Shadow AI arrives through a browser tab, not a purchase order. Find all of it, with an owner attached.
It is the AI equivalent of shadow IT, with one difference that decides everything downstream. Shadow IT usually needed a purchase. Shadow AI usually needs a browser tab and a personal login. There is no invoice, no vendor record, no contract, and frequently no install.
The question a security team can actually answer about shadow AI is therefore not how much of it there is. It is which of it they can name.
Four measurements, four unrelated methodologies. Each is printed with the population it was measured in, because a percentage without its population is how the wrong number ends up on a website.
Security incidents involving shadow AI more than doubled in a year, to 43 percent from 20 percent.
Those incidents also cost more, averaging USD 5.39 million against USD 4.63 million a year earlier, and in about one in five of them the organization reported paying a regulatory fine.
IBM Cost of a Data Breach Report 2026, research conducted by Ponemon Institute, published 29 July 2026. Population: 602 organizations that suffered a breach, across 17 industries and 16 countries, breaches occurring March 2025 to February 2026. This is a share of breached organizations, not of all organizations.
67 percent of users are using non-corporate accounts on their corporate devices to access AI services.
The same report records shadow AI as the third most common non-malicious insider action in its data loss prevention dataset in 2025, a fourfold increase in percentage from the previous year, across 4,280,149 events.
Verizon 2026 Data Breach Investigations Report, published 19 May 2026. Population: data loss prevention service datasets, inside a report covering more than 31,000 incidents and more than 22,000 confirmed breaches across 145 countries. This is a share of users, not of employees and not of organizations.
47 percent say they lack visibility into the shadow AI tools employees are using today.
An unrelated survey of a different population landed on the same figure: nearly half, 47 percent, of large organizations report they do not have full visibility into employee AI tool usage. Two independent methodologies agreeing to the point is unusual for survey data.
Bitdefender 2026 Cybersecurity Assessment Report, published 29 June 2026. Population: 1,200 IT and cybersecurity professionals across 6 countries. Corroborated by the Protiviti AI Pulse Survey, 4th edition, published 6 May 2026, approximately 345 C-suite executives, board members and IT leaders.
75 percent have discovered unsanctioned AI tools currently running in their environments.
Discovery is no longer the surprising part. Three quarters of this population have already found the tools. What happens next is the unsolved half.
Cybersecurity Insiders, 2026 CISO AI Risk Report, sponsored by Saviynt, published 24 January 2026. Population: 235 CISOs, CIOs and senior security leaders at enterprises of 5,000 or more employees in the United States and United Kingdom, margin of error 6.4 percent at 95 percent confidence. Vendor sponsored survey, sponsor named.
The four disagree on magnitude because they count different units: incidents, users, professionals, and enterprises. They should not be averaged into a single number, and not one of them is a claim about AIBound.
CASB and SaaS discovery
Accounts, licenses, tenants, and administrative records
A personal ChatGPT login on a corporate device, which has none of those
Endpoint tooling
Installed executables and anomalous process behavior
A browser extension, which is neither an installed application nor anomalous
In the average company, more than 15 percent of users had unauthorized AI extensions installed on their browsers. Verizon 2026 Data Breach Investigations Report, published 19 May 2026.
Legacy data loss prevention
Patterns inside files and messages
A prompt, a multi turn conversation, or an agent tool call, which is where the data actually goes
Half of organizations, 50 percent, lack enforceable data protection policies for generative AI applications at all. Netskope Cloud and Threat Report 2026, published 5 January 2026, anonymized telemetry from millions of users worldwide, period 1 October 2024 to 31 October 2025.
None of the three is broken. Each was scoped before the artifact existed. That is why adding another rule to any of them does not close the gap. It is a discovery problem before it is an enforcement problem.
Every AI resource, from browser extensions to autonomous agents, enters a governed approval workflow automatically, with owner tracking and enforceable policy.
| Resource | Surface | Users | Status |
|---|---|---|---|
| ChatGPT (personal) | Browser | 184 | Pending Review |
| Perplexity Ext. | Browser | 231 | Pending Review |
| Cursor + MCP | Endpoint | 67 | Under Review |
| Claude Enterprise | Endpoint | 42 | Approved |
| Unknown MCP srv | Network | 3 | Blocked |
Pending Review is a resource that has been discovered and not yet triaged.
Under Review is a resource a named owner is actively assessing.
Approved is a resource cleared for use under policy.
Blocked is a resource that policy is actively preventing.
One inventory rather than five outputs: every discovered AI resource, the shadow AI findings inside it, the agents and MCP servers among them, an alert when a new resource appears, and an owner and a status on every row. Discovery runs across browser, endpoint, network, and cloud, produces per user AI risk profiles with usage context, carries an audit trail through the approval workflow, and enforces through the endpoint and MDM tools already deployed.
Shadow AI is any AI application, model, agent, browser extension, or MCP server in use inside an organization without the approval or knowledge of IT and security. It differs from earlier shadow IT in how little friction it takes to start: no purchase order, no vendor contract, often no install, frequently just a browser tab and a personal login. That is why procurement records, which surfaced the last generation of unsanctioned software, surface almost none of this one.
Because each control category is looking for the wrong artifact. SaaS and CASB discovery look for accounts, licenses and administrative records, endpoint tooling looks for installed executables, and legacy data loss prevention looks for patterns inside files and messages. Shadow AI usually presents as none of the three: a browser extension, a personal login, or a prompt typed into a tab.
A shadow AI finding is a specific AI resource observed in the environment that no approval record covers: an AI application, a model, an agent, a browser extension, or an MCP server. Each finding arrives with the surface it was seen on, browser, endpoint, network or cloud, the number of users touching it, an owner field, and a status. That is the difference between a governable inventory and a list of alerts nobody owns.
Discovery produces the list. Scoring produces the order of work. Every discovered resource enters the inventory with an owner and a status, then receives an A to F grade weighing technical severity against business context, data sensitivity, and how far the resource can reach. Without that second step, a complete inventory is several hundred findings and no priority.
Within 24 hours of connection, using an agentless and read-only deployment. The sequence matters more than the headline number: the first 24 hours produce the first complete inventory, and discovery then runs continuously rather than as a scheduled scan, so a tool installed next week appears on its own rather than waiting for the next cycle. For external context, the mean time to identify and contain a breach rose to 247 days last year, according to IBM's Cost of a Data Breach Report 2026.
This gives the level of detail I'm looking for… we don't have that at the moment.
Get a complete, defensible AI inventory across every surface, with no agents to deploy.