Blocking AI applications does not stop shadow AI. IBM's 2026 Cost of a Data Breach research found shadow AI involved in 43% of security incidents, more than double the 20% reported a year earlier, during the same period in which Netskope found that 90% of organizations were already blocking at least one generative AI app. The two numbers rose together. That is not a coincidence. It is the predictable result of treating a workflow problem as a firewall problem.
Security leaders have spent two years building blocklists, and employees have spent the same two years walking around them. UpGuard's research puts it bluntly. Eight in ten employees use unauthorized AI tools, 68% of security leaders admit to doing the same, and 41% of employees who encounter a blocked AI app simply find another way in. The question for 2027 planning is not which apps to block next. It is what you do once you accept that sensitive data is already moving through AI tools you never approved.
For two years, shadow AI statistics were easy to dismiss as survey noise. Different vendors asked different questions and got different numbers. The 2026 data ended that ambiguity because the trend lines all point the same direction, and because IBM attached hard costs to them.
Start with prevalence. The Netskope Cloud and Threat Report 2026 found that 47% of generative AI users at work still use personal AI apps, that prompts sent per organization rose sixfold in a year, and that the average organization now records 223 generative AI data policy violations per month, double the prior year. LayerX's 2025 browser telemetry found 77% of employees paste data into generative AI tools, and 82% of that pasting comes from unmanaged personal accounts.
Then attach the cost. IBM's Cost of a Data Breach Report 2025 found 1 in 5 organizations suffered a breach attributable to shadow AI, and organizations with high levels of shadow AI paid an average of $670,000 more per breach. The 2026 edition found shadow AI involved in 43% of security incidents and reported that AI-enabled breaches now average $6 million against a $4.99 million global mean. Kiteworks' analysis of that report makes the underlying point well. AI governance failure, not AI itself, is driving breach costs.
One more pair of numbers deserves attention. IBM found that incidents involving shadow AI compromised customer personally identifiable information 65% of the time, against a 53% global average. Shadow AI does not leak random data. It leaks the data your employees work with all day, which is precisely the data your regulators, customers, and competitors care about.
Blocking fails for a reason that has nothing to do with security engineering and everything to do with incentives. Employees use unapproved AI tools because those tools make them measurably faster at their jobs. A control that removes the productivity without replacing it creates a motivated adversary out of your own workforce.
The evidence is consistent across independent studies. UpGuard found 41% of employees work around blocked AI apps. Software AG found 46% of knowledge workers would keep using personal AI tools even under an outright ban. KPMG and the University of Melbourne found 57% of employees hide their AI use and present AI-generated work as their own. When half your workforce is willing to defy policy and most of them are willing to conceal it, a blocklist is not a control. It is a visibility tax. You pay it by losing the telemetry you would have had if the usage were sanctioned and observed.
There is also a seniority problem that makes prohibition politically unenforceable. Kiteworks' research found that senior executives are among the heaviest users of unapproved AI tools, which means the people who would approve the ban are disproportionately the people violating it. We made a similar observation at Bonfy when we looked at where shadow AI hides inside the enterprise. The usage is not concentrated among junior staff cutting corners. It spreads wherever the pressure to produce exceeds the patience for procurement.
None of this means blocking has no role. Blocking known-malicious tools and enforcing enterprise tenants over personal accounts are both sensible. The failure is treating the blocklist as the strategy rather than as one minor tactic inside a governance model.
The original shadow AI threat model was an employee pasting a customer record into a public chatbot. That model is already outdated. The 2026 risk increasingly involves AI agents and assistants operating with delegated credentials, retrieving data from enterprise stores like SharePoint and Google Drive, and moving content between systems without a human reviewing each step.
This matters for shadow AI specifically because the agent inherits the governance posture of whoever deployed it. An unapproved agent wired to a sanctioned data store is shadow AI with a service account. Traditional perimeter tools were not built to see it. Network-level DLP sees an encrypted session to an approved cloud service. Identity systems see a valid credential. Nobody sees what content the agent retrieved, whether that content was appropriate to its task, or where it went next. We wrote about the organizational version of this failure in Naming an AI Owner Is Not the Same as Governing AI Data, and about the behavioral version in Nobody Told It To. It Did It Anyway.
Most tools ask what an agent is configured to do. Bonfy asks what data is actually flowing through it. That distinction is the whole game for shadow AI, because shadow usage is by definition usage that nobody configured, reviewed, or approved. A control that depends on knowing the tool in advance cannot govern a tool it has never heard of. A control that inspects the content as it moves can.
If blocking is the wrong primary control, what is the right one? The answer the data points to has three parts, and all three operate at the content layer rather than the application layer.
