Security

Your Staff Are Already Using AI You Didn't Approve. Banning It Is the Worst Option

Somebody has pasted customer information into a free AI tool this month. They were not being reckless — they were behind, and nobody had given them a sanctioned way to do it. The 2026 data says the obvious response, a firmer ban, is the one that measurably fails.

Disclosure, up front

We set up sanctioned AI tools for businesses, so "give your staff a proper tool" is a conclusion we profit from. Read section 05 with that in mind — most of what we recommend there costs nothing and involves no vendor. We have also put the enterprise-versus-small-business caveat on every figure below, because the headline numbers in this field come from organisations nothing like yours and are routinely quoted as if they did not.

Somebody in your business has pasted customer information into a free AI tool. Probably this month. Possibly today.

They were not being reckless. They had a list to reformat, or an angry email to soften, or a contract to summarise, and the tool did in thirty seconds what would have taken forty minutes. If you have never given them a sanctioned way to do that, they used whichever one came up first, signed in with a personal account.

This has a name now — shadow AI — and 2026 is the year it became the largest single line item in breach reporting. The interesting part is what the data says about the obvious response. Banning it is measurably not working.

What the 2026 data actually says

  • Shadow AI incidents more than doubled, from 20% to 43% of AI-related breaches, per IBM's 2026 Cost of a Data Breach Report.
  • Approval requirements went down while incidents went up. Organisations requiring IT sign-off before deploying AI fell from 45% to 38%.
  • 68% had no AI governance at all to manage AI use or detect shadow AI.
  • Around two thirds of office workers say they have used AI at work believing it broke company policy — so the policy existed, and they used it anyway.
  • Roughly 47% of generative AI users reach the tools through personal accounts, which is the part no company control can see.

Cost figures from that report — a $4.99m global average breach, $5.39m where shadow AI was involved — are enterprise averages and are not your exposure. Read them as evidence that the mechanism is real and expensive, not as a forecast for a ten-person firm.

01The number that matters is not the dollar figure

Every write-up of this leads with $5.39 million. For a small business that number is worse than useless, because it describes companies with security teams, legal departments and regulatory reporting duties you do not have. Quoting it at you is fear-selling.

The genuinely informative figures are the behavioural ones, and they tell a coherent story:

Shadow AI: prevalence, governance and outcomes, 2026
Measure 2026 Year earlier What it tells you
Share of AI-related breaches involving shadow AI 43% 20% More than doubled in a year.
Organisations requiring IT approval before AI is deployed 38% 45% Control is loosening while exposure rises.
Organisations with no AI governance to detect shadow AI 68% Most cannot see the problem at all.
Shadow AI incidents causing data loss or compromise 49% About half of incidents actually lose data.
Malicious breaches that were AI-enabled 1 in 4 (+56%) The attacker side is growing too.

IBM Cost of a Data Breach Report 2026, via IBM's own newsroom summary of 29 July 2026, read 9 September 2026. The sample is enterprise-weighted. Employee-behaviour figures cited elsewhere in this article (roughly two thirds using AI against policy, about 47% via personal accounts) come from separate third-party workplace surveys, not from IBM, and survey self-reporting is softer evidence than incident data.

02Why banning it makes things worse

Put two of those figures side by side. Roughly two thirds of office workers report having used AI at work while believing it was against policy. And the proportion of organisations requiring approval fell from 45% to 38% while incidents doubled.

A prohibition that most staff quietly ignore is not a control. It is worse than no policy at all, for three reasons:

  • It moves the activity onto personal accounts. Which is precisely the 47% figure. Work done in a sanctioned account is visible, revocable and covered by a contract. The same work in someone's personal account is none of those things, and it survives them leaving.
  • It destroys your reporting line. If somebody pastes a client list somewhere they should not have, you need to hear about it that afternoon. Under a ban, telling you means admitting to a disciplinary offence. You will find out much later, from someone else.
  • It does not survive the pressure that caused it. The person was not curious; they were behind. A rule that competes against a deadline loses to the deadline.

