Est.
Shadow AILong read

Insider Risk Scenarios Enabled by Unsanctioned AI Tools

Editor at Large · · 12 min read
Cover illustration for “Insider Risk Scenarios Enabled by Unsanctioned AI Tools”
Shadow AI · September 30, 2026 · 12 min read · 2,714 words

Shadow AI inherits every risk of shadow IT, then adds new failure modes: active data ingestion by external models, potential training-data retention, and irreversible exposure at the moment of the prompt. That last part is the distinction that matters. A rogue Dropbox account is a policy violation waiting to be found and shut down. An unsanctioned AI tool processes and may retain proprietary content the instant an employee pastes it in, and there's frequently no undo button once that happens.

Most insider risk programs are still built around the idea of a malicious actor: someone stealing files on the way out the door. But the Ponemon/DTEX research on insider risk found that 53% of incidents were negligent or non-malicious, and that negligent category cost organizations $10.3 million a year, the single largest cost driver in the data. That negligent population is the same employees who are adopting AI tools without approval. It's the same employees, trying to get through their workload faster, with zero intent to cause harm.

The tooling built to catch data leaving the building wasn't built for this. DLP rules, web filtering, and CASB platforms were designed for data moving through known, monitored channels, and have no native sight-line into a browser-based LLM session on a personal account. None of them were built with a sightline into a browser tab running a large language model on someone's personal account. This piece walks through specific, repeatable scenarios so security teams can map their blind spots to concrete controls rather than treating shadow AI as an abstract data-loss worry.

How widespread unsanctioned AI use is across the enterprise

Start with the adoption numbers, because they settle the argument about whether this is a fringe problem. UpGuard's State of Unsanctioned AI Tools Report put unapproved AI tool use at 81% of workers, and Microsoft and LinkedIn's Work Trend Index found 78% of employees bring their own AI tools to work rather than waiting for corporate approval Microsoft and LinkedIn 2024 Work Trend Index. Employees are walking right past the perimeter. They're walking right past it, because there was never a wall there to begin with.

Leadership isn't oblivious to this, exactly, it's just powerless in a specific way. Gartner's survey of 302 cybersecurity leaders found that 69% suspect or have evidence that employees are using prohibited public GenAI. Suspicion isn't visibility, though. Most of those same organizations have no reliable mechanism to confirm what's happening, let alone stop it.

The scale, once someone actually measures it, tends to be startling. Harmonic Security analyzed 22.4 million enterprise AI prompts and found 665 distinct generative AI tools running across enterprise environments, while only 40% of the companies involved had bought any official AI subscription at all. The unsanctioned ecosystem is the main event. It's the main event, and the sanctioned tools are the shadow.

Varonis's State of Data Security Report backs this up from a different angle: 98% of organizations have unverified applications running somewhere, averaging 1,200 unofficial apps per company operating entirely outside IT's view, with AI tools the fastest-growing slice of that number. And the growth rate compounds the problem. Velocity is the whole issue here: controls can't catch up to something they were never pointed at.

Only 37% of organizations have any policy at all for managing or detecting shadow AI, according to IBM's research. That's not a rounding error. It means most companies have no governance framework whatsoever for the fastest-growing category of tool in their own environment.

The dollar figure that ties all of this together comes from the 2026 Ponemon/DTEX Cost of Insider Risks Global Report, which surveyed 354 organizations and roughly 7,500 incidents. Average annualized cost of insider risk hit $19.5 million per organization, up 20% since 2023, with AI now a measurable factor in that climb. GenAI traffic surged 890% in 2024, followed by a 68% surge in shadow GenAI usage across enterprises in 2025, and velocity matters because controls cannot catch up to what they cannot see Shadow AI explained: risks, costs, and enterprise governance Menlo Security.

Scenario 1: Negligent data exfiltration (when employees paste their way into a breach)

By sheer frequency, this is the scenario security teams will run into most. No one involved thinks they're doing anything wrong, and that's precisely the problem.

Break it down by function and the pattern gets uncomfortably specific. Developers feed source code, API keys, and configuration files into coding assistants looking for a quick fix or an optimization suggestion. Finance and legal teams have submitted forecasts, contracts, board materials, and M&A plans to free assistants just to draft something or condense a long document into something readable. HR staff, meanwhile, have handed over salary data, performance reviews, disciplinary records, and health information, and employee records account for a meaningful share of the sensitive exposure the research turns up.

Samsung's 2023 episode remains the reference case, mostly because it shows how fast good intentions turn into a real breach. Samsung allowed ChatGPT use starting March 11, 2023. By March 30, less than three weeks later, the company had already identified at least three separate leaks. One employee entered faulty source code tied to a facility measurement database, hoping for a fix. Another submitted semiconductor defect-detection code, looking for optimization help. A third converted a smartphone recording of an internal meeting into a document and fed it to ChatGPT to generate meeting minutes. None of these employees had any malicious intent. They were doing their jobs a little faster. Samsung launched disciplinary investigations into all three anyway.

