AI Boss Tools | Diagnostic 09 • Back to the Hub
Most organisations have staff using AI tools nobody approved. IBM's 2025 breach study found shadow AI in one in five data breaches, adding US$670,000 to the average breach cost. Twelve questions score how exposed your organisation is, across policy, controls, staff behaviour, and detection, and show where the gaps sit.
Shadow AI means staff using AI tools for work without approval or oversight. It spreads because public tools are free and easy to reach and many organisations offer no approved option, so an employee can paste customer records into a public chatbot and leave no record that it happened. The diagnostic scores four areas: your policies, your technical controls, how staff behave in practice, and whether you could detect a problem. Banning tools tends to make it worse; the organisations that manage it give staff good approved tools, publish clear data rules, and keep visibility over usage.
Sources: IBM Cost of a Data Breach Report 2025 (shadow AI in 20 percent of breaches, up to US$670,000 added cost, 97 percent of AI-related breaches lacked access controls); IBM and Ponemon Institute (63 percent of organisations had no AI governance policy).