The question that reframes this

Not "how do we stop people using AI" but "what were they trying to do, and what is the sanctioned way to do it?" Shadow AI is nearly always a symptom of a task that is too slow and a tool that was never provided. Remove the reason and the behaviour goes with it; leave the reason and no policy will hold.

03What actually leaks in a small business

Enterprise write-ups describe model training pipelines and API sprawl. In a business under fifty people, the realistic incidents are mundane and specific:

  • A customer list pasted in to be reformatted or deduplicated. The single most common one we see. Names, addresses, phone numbers, sometimes payment references.
  • A contract or quote uploaded to be summarised — frequently someone else's confidential document, which makes it their problem as well as yours.
  • An angry customer email pasted in to draft a reply, complete with the customer's account details and complaint.
  • Medical, financial or HR information pasted by someone who did not register that the rules are different for that category.
  • Credentials in a config file or error log pasted while debugging. This one is the fastest route to a real compromise, because the pasted secret is often still live.

None of these is exotic and none involves an attacker. They are ordinary people doing their jobs with the only tool available.

04The three questions that decide whether a tool is safe to sanction

You do not need a security assessment. You need three answers, in writing, from each tool you are considering blessing.

  • Does it train on what we put in? Consumer tiers frequently do by default; business tiers frequently do not. This is usually a setting and a plan level, and it is the single biggest difference between a free account and a sanctioned one.
  • Where does the data go, and how long does it stay? Retention period, region, and whether staff can delete a conversation permanently. This is what you will need if a customer ever exercises a deletion right.
  • Can we see and revoke access? Can you list who in your business uses it, and cut someone off the day they leave? A personal account fails this question completely, which is the whole argument for providing accounts.

A vendor that answers all three crisply has thought about business customers. One that has to check is telling you where you sit on their roadmap — the same test we suggest for agent permissions.

05The policy that actually fits a small business

One page. Most of it costs nothing.

  • Provide a sanctioned tool, on company accounts, before you restrict anything. Order matters. Restriction without provision is the ban that does not work.
  • Write down three things that never go in, in plain words. Not a taxonomy. Something like: no customer personal details, no passwords or keys, nothing covered by somebody else's confidentiality agreement. People remember three.
  • Say what to do instead for each of those, because "don't" without "instead" fails at the first deadline.
  • Make reporting a mistake consequence-free, out loud and in writing. The value of hearing about a paste within the hour is enormous; the value of punishing it is zero. Say so explicitly or nobody will believe it.
  • Turn off training on your inputs wherever the setting exists, and check it after vendor updates, since defaults move.
  • Review who has access quarterly and remove leavers — the same quarterly review the subscription audit already needs.

Note what is absent: monitoring software, blocking, and training people to fear the tools. None of it is necessary at this size, and the first two mostly push usage further out of sight.

06What not to do

  • Do not buy shadow-AI detection first. If you have not provided a sanctioned tool, detection just produces a list of people to be annoyed with. Provision first, detect later if you ever need to.
  • Do not write the long policy. A document nobody finishes reading protects nobody. Three prohibitions people can recall beat twelve they cannot.
  • Do not quote the enterprise breach figures at your staff. They know a $5 million average is not your business, and using it costs you credibility on the parts that are true.
  • Do not assume the paid tier is private. Check the setting. Plans get restructured and defaults change; this is a thing to verify, not to believe.

07The honest summary

Shadow AI went from a fifth to nearly half of AI-related breaches in a year, while the share of organisations requiring approval fell and most had no way to see the problem. Two thirds of workers say they have used AI against policy, and about half reach it through personal accounts where no employer control applies.

Read together, that is not an argument for a firmer ban. It is evidence that bans are what produced the personal accounts. The response that fits a small business is to provide a decent sanctioned tool, name three things that never go into it, and make owning up cost nothing. That is an afternoon's work, and it removes the reason the behaviour exists rather than adding a rule on top of it.

08Common questions

What is shadow AI?

Employees using AI tools the business has not approved or does not know about, usually through personal accounts. It matters because work done in a personal account is invisible to the employer, is not covered by a business contract with the vendor, cannot be revoked when the person leaves, and may be used to train the vendor's models depending on the plan and settings.

