Shadow AI adds breach risk and forces companies to rethink AI governance
A new Lyro briefing argues that the real choice for employers is not whether AI is used, but whether it is governed. Drawing on 45 sources, the report links shadow AI to higher breach costs, wider data exposure and a growing case for sanctioned use in customer service.
Why it matters: - Organizations with high levels of shadow AI paid an average of $670,000 more per data breach than organizations with little or none, according to IBM's Cost of a Data Breach Report 2025. - The report frames shadow AI as a governance problem with direct financial, security and productivity consequences. - Customer-facing teams are a likely early test case because the workflow has clear metrics and documented productivity gains from AI assistance.
What happened: - Lyro published "Shadow AI. From Hidden Habit to Deliberate Strategy," a briefing that draws on 45 published sources. - The report argues that the status quo is not the absence of AI, but ungoverned AI. - Tidio is the company behind Lyro, its AI agent for customer service. - The report was released Sept. 11, 2026, in San Francisco.
The details: - A field study of 5,172 customer-support agents published in the Quarterly Journal of Economics found that access to an AI assistant raised issues resolved per hour by 15% on average. - The same study found gains of about 34% for the least-experienced, lowest-skilled workers. - MIT's 2025 NANDA study found that employees at more than 90% of firms use personal AI tools for work, while only about 40% of companies hold an official AI subscription. - Microsoft's 2024 Work Trend Index, based on 31,000 people across 31 countries, found generative-AI use among knowledge workers at 75%, with 78% of those users bringing their own tools. - Software AG's study of 6,000 knowledge workers concluded that half of all employees are shadow AI users. - Cyberhaven found that 27.4% of the corporate data employees put into AI tools by March 2024 was sensitive, up from 10.7% a year earlier. - Cyberhaven also found that the total volume of corporate data flowing into those tools rose 485% year over year. - IBM found that one in five breached organizations was compromised through shadow AI. - IBM also found that 63% of organizations either had no AI governance policy or were still developing one. - IBM said 97% of organizations suffering AI-related security incidents lacked proper AI access controls. - KPMG and the University of Melbourne found that only 40% of employees say their workplace has a policy on generative-AI use, and only 47% have received AI training. - PwC's 2025 analysis of close to a billion job postings linked AI-exposed industries to nearly four times the productivity growth and roughly three times the revenue-per-employee growth of less-exposed sectors. - Tytus Gołas, Tidio's co-founder and CEO, wrote in the preface that if employees are already using AI without approval, doing nothing keeps the risk and forfeits the upside. - Software AG found that 46% of workers would refuse to stop using personal AI tools even if their employer banned them outright. - Netskope found that when employees receive a real-time warning before sending sensitive data to an unapproved tool, they decline to proceed 73% of the time. - Netskope also observed personal-account generative-AI use fall by 12 percentage points in three months as organizations rolled out approved alternatives. - Contentsquare's analysis of 22 million customer-service conversations found human-plus-bot resolution at 57%, compared with 29% for bots alone. - Bot-only performance was weakest in refunds at 18%, technical issues at 15% and security problems at 14%. - Tidio said Lyro averages a 72% resolution rate across its clients. - The EU AI Act allows penalties of up to €35 million or 7% of global annual turnover for prohibited practices, with obligations for high-risk AI systems being phased in under the Act's implementation timetable.
Between the lines: - The report's central argument is that banning AI use is unlikely to work if employees already rely on personal tools for work. - The data suggests companies need visibility, approved tools and guardrails, not just policy memos. - The customer service examples point to a broader strategy: start with workflows where AI can help quickly, measure results and keep humans in the loop for harder cases. - The regulatory backdrop makes inaction more expensive as AI rules harden, especially for firms handling sensitive data or high-risk use cases.
What's next: - The report recommends sanctioning customer service first, then expanding use in narrow scopes with guardrails. - Tidio says the full report is available at the full report. - Media inquiries go to the newsroom. - The company is positioning Lyro as an approved alternative that can capture productivity gains while reducing shadow-AI risk.
The bottom line: - The report's message is simple: companies are already living with AI, so the real decision is whether to govern it or absorb the cost of unmanaged use.
Disclaimer: This article was produced by AGP Wire with the assistance of artificial intelligence based on original source content and has been refined to improve clarity, structure, and readability. This content is provided on an “as is” basis. While care has been taken in its preparation, it may contain inaccuracies or omissions, and readers should consult the original source and independently verify key information where appropriate. This content is for informational purposes only and does not constitute legal, financial, investment, or other professional advice.
Sign up for:
Today in Business
The daily local news briefing you can trust. Every day. Subscribe now.
Check Your Email!
We sent a one-time activation link to: .
Confirm it's you by clicking the email link.
If the email is not in your inbox, check spam or try again.
Welcome back!
is already signed up. Check your inbox for updates.