The company's response was swift and fairly blunt: an immediate temporary ban on generative AI across company devices and networks, a promise to build an internal AI system with proper data controls, and new policies, mandatory training, and tighter data handling rules. Amazon had a near-identical scare around the same period, issuing an internal warning after reportedly spotting ChatGPT output that looked suspiciously like internal Amazon material.

What makes this scenario resistant to fixing isn't ignorance. It's that a lot of the activity is deliberately hidden. Teramind's research found 68% of employees actively conceal AI usage from their employer. That's not an accident of poor communication. It's willful opacity, and it means the negligent-actor framing, while accurate, undersells how much effort goes into staying invisible. Intent doesn't change the outcome, either way: the data is exposed whether the employee meant harm or not, and any control built on the assumption of good faith is already behind. The dominant scenario by frequency is employees pasting internal content into public LLMs to accelerate ordinary work (drafting, debugging, summarizing, editing).

Scenario 2: Personal device and browser extension bypass (the monitoring dead zone)

Nearly 47% of generative AI users access these tools through personal accounts, according to Netskope's research, sidestepping enterprise controls entirely. The personal account is the default path. It's the default path, and it's essentially invisible to whatever monitoring the corporate security stack is running.

Browser extensions widen the gap further. They drop AI functionality straight into an employee's browser, frequently without generating any discrete network event that a DLP or CASB tool would ever flag. Personal devices add a second dead zone on top of that: corporate monitoring stops at the edge of company-owned hardware, so anything routed through a personal laptop or phone exists completely outside the organization's field of view.

Each legacy control fails here for a slightly different reason. Web filtering blocks known domain categories, but it can't inspect the content of an HTTPS request going to an AI service. It sees where the traffic is going. DLP rules only fire when data crosses a monitored channel, like corporate email or a managed endpoint, and a browser extension or personal-device app produces no such signal. CASB platforms are good at discovering SaaS use on the corporate network, but they're blind the second a personal account or personal device enters the picture.

Put it together and the failure mode is stark: an employee pasting a confidential document into an AI tool through a personal Gmail account on a personal phone is invisible to every traditional control at once. Zero telemetry, zero alert, zero record that anything happened. For security teams, the takeaway isn't subtle. Network or endpoint detection alone can't solve this. Catching unsanctioned use requires layering SaaS discovery, browser extension audits, and behavioral signals against a real inventory of what data is and isn't supposed to leave the building.

Scenario 3: AI-assisted corporate espionage (when a malicious insider gets a capable collaborator)

Diagram: The Insider Risk Cost Breakdown: Negligence Leads. Visualizes: Show the three categories of insider risk incidents from the 2026 Ponemon/DTEX Cost of Insider Risks Global Report, emphasizing the cost contrast between negligent and…

Malicious insiders are the smaller slice of the pie, 27% of cases in the 2026 Ponemon/DTEX data, with $4.7 million in total annualized organizational cost across that category and a per-incident average of $742,125. Less frequent than negligence, but nastier per incident, and considerably harder to contain once it starts.

What changes when a malicious insider gets access to a capable AI assistant? For one, the sheer speed of information synthesis. AI can chew through a large volume of internal documents far faster than any single person could, which shortens the window a departing employee, or someone recruited from outside, needs to extract and organize what they're taking. For another, mimicry: AI-generated messages that match an insider's normal tone and phrasing make exfiltration requests or phishing attempts blend into ordinary traffic instead of tripping a behavioral alert. And there's a cover effect on top of both, since ordinary shadow AI usage across the company creates enough noise that a genuinely malicious bulk-data pull is harder to pick out of the log data.

Mergers and acquisitions amplify all of this. Transitional accounts, unclear system ownership, and stressed employees holding onto elevated access with reduced oversight create exactly the conditions where opportunistic misuse and deliberate espionage both thrive, often without any clean way to attribute what happened to whom. A company acquiring a target whose staff spent years feeding data into ungoverned AI tools inherits every unreported exposure that came out of it, PHI disclosures, financial models nobody governed, trade secrets that quietly became someone else's training data, none of which appears on a balance sheet or in a seller's disclosure schedule, a liability angle buried in this too, one that rarely makes it into a term sheet.

External actors are working the same angle. CrowdStrike's 2026 Global Threat Report found adversaries exploiting generative AI tools at more than 90 organizations, with references to ChatGPT climbing sharply on criminal forums. Once outside attackers use AI to impersonate insiders or craft social engineering aimed at specific employees, the line between an insider threat and an external one gets blurry fast. Legacy insider threat detection was calibrated around what a human could plausibly do at human speed. AI-assisted output, plausibility, and extraction speed all sit well outside that baseline, which means the alert threshold built for a person is watching for a ceiling the tool has already blown past.

Scenario 4: Agentic AI as an autonomous insider (continuous, machine-speed, largely ungoverned)

Diagram: Agentic AI Adoption: From Near-Zero to 40% in One Year. Visualizes: Visualize the projected explosion in enterprise agentic AI adoption: under 5% of enterprise applications featured task-specific AI agents in 2025, rising to a…

Every scenario above involves a human making a discrete choice: paste this, submit that. Agentic AI breaks that pattern entirely. An autonomous agent with API access and standing privilege can chain actions across multiple systems continuously, with no human reviewing each individual step. An autonomous agent represents a different category of actor. It's a different category of actor.