How common is shadow AI?

IBM's 2026 Cost of a Data Breach Report found shadow AI involved in 43% of AI-related breaches, up from 20% a year earlier, and that 68% of organisations had no AI governance capable of detecting it. Separate workplace surveys put roughly two thirds of office professionals as having used AI at work while believing it broke policy, with about 47% of generative AI users reaching tools through personal accounts.

Should we ban AI tools at work?

The evidence argues against it. Around two thirds of workers report using AI despite believing it was against policy, and the share of organisations requiring approval fell from 45% to 38% while incidents doubled. A ban tends to push activity onto personal accounts, which is exactly the exposure you cannot see or revoke, and it destroys your reporting line because admitting a mistake means admitting a disciplinary offence. Provide a sanctioned tool first, then set limits.

What kinds of data actually leak through shadow AI in a small business?

Mundane, specific things: a customer list pasted in to be reformatted or deduplicated; a contract or quote uploaded for summarising, often someone else's confidential document; an angry customer email pasted in to draft a reply, with account details attached; medical, financial or HR information pasted by someone who did not register that category is different; and credentials from a config file or error log pasted while debugging, which is the fastest route to real compromise because the secret is often still live.

What should I ask an AI vendor before approving a tool?

Three things, in writing. Does it train on what we put in — consumer tiers frequently do by default and business tiers frequently do not. Where does the data go and how long does it stay, including region, retention period and whether a conversation can be permanently deleted. And can we see who uses it and revoke access when someone leaves. A personal account fails that last question entirely, which is the core argument for providing company accounts.

Do the million-dollar breach figures apply to a small business?

No. IBM's $4.99 million global average, and the $5.39 million average where shadow AI was involved, come from an enterprise-weighted sample of organisations with security teams, legal departments and regulatory reporting duties. Treat those numbers as evidence that the mechanism is real and costly, not as a forecast of your exposure. The behavioural figures — how many people do this, and through what accounts — transfer far better than the dollar amounts.

What should a small business AI policy contain?

One page. Provide a sanctioned tool on company accounts before restricting anything. Name three things that never go in, in plain words: no customer personal details, no passwords or keys, nothing covered by someone else's confidentiality agreement. Say what to do instead for each. State explicitly and in writing that reporting a mistake carries no consequence. Turn off training on your inputs where the setting exists and re-check after vendor updates. Review access quarterly and remove leavers.

Should we buy shadow AI detection software?

Not as a first step. If you have not yet provided a sanctioned alternative, detection produces a list of people to be annoyed with rather than a reduction in risk, and it pushes the behaviour further out of sight. Provision first. Detection and monitoring are reasonable later, at a size where you genuinely cannot see your own tool estate, but for most small businesses the quarterly access review does the same job for nothing.

Ask your team one question

Ask what they have used AI for in the last month, with an explicit promise that nobody is in trouble. Send us the list. We will tell you which of those tasks needs a sanctioned tool, which needs a rule, and which is fine as it is. Most lists come back with one genuine risk and several things that were never a problem — and the audit is free either way.

Ask for a shadow AI check

Sources, read 9 September 2026: IBM's Cost of a Data Breach Report 2026, via IBM's own newsroom summary of 29 July 2026, for the 43%/20% shadow AI share, the 45%-to-38% approval decline, the 68% governance gap, the 49% data-loss rate, the one-in-four AI-enabled malicious breach figure and the $4.99m / $5.39m cost averages. That sample is enterprise-weighted and its dollar figures are not a small business's exposure, which is stated wherever they appear. The employee-behaviour figures — roughly two thirds using AI against policy, about 47% via personal accounts — are from separate third-party workplace surveys, are self-reported, and are weaker evidence than incident data. The five leak scenarios and the one-page policy are our own, drawn from client work rather than from any dataset. Related: An AI Agent Breached a Real Company and AI That Remembers Your Business.

Hero image from Unsplash, used under the Unsplash License.