Highlighted
5
Min Read
May 20, 2026

AI Series - Part 1: The Calm Before the Storm: AI Adoption, Shadow AI, and the Underestimated Data Breach Risk

 Jurgen Otten
Jurgen Otten
GRC Consultant
AI Series - Part 1: The Calm Before the Storm: AI Adoption, Shadow AI, and the Underestimated Data Breach Risk

AI is rapidly becoming a critical component of business operations. At the same time, recent data breach analyses show that security and governance are struggling to keep pace with this development.

In a three-part series based on the IBM/Ponemon Cost of a Data Breach Report 2025 Jurgen Otten discusses:


– the risks of rapid AI adoption and shadow AI;

– the dual nature of AI as both a threat and a defense mechanism; and

– why investing in IAM, SOC, and GRC demonstrably pays off.

The insights from the 2025 edition describe trends that are continuing to develop and are likely to be quantitatively confirmed in the 2026 edition.

The 2026 edition of the IBM/Ponemon Cost of a Data Breach Report is expected sometime this summer.

The risks of rapid AI adoption and shadow AI

The adoption of AI within organizations is progressing faster than almost any previous technology. While AI was initially primarily seen as a tool for productivity and innovation, it is now undeniably moving towards the core of business operations. AI is becoming a critical business process, or increasingly an integral and indispensable part of it.

Precisely this fact makes the findings from the IBM/Ponemon Cost of a Data Breach Report 2025 strategically relevant.

The report shows that the number of data breaches directly involving AI systems is still relatively limited. While this may seem reassuring, it should not be misinterpreted. The IBM and Ponemon report is an early warning sign: a snapshot taken just before an anticipated acceleration in risk and impact.

This acceleration is driven by two interconnected developments. Firstly, the high adoption rate of AI, often spurred by competitive pressure and innovation ambitions. Secondly, the widespread emergence of shadow AI, which is a direct consequence of lagging security and governance. Shadow AI refers to AI applications introduced and used outside formal IT, security, and governance structures. Together, these trends create a situation where the current low number of AI incidents says little about the medium-term risks, especially since the potential impact of these incidents is demonstrably greater.

The figures from the report clearly show that when AI or shadow AI *is* involved in a data breach, the impact is structurally greater than with traditional incidents. These breaches disproportionately often result in the exfiltration of customer data. Shadow AI frequently acts as a gateway to multiple IT environments simultaneously — public cloud, private cloud & on-prem — causing the attack surface to grow more rapidly and become less manageable.

Another significant signal highlighted in the report concerns the structural lack of governance mechanisms around AI. Not only do most affected organizations lack adequate access controls on AI systems, but the absence of formal policies and clear review and approval processes also proves to be an aggravating factor for organizations hit by a data breach.

It is precisely this gap that takes its toll during incidents. Missing processes for reviewing and approving AI applications mean that vulnerable AI systems are not identified – or not in a timely manner – that stakeholder considerations and risk analyses are not documented, and that clear "ownership" is not assigned, which particularly hinders organizations when a data breach occurs. The consequence is not only a higher chance of incidents but, more importantly, a greater impact when things go wrong: more and costlier data exposed, longer detection and containment times, and higher recovery and compliance costs.

The value of the IBM/Ponemon report lies precisely in this. It doesn't describe a crisis that has already occurred, but rather marks the moment just before the storm. The upcoming 2026 edition — expected in the summer of this year — is anticipated to show the extent to which these trends have continued. Everything indicates that the risks are deepening, not diminishing.

For executives, CISOs, and those responsible for compliance and privacy, a clear choice lies ahead. Those who wait until AI incidents become commonplace will face data breaches where the financial, operational, and reputational damage is significantly greater than has been the case so far with traditional incidents and data breaches not involving AI.

 

Conversely, those who now invest in mature GRC structures, AI governance, and security will leverage this period of relative calm to prepare for and more efficiently address future incidents and data breaches involving AI or shadow AI.

 

Navaio would be happy to discuss with you your organization's current position, what risks are realistic, and where targeted efforts can yield the most value.

Also read the other two parts of this triptych:

Part 2: The Devil's Dilemma: Why AI Increases Data Breach Risk AND Limits Damage. [link]

Part 3: From Risk to Return: Gaining Control over AI and Shadow AI with Demonstrable ROI. [link]

Stel ons jouw vraag!
Thank you! You have been subscribed.
Oops! Something went wrong while submitting the form.
Download E-Book Unravelling UGC: A Comprehensive Exploration