In April 2023, engineers at Samsung pasted internal source code into ChatGPT.
By early May the company had banned generative AI on its phones, computers, tablets and internal network. The memo did not soften it. Failure to follow the guideline could result in disciplinary action up to and including termination of employment.
Samsung had two things most organizations do not. They detected the leak, and they had the authority to act on it.
Both halves matter. Detection without authority produces a memo nobody enforces. Authority without detection produces a policy about a problem you cannot see.
Almost everybody else responded to the same risk differently. They did not ban it and they did not sanction it. They stopped counting.
Which is a decision, even when nobody makes it out loud. It converts a governance problem into an invisible one, and invisible problems do not get cheaper while you wait.
The number attached to not knowing
IBM's 2025 breach research put a figure on that choice.
Security incidents involving shadow AI, meaning AI used without employer approval or oversight, accounted for 20 percent of breaches. That is 7 percentage points higher than incidents involving sanctioned AI. A further 11 percent of breached organizations were not sure either way.
Where shadow AI use was high, breaches cost $670,000 more on average. The shadow AI breach averaged $4.63 million. The global average fell to $4.44 million that year, so the gap widened while the baseline improved.
The cost gap is not because these breaches are more severe. It is because they take longer to find. Detection and containment ran roughly a week longer than the global average, and a week is a long time when the thing you are looking for is not in your asset inventory.
One more figure from the same work belongs in every architecture review. In 97 percent of AI-related security breaches, the AI systems involved lacked proper access controls.
What actually goes in
Cyberhaven measured the other side of it, watching what employees put into these tools rather than what happened afterward.
By March 2024, 27.4 percent of corporate data being pasted into AI tools was sensitive. A year earlier that figure was 10.7 percent. The share more than doubled in twelve months, which is a different kind of problem from a slow drift.
The categories are not exotic. Customer support content, 16.3 percent of sensitive data. Source code, 12.7 percent. Research and development, 10.8 percent. Ordinary work, sent to an ordinary tool.
The most revealing line is about legal documents. They are only 2.4 percent of the sensitive data flowing into these tools, so a dashboard would rank them last. But 82.8 percent of them go in through unsanctioned accounts. Low volume, almost entirely unmonitored, and precisely the material you would least like to see in someone else's training corpus.
The account is the problem, not the model
Here is where most policy conversations go wrong. They argue about which model is safe.
The measurement says the exposure sits in the account. Cyberhaven found 73.8 percent of ChatGPT accounts in use at work were not corporate accounts. For Gemini it was 94.4 percent.
Think about what a personal account removes.
No single sign-on. The identity is not yours. No central logging, so the prompt history is not discoverable. No retention control, so you cannot say what was kept. And no revocation. When the employee leaves, the account goes with them, and so does everything in it.
The model on the other end could be flawless and none of that would change. An employee using a personal account has moved company data to a third party under a contract the company never signed.
A safe model reached through an account you do not control is still an uncontrolled data transfer. A mediocre model reached through your own tenant, with logging and revocation, is a governed one.
Prohibition is the answer that does not scale
Samsung banned it. That was the right call for them and it is worth understanding why it is rarely repeated.
A ban is enforceable when you control three things. The device, the network and the consequence. Most organizations control one. Block the tools on the corporate network and the work moves to a phone, where you have no visibility at all. You have not reduced the exposure, you have relocated it somewhere you cannot measure.
People use these tools because they work. Every hour saved is real, the employee knows it, and a policy that ignores that gets routed around by capable people acting in good faith.
Treat that as design information rather than a discipline problem. The 73.8 percent figure is not evidence of 73.8 percent of employees behaving badly. It is evidence that the sanctioned path was slower, or absent, or nobody knew it existed.
What works instead
The pattern that holds is unglamorous. Make the sanctioned path better than the shadow one, then close the shadow one.
Provide enterprise accounts with single sign-on, so usage is attributable and revocable. Buy enough seats that nobody has a reason to reach for a personal login.
The arithmetic on that is not close. A year of enterprise seats for a 500-person company costs a fraction of the $670,000 the shadow AI premium adds to a single breach. Rationing seats to control spend is the most expensive saving available here. That sounds trivial and it is the single highest-return control here, because it converts invisible usage into logged usage without asking anyone to work worse.
Then inspect the boundary, not the model. Data loss prevention on paste and upload catches source code and regulated data on the way out. It works whatever the destination is called next quarter.
That ordering matters. Controls at the boundary survive the vendor list changing. Controls tied to named tools do not.
Publish what is allowed in plain language. Most employees cannot tell whether a customer email counts as regulated data, and nobody has told them.
One page. Three lists. What you can put in, what you cannot, and where to ask. Any policy longer than that will be read by the compliance team and nobody else.
The measurement that changes the conversation
If you take one thing from the IBM figures, make it the 11 percent who did not know.
Certainty about your own environment is the precondition for every other control. An organization that cannot say whether shadow AI was involved in a breach also cannot say whether its data is in a vendor's logs, cannot answer a regulator, and cannot tell you what a specific employee sent last Thursday.
That is not a technology gap. It is an inventory gap. Inventory has never been the exciting part of anything, and it is the part that decides whether you can answer a question under pressure.
The test to run this week
Ask your network or security team for one number. How many distinct AI tools were reached from your environment in the last 30 days.
Then ask how many are on your approved list. The gap is your shadow AI estate, and it is usually larger than the list by an order of magnitude.
Do not treat the gap as a violation report. Treat it as a demand signal. The tools people reached for without asking are the ones worth buying properly.
Then ask the harder question, which is not about tools at all. For the ones on the approved list, is usage tied to a corporate identity you can revoke on someone's last day? If the answer is no, an approved tool on a personal account is still shadow AI. It just has permission.
Sources
IBM, Cost of a Data Breach Report 2025, July 2025. Shadow AI accounted for 20% of breaches, 7 points above sanctioned AI, adding $670,000 to average cost and taking about a week longer to contain. 97% of AI-related breaches involved systems lacking proper access controls.
Cyberhaven, Shadow AI: how employees are leading the charge in AI adoption and putting company data at risk, May 2024. By March 2024, 27.4% of corporate data entering AI tools was sensitive, up from 10.7% a year earlier. 73.8% of workplace ChatGPT accounts were non-corporate. Company-published.
CNBC, Samsung bans use of A.I. like ChatGPT for employees after misuse of the chatbot, May 2023. Samsung prohibited generative AI on company devices and its internal network after engineers leaked internal source code, warning that breaches could lead to termination. Trade reporting.
