Shadow AI Is Not a 670,000 Dollar Line Item

IBM’s 2025 breach benchmark is useful, but not because it hands security leaders a neat shadow AI surcharge. The more actionable reading is that unmanaged AI tools reduce Resistance Strength across an expanding asset class before the loss event ever occurs.

Most risk registers get shadow AI wrong by treating it as a named scenario instead of a control-state problem. They add “AI data leakage” or “AI-enabled phishing” as a row, score it high, attach a mitigation owner, and move on. That feels current, but it is qualitative concern with newer vocabulary, not quantitative risk management.

The IBM Cost of a Data Breach Report 2025, published by IBM Security with the Ponemon Institute under the subtitle “The AI Oversight Gap,” offers a better frame. The finding most readers will remember is the shadow AI breach cost premium of about 670,000 dollars over baseline. That number is attention-grabbing, and it is the least useful way to hold the finding in a risk model. It is an average increment, conditioned on a breach that already involved shadow AI, across a small subsample. It is not an annualized expected loss, it is not a universal uplift to apply to every AI scenario, and it does not replace estimating frequency, vulnerability, and loss magnitude. In quantitative risk terms the better interpretation is simpler: unmanaged AI tools reduce Resistance Strength across a fast-growing asset class.

The benchmark is pointing at coverage

IBM’s 2025 study covered 600 organizations with incidents between March 2024 and February 2025. It reported a global average breach cost of 4.44 million dollars, down 9 percent year over year and the first decline in five years, with a US average of 10.22 million dollars, a record high. Those are useful anchors, but they are per-incident cost figures. They describe single-loss magnitude, not annualized exposure, and IBM’s own quantitative-risk mapping notes that average costs are sensitive to a small number of high-cost outliers, so a median or percentile range is the better input for Loss Magnitude calibration.

The AI findings are more operationally interesting. IBM reported that 63 percent of organizations lacked AI governance policies, and that 97 percent of AI-related breaches involved organizations that lacked proper AI access controls. About 13 percent of organizations in the sample had an AI-related breach. Separately, 16 percent of breaches, roughly one in six, involved attackers using AI, with AI-generated phishing accounting for 37 percent of that attacker AI use.

The weak response is to create an “AI breach” scenario and add 670,000 dollars to the loss estimate. That mistakes a benchmark association for a calibrated exposure model. The governance and access-control figures point to coverage failure: the control environment around AI adoption is often incomplete, and AI-related breaches overwhelmingly appear where access control was not properly established. That is a Resistance Strength question. Which AI tools exist? Which identities can use them? What data can they reach? Which have passed access review, and which inherit permissions through OAuth grants, browser extensions, service accounts, or sanctioned SaaS features? The unit of analysis is not the incident surcharge. It is the fraction of the AI asset class operating below the organization’s intended control standard.

The 2026 tooling view makes the gap harder to ignore

Reco research reported by Infosecurity Magazine on 26 August 2026 found that four in five AI tools in enterprises operate with no IT oversight, alongside a surge in vulnerability disclosures for AI tools. IBM’s 63 percent governance-policy gap was visible from the breach-study side. Reco’s finding shows the same problem from the environment side a year later. These are not identical datasets and should not be forced into one false-precision estimate, but directionally they describe the same failure mode: AI adoption is outrunning the governance mechanisms that define ownership, access, review, and accountability.

The vulnerability-disclosure surge changes the quantitative risk reading. If unmanaged AI tools are a Resistance Strength reduction, rising disclosures indicate Threat Capability increasing against an asset class whose Resistance Strength was never reliably established. That is the load-bearing development. Without it, shadow AI is an immature governance issue. With it, it becomes a measurable mismatch between expanding attacker capability and poorly measured control coverage. The 670,000 dollar figure is downstream of that mismatch: by the time it appears in the loss narrative, the breach has already involved shadow AI. The decision point is earlier: what proportion of AI tools in use are known, owned, reviewed, access-controlled, monitored, and removable?

A better quantitative treatment

A useful model defines the AI asset class broadly enough to match real usage: sanctioned platforms, embedded copilots, browser-based tools, automation agents, plugins, connectors, and AI features inside ordinary business applications. The inventory will not be perfect at first, and that uncertainty belongs inside the model rather than outside it.

The practical substitution is this. Do not add 670,000 dollars to the AI scenario. Estimate what fraction of AI tools in use have passed access review, treat the uncovered fraction as a Resistance Strength reduction on that asset class, and carry it as a distribution. That distribution can be shaped by evidence the organization can actually collect. Security and IT provide identity-provider logs, SaaS discovery, endpoint telemetry, egress data, and procurement records. Data owners identify which repositories and workflows the tools can reach. Tool sponsors explain business use and operational dependency. An outside analyst scopes the AI asset class into the quantitative risk model while the organization’s risk and control owners supply the inventory evidence and the coverage ratio.

This collaboration matters because AI risk is easy to overstate in generic terms and understate in specific terms. A generic “shadow AI” label sounds severe while remaining unmeasurable. A coverage ratio is less dramatic but more decision-useful. The same logic separates defensive AI from unmanaged AI. IBM reported that organizations using AI and automation extensively in defense saw about 1.9 million dollars lower breach cost and 80 fewer days. That does not mean AI reduces cost in general. It means governed, defensive automation can change detection, response, and containment, while unmanaged AI tools do the opposite by expanding access paths and weakening control visibility.

What to put in the risk register

A better entry would not read “shadow AI increases breach cost by 670,000 dollars.” It would read closer to “unreviewed AI tools and agents reduce Resistance Strength for data-access and workflow-execution assets, increasing vulnerability where tool identity, access scope, logging, and ownership are unknown.” That wording forces the right evidence request: inventory, access-review coverage, data reach, workflow privileges, monitoring status, and exception ownership. It also avoids pretending that one average breach-cost increment is a calibrated loss estimate.

IBM’s 2025 report gives the context: the AI oversight gap is already present in breach outcomes. Reco’s 2026 research shows why it is becoming more urgent, with most enterprise AI tools apparently operating outside IT oversight while vulnerability disclosures accelerate. The conclusion for quantitative cyber risk is not that every AI scenario needs a fixed surcharge. It is that AI governance coverage has become a measurable control variable. Treat the unknown AI estate as a Resistance Strength deficit, carry the uncertainty explicitly, and calibrate Loss Magnitude with distributions rather than averages. That is how the discussion moves from “shadow AI is risky” to “this is how much unmanaged exposure we are carrying, and this is the control coverage needed to reduce it.”