Verizon says shadow AI is exposing company IP through unsanctioned AI use
Verizon's 2026 Data Breach Investigations Report has quantified a significant security gap: 67% of professionals using AI tools at work do so through personal accounts that IT has not authorized, and 28% of data-loss-prevention violations now involve employees uploading source code into unapproved AI systems. The report defines "shadow AI" as the use of AI tools, assistants, models, browser extensions, or personal accounts without formal approval from IT, security, legal, or compliance teams. Exposed material includes source code, intellectual property, internal documents, and customer records.