A quarter of your workforce is already pasting company data into AI tools you don't control, and the finance line for that behaviour is now measurable. IBM's 2025 Cost of a Data Breach Report gives boards something they've been missing in the Shadow AI conversation: not a scare, but a price. Breaches involving high levels of Shadow AI cost about $670K more on average — $4.63M versus $3.96M. That gap is the cost of a blind spot, and the report is unusually clear about why the blind spot exists.
For a CISO briefing a board, the useful move isn't to sound the alarm. It's to translate three of IBM's numbers into the specific control decision they imply — because the same report that quantifies the loss also names the missing safeguard.
The number that should reframe the conversation
Start with the headline gap. A $670K premium on Shadow-AI-involved breaches is not an abstraction; it's roughly the difference between a manageable incident and a material one. Pair it with a second figure: 20% of organizations in the report were breached via Shadow AI. That's one in five, and it's not a projection about the future — it's what already happened.
Boards are used to weighing likelihood against impact. Here both moved in the wrong direction at once. The likelihood is a fifth of organizations. The impact carries a six-figure premium over the average breach, which itself sits at $4.44M globally and far higher in regulated sectors — US breaches averaged $10.22M and healthcare $7.42M. Layer Shadow AI onto a healthcare or financial-services threat model and the numbers stop being someone else's problem.
What makes this different from the usual breach statistic is where the exposure originates. It doesn't come through the perimeter. It walks in through the browser, in a prompt box, from an employee trying to do their job faster.
Why the loss keeps happening: the controls aren't there
The report is blunt about the mechanism. 97% of organizations that suffered an AI-related breach lacked proper AI access controls. Not most — nearly all. That's a near-perfect correlation between "we had a breach" and "we had nothing watching the AI usage."
Go one layer deeper and it gets sharper. 63% of organizations have no AI governance policy at all, and only 17% have technical controls to redact or block sensitive data at the point of entry. Read those two together: even among the minority with a policy, most have no way to enforce it where the data actually leaves. A policy that says "don't paste client data into ChatGPT" is a sentence in a document. The 17% figure is the share of organizations that can actually act on that sentence at the moment it matters.
This is the gap most security stacks don't cover. Traditional data-loss tooling was built for files moving across networks and email — it doesn't see a paragraph typed into a web form and sent to an AI provider. The prompt box is a channel the existing controls were never designed to watch.
What a $670K premium looks like in one prompt
Make it concrete. A revenue analyst is under deadline to explain a variance to the board. She has the quarterly model open — actuals, forecast, a few customer names tied to deal sizes. She pastes the relevant tab into an AI assistant and asks it to draft the narrative. The draft is good. The work ships on time.
What also happened: customer-identifying data, financial figures, and internal deal information were submitted to a public AI tool. Once that prompt is sent, it can't be recalled. It may be retained, processed by sub-processors, or used to train the provider's model, and the pasted content becomes subject to that provider's terms of use. There was no malice, no external attacker, no alert. And nothing in the environment saw it happen — which is exactly the condition IBM's 97% describes.
Multiply that analyst by every team touching sensitive data under deadline pressure, and you have the shape of the one-in-five statistic. The behaviour is rational for the individual and invisible to the organization. That combination is what the $670K premium is really pricing.
The control decision the data points to
IBM's own framing narrows the options. The correlation isn't between breaches and having AI — it's between breaches and having no controls on how AI is used. So banning tools doesn't address the finding; people move to personal accounts and the usage simply goes dark, which makes the visibility problem worse, not better. The report's implied fix is the 17% control: the ability to redact or block sensitive data at the point of entry, before it leaves the organization's hands.
That point-of-entry framing matters because of the irreversibility. After submission there is nothing left to govern — the data is already out. The only place a control can change the outcome is before the prompt reaches the AI tool. That is also where in-the-moment education lives: a prompt that's stopped with a plain explanation of what was flagged teaches the analyst why, and turns a near-miss into a habit instead of a repeat incident.
This is the principle Sanitized AI is built on — catching sensitive data in a prompt and redacting or blocking it before it reaches the AI tool, with a policy-event record for leadership that never captures what the person actually typed. For a board, that record is also the answer to the diligence question: evidence that the organization moved from the 63% with no governance toward the 17% that can act.
So the question to bring to your next risk review isn't whether employees are using AI — assume they are. It's a sharper one: if a sensitive prompt were submitted today, would anything in your environment have caught it before it left? If the honest answer is no, you're in the 97%. If you want to see what closing that gap looks like in practice, request a demo.