First, inspect the content, not the destination. The meaningful question is never "is this app on the list" but "is this specific content appropriate to leave this boundary, in this context, sent by this person or this agent." That requires classification that understands entities and context rather than regex patterns. Netskope's finding that source code accounts for 42% of generative AI policy violations illustrates why. Source code does not match a credit card pattern. Catching it requires understanding what it is. We described the architectural shift this requires in From Architectural Break to Practical Reality, and why entity awareness has become the CISO's working advantage. Legacy pattern-matching DLP, as we argued in Legacy DLP Falls Short, produces exactly the false-positive noise that causes security teams to loosen policies until they catch nothing.
Second, give employees a governed path that beats the workaround. The organizations making progress are not the ones with the longest blocklists. They are the ones that stood up sanctioned AI tooling with enterprise data protections, then made it better than the personal alternative. Kiteworks has outlined this playbook in how to respond to shadow AI without banning everything and in its framework for content-layer controls that enable secure innovation. The principle is the same one that ended shadow IT a decade ago. Nobody runs a rogue file server anymore because the sanctioned option became the easier option.
Third, extend the same enforcement to AI agents that applies to humans. Agents and people must sit under one policy model, because data does not distinguish between a human pasting it and an agent retrieving it. The combined Bonfy and Kiteworks architecture exists for exactly this reason. Bonfy provides inline, context-aware classification and enforcement on content in motion, including what AI clients retrieve from enterprise data stores mid-task. Kiteworks provides the control plane for governing data access, use, and exchange across channels, for humans and AI agents alike, with the audit trail regulators expect. One policy model, applied to the data itself, wherever it moves and whoever or whatever moves it.
The argument for acting in 2026 rather than 2027 is no longer abstract. IBM priced it. A breach involving high levels of shadow AI costs $670,000 more than one without. AI-enabled breaches average $6 million. And the governance gap is not closing on its own. IBM found more than two-thirds of breached organizations lacked governance processes to limit shadow AI, and Netskope found half of all organizations still lack enforceable data protection policies for generative AI apps.
Gartner's projection is that by 2030 more than 40% of enterprises will have experienced security or compliance incidents tied to unauthorized AI. The trend data suggests that estimate is conservative. The organizations that will be fine in 2030 are the ones that stopped asking "how do we keep AI out" and started asking "how do we see and govern what our data does when AI touches it." The second question has an answer. The first one never did.
Shadow AI is the use of AI tools, services, or agents inside an organization without the approval, oversight, or visibility of IT and security teams. It covers everything from an employee using a personal ChatGPT account for work tasks to an unapproved AI agent retrieving files from a corporate data store with delegated credentials. Kiteworks maintains a useful overview of how shadow AI turns employees into unintentional data leaks.
Per IBM's 2026 Cost of a Data Breach research, shadow AI was involved in 43% of security incidents, up from 20% a year earlier. IBM's 2025 edition found 1 in 5 organizations had suffered a breach attributable to shadow AI, with high shadow AI levels adding an average of $670,000 to breach costs.
Because employees route around blocks faster than security teams can extend them. UpGuard found 41% of employees work around blocked AI apps, and Software AG found 46% would keep using personal AI tools even if banned. Blocking also destroys visibility, since usage that would have been observable through a sanctioned tool moves to personal devices and personal accounts where no enterprise control can see it.
Bonfy operates as the inline inspection and enforcement layer. It classifies content contextually as it moves through email, Slack, Microsoft 365, and AI tools, including what AI agents retrieve from enterprise data stores mid-task, and remediates risky flows with low false positives. Kiteworks operates as the control plane for secure data exchange, governing who and what can access, use, and transmit sensitive content, and producing the unified audit evidence compliance teams need. Together they apply one policy model to data in motion, at rest, and in use, for humans and AI agents alike. Our post on rebuilding the judgment layer AI agents never inherited explains the Bonfy half of that architecture in more depth.
Neither replaces the other, because they solve adjacent problems. An organization that only governs its exchange channels still needs runtime inspection of what content AI tools and agents handle. An organization that only inspects AI flows still needs governed, auditable channels for moving sensitive data with partners, customers, and regulators. Most organizations start with the problem that is burning hottest, then extend to the unified model.
Measure before you mandate. Establish visibility into which AI tools are in use, what categories of content are flowing into them, and which flows involve regulated data or intellectual property. Then stand up a governed alternative before tightening enforcement, so the policy has somewhere to point. Verizon's DBIR data, summarized in Kiteworks' analysis of shadow AI as a top insider threat, is a solid resource for building the internal business case.
The uncomfortable truth in the 2026 data is that shadow AI is not coming. It is installed, in use, and moving your most sensitive content right now. Bonfy Adaptive Content Security shows you what that content is and enforces policy on it in real time, without the false-positive noise that makes legacy DLP unusable. Schedule a demo to see contextual data enforcement against your own traffic, or start with how Bonfy addresses Shadow AI.
Gidi Cohen, VP Product, Kiteworks
Gidi Cohen is the co-founder of Bonfy.AI, now part of Kiteworks, where he leads product for AI-native content security. He has spent two decades building security analytics and risk management platforms, including as founder of Skybox Security.