In a single year, the share of employees using AI tools on corporate devices tripled. From 15% to 45%. Most of that usage is happening through personal accounts that organizations don’t control, can’t audit, and didn’t approve. And the most common type of data being uploaded to those tools isn’t marketing copy or calendar notes. It’s source code, internal documents, and proprietary research.

Those figures come from the Verizon 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches. Shadow AI is now the third most common non-malicious insider action detected in enterprise data loss prevention datasets, a fourfold increase from the prior year. The question isn’t whether your organization is affected. It’s whether anyone is watching.

Most Organizations Are Governing AI the Same Way They Governed Cloud Storage in 2011

When Dropbox went mainstream, most IT teams had no visibility into what employees were syncing. Client files, contracts, and financial documents moved to personal accounts because it was faster. By the time organizations built policies, years of untracked data had already moved.

AI is following the same pattern, with two key differences. Adoption is faster. And the exposure works differently. When a staff member pastes client data into ChatGPT or Claude through a personal account, that data is processed by an external model under terms the organization never agreed to, can’t audit, and often can’t even identify.

IBM’s 2025 Cost of a Data Breach Report found that only 37% of organizations have any AI governance policy at all, and among those that do, fewer than half have an actual approval process for AI deployments. The gap between adoption and governance is where incidents happen, and the financial consequences are measurable: shadow AI breaches carry an average premium of $670,000 above a standard incident.

What AI Data Leakage Actually Looks Like

The term “data leakage” suggests hackers and exfiltration tools. The reality is more mundane, and harder to catch for exactly that reason.

An association’s communications director uploads a grant application to Claude for editing help. A nonprofit’s finance manager pastes a donor report into ChatGPT to summarize it for the board. A program officer copies internal research into an AI interface to draft a policy brief faster. No malicious intent, no security awareness, and sensitive organizational data is now sitting on infrastructure the organization doesn’t control, processed under retention terms nobody reviewed.

IBM’s breach data shows customer PII appearing in 65% of shadow AI incidents (versus 53% in standard breaches), with intellectual property exposed in 40% of cases. For nonprofits and associations handling donor records, membership data, or beneficiary information, most AI tools accessed through personal accounts operate without a Data Processing Agreement. In some jurisdictions, that’s a compliance exposure in its own right, regardless of whether a breach ever occurs.

Agentic AI Makes the Problem Harder to Contain

The shadow AI problem has a second layer that most governance discussions haven’t caught up with yet.

Modern AI tools are increasingly agentic. They don’t just respond to prompts. Through integrations like Claude’s Model Context Protocol (MCP), they connect to Slack, Google Drive, M365, and internal databases and take actions autonomously. A staff member who connects Claude to their work calendar to manage scheduling has granted an external AI system ongoing access to organizational data, often without understanding what that means at a data governance level.

When AI has persistent access to systems and acts autonomously, revoking access after an incident doesn’t undo what’s already been processed. There’s no reliable way to retrieve data that has passed through an external model’s context. The remediation shifts from a technical problem to a legal exposure management problem, which is considerably more expensive and uncertain.

What Your IT Company Should Be Doing About This

AI governance isn’t a problem your IT provider should be waiting for you to raise. If they haven’t brought it up, that’s worth noting. Effective oversight has four components:

  1. Visibility: A live inventory of which AI tools are in use, by whom, and through which account types (corporate-managed or personal). Without this, everything else is guesswork. Most standard network monitoring doesn’t surface AI-specific data flows without deliberate configuration.
  2. Policy: A written AI acceptable use policy that classifies tools, defines what data categories can and cannot enter AI interfaces, and establishes what happens when someone violates it. A policy that hasn’t been communicated is not a control.
  3. Sanctioned alternatives: Blocking AI tools doesn’t stop employees from using them. It drives usage underground. Research consistently shows that providing approved alternatives dramatically reduces shadow AI usage. The goal is to make the safe path the easy path.
  4. Ongoing monitoring: New tools appear constantly and employee behavior changes. Continuous monitoring with alerts for anomalous AI data flows is how organizations catch issues before they become incidents, rather than discovering them 247 days later (the average detection window for shadow AI breaches, per IBM’s 2025 data).

The Right AI Governance Question to Ask Your IT Company

Ask them:

“can you tell me which AI tools are currently in use in our environment, through which account types, and what data has been processed through them in the last 90 days?”

If the answer is “we don’t have that visibility,” that’s important information. Any governance policy you have in place is unenforceable without monitoring behind it.

Orion Networks works with nonprofits and associations in the DC metro area to build IT programs that treat AI governance as a standing operational concern, not a one-time project. That includes discovery, policy development, approved tool deployment, and the monitoring infrastructure to make oversight real. If you’re not sure where your organization stands, reach out to the Orion Networks team at (202) 505-6157 to start the conversation.

Orion Technologies Tips & Articles

Check Out Our Tech Education