ever-shifting and increasingly complex, presents a paradox.
A recent report from IBM, the 2025 Cost of a Data Breach Report, offers a glimmer of hope on one front, only to reveal a far more insidious threat lurking in the shadows of the artificial intelligence revolution.
For the first time in five years, the global average cost of a data breach has decreased, settling at $4.44 million.
This positive trend is largely attributed to the very technology causing new anxieties: AI-powered defenses, which are enabling faster containment of cyber incidents.
Yet, this small victory masks a deeper, more fundamental challenge to organizational integrity and control.
The report paints a stark picture of enterprises grappling with a growing crisis of “ungoverned AI”—systems and tools that have proliferated within organizations without official knowledge, approval, or oversight.
It’s a digital blind spot, a creeping loss of control that traditional cybersecurity frameworks are ill-equipped to address, threatening to compromise institutional decision-making at its core.
The numbers are alarming.
A staggering 97% of organizations that experienced AI-related security incidents lacked proper AI access controls.
Even more concerning, nearly two-thirds of breached organizations, 63% to be precise, had no governance policies whatsoever for managing AI or detecting its unauthorized use.
These aren’t just technical oversights; they represent systemic organizational vulnerabilities, a collective shrug in the face of a rapidly evolving technological frontier.
At the heart of this emerging crisis is “shadow AI.”
Picture employees, often with good intentions, adopting readily available AI tools to streamline tasks, analyze data, or generate content – all outside the purview of IT departments and security protocols.
This informal adoption has become a significant liability.
One in five organizations reported a breach directly linked to shadow AI, with these incidents adding an average of $670,000 to the cost of a breach.
Why the higher price tag? Because these hidden systems take a week longer to detect and contain, allowing more damage to accrue.
More often than not, shadow AI breaches lead to the compromise of personally identifiable information (65%) and intellectual property (40%), displacing even the perennial security skills shortage as one of the top three most costly breach factors.
This pervasive “governance vacuum” isn’t merely an inconvenience; it’s a ticking time bomb.
The finding that 63% of organizations lack AI governance policies underscores a profound underinvestment in oversight.
Traditional IT governance assumes a clear inventory of technical assets and controlled deployment.
But AI, with its ease of adoption and often subtle integration, defies these established norms.
Even among organizations that do have policies, less than half have formal approval processes for AI deployments, and a mere 34% conduct regular audits for unsanctioned AI.
This oversight deficit creates a cascade of risks: invisible dependencies where critical operations rely on unknown AI, compliance blindness to regulatory requirements, and an accumulating liability from AI decisions, biases, errors, and security incidents that go unmanaged and uninsured.
The challenge extends to access controls.
The fact that 97% of organizations with AI security incidents lacked proper controls highlights an inherent tension: AI systems often require broad data access to function effectively, a need that frequently clashes with stringent security requirements.
The AI supply chain itself is emerging as a critical attack vector, with incidents often originating from compromised apps, APIs, or plug-ins.
These vulnerabilities have far-reaching consequences, leading to widespread data compromise in 60% of cases and operational disruption in 31%, signaling that AI systems are becoming high-value targets for malicious actors.
Globally, the picture is equally fragmented.
While many countries saw a decrease in average breach costs, the US experienced a surge to an all-time high of $10.22 million, largely driven by steeper regulatory fines.
This divergence suggests that organizations operating across borders face an uphill battle in maintaining consistent AI oversight while navigating a patchwork of evolving and often conflicting regulatory requirements.
The IBM report, therefore, serves as a crucial wake-up call, urging organizations to move beyond reactive cybersecurity measures to proactive AI governance.
The path forward demands a multi-pronged approach: systematically identifying all AI usage, including informal tools; implementing monitoring systems to detect shadow AI before it becomes a liability; developing comprehensive governance frameworks with strict approval processes; integrating AI-specific risks into existing enterprise risk management; and, critically, preserving human oversight to ensure that AI remains a tool, not an autonomous decision-maker.
Ultimately, effective AI security transcends the traditional IT perimeter.
It requires a fundamental shift in organizational culture, demanding transparency, accountability, and a commitment to maintaining institutional awareness and control over AI-influenced decision-making processes.
The alternative – a landscape riddled with invisible AI dependencies and ungoverned shadow systems – promises not just increased data breach costs, but an erosion of trust, a proliferation of compliance failures, and an accumulation of liabilities that could fundamentally undermine an organization’s future.
The time to bridge the AI oversight gap is now, before the very technology designed to empower us inadvertently strips away our control.