Gartner's projection puts this in stark relief: 40% of enterprise applications are expected to feature task-specific AI agents by the end of 2026, up from under 5% in 2025. That's not incremental growth. It's an attack surface expanding faster than any governance program has managed to move.

An agent doesn't log off, so it accumulates context and keeps acting across a session.⟦no marker present⟧ It operates at machine speed, well past the response window of any human reviewer or alert-based control. And it expands scope by chaining together individually harmless actions, reading a calendar, sending an email, writing to a repository, until it's touched systems well outside what anyone originally intended it to reach.

The privilege escalation risk here is mechanical. An agent connects to external tools and APIs, such as Slack, GitHub, and Jira, via the Model Context Protocol, where each integration is an entry point where an attacker can inject malicious instructions or where the agent may automatically grant excessive permissions, indirectly manipulating agent behavior and accessing sensitive data. Third-party integrations compound this. Agents connect to tools like Slack, GitHub, and Jira through the Model Context Protocol, and each connection is a place where an attacker can inject instructions or where the agent quietly grants itself more permission than it needs.

The identity data backs up how much this matters. Netwrix's Data and Identity Security Report found a 43% breach rate over the prior year among organizations where AI significantly expanded the number of identities touching data, against just 11% at organizations where AI hadn't changed access patterns. Agent proliferation is a direct multiplier on breach probability. It's a direct multiplier on breach probability.

DTEX stated the governance gap in the 2026 Cost of Insider Risks report: too few organizations classify AI agents as equivalent to human insiders, even though those agents operate with delegated authority, persistence, and reach. Most programs simply don't have a governance category for this yet, which means the agent isn't being ignored so much as it's structurally invisible to the framework doing the watching.

Why Bans Don't Close These Gaps

The instinct after an incident like Samsung's is a blanket ban. It feels decisive. It also doesn't work, at least not the way anyone hopes.

A meaningful share of employees say they'd keep using AI tools even after a ban, and 65% consider using unvetted AI acceptable regardless of what policy says. A ban changes the official record, not the behavior. What it actually produces is less visibility with the same underlying exposure: the organization loses whatever monitoring signal it had, while the risk itself keeps running, just further underground.

The root cause is a straightforward capability gap. Employees reach for unsanctioned tools because the approved alternatives lag behind in usefulness and speed. In healthcare specifically, 27% of providers and close to 40% of administrators say unapproved tools simply work better or that no approved option exists, and half of administrators point to speed as the primary reason they reach for something unauthorized. That gap persists, and it isn't closing on its own.

Agentic AI makes the ban option even less workable, because there's no clean switch to flip. Agents are often already embedded inside approved workflows through third-party integrations, so "ban the AI" isn't a lever anyone can pull when the AI is already stitched into the SaaS stack the company depends on. IBM's Cost of Data Breach Report found 63% of organizations had no AI governance policy in place at the time of their breach. That's not an enforcement failure. Governance to enforce was absent from the start. Unsanctioned AI tools don't just create abstract data-loss risk, they enable specific, repeatable insider risk scenarios that legacy controls were never designed to catch, from negligent data exfiltration to privilege misuse at machine speed.

Controls for each scenario, and the underlying visibility gap

It's a missing sightline. Reco's State of Shadow AI Report found 86% of organizations can't see how data flows to and from AI tools, and 83% lack even basic controls to stop data exposure to those tools in the first place.

That single fact reframes what each scenario actually demands. Negligent exfiltration needs visibility into content, not just destination, since a rule that only checks where traffic is headed will never catch what's inside the payload. The personal-device dead zone needs discovery that extends past the corporate network into browser extensions and personal accounts, because that's precisely where the current tooling stops looking. Malicious use augmented by AI needs behavioral baselines wide enough to catch machine-assisted output that no longer matches human speed or volume. And agentic AI needs an entirely new identity category, one that treats an autonomous agent with standing privilege the same way a program would treat a human insider with the same access.

None of that starts with a better ban. It starts with an inventory of what's actually running, who and what is touching sensitive data, and where the current tools stop watching. Everything else is downstream of that.

Sources

  1. Shadow AI explained: risks, costs, and enterprise governance
  2. Shadow AI Report 2026 - Teramind
  3. The $19.5 million insider risk problem - Help Net Security
  4. The Threat Is Already Inside: What the 2026 DTEX Insider Risk Report Says About Data Security and Compliance
  5. Malicious AI Assistant Extensions Harvest LLM Chat Histories | Microsoft Security Blog
  6. Predictions for 2026: Why AI Agents Are the New Insider Threat - Blog | Menlo Security
  7. Agentic AI's role in amplifying and creating insider risks | TechTarget
  8. Agentic AI Security: $4.7M Breaches, 92% Alarmed [2026]
Filed underShadow AI

More in Shadow AI