Shadow AI Risk Governance: Why Asset Mapping and Telemetry Matter Now
forbes.com

Shadow AI Risk Governance: Why Asset Mapping and Telemetry Matter Now

Tech News
4 min read

Published by AINave Editorial • Reviewed by Ramit

TL;DRIBM's 2026 data breach report links 43% of incidents to shadow AI, and 68% of breached firms lack AI policies. Experts say 70-75% of AI risk is usage risk, not model risk. Asset mapping and real-time telemetry are essential for governance, board reporting, and compliance with new EU AI disclosure rules.

Shadow AI, the unapproved tools and workflows your team is already running, now drives nearly half of security incidents and sets the terms for insurance coverage and regulatory compliance. The risk is not primarily in model hallucinations or bias but in how staff and systems actually use AI tools, a gap most organizations cannot see, let alone price.

The numbers that changed the conversation

IBM's Cost of a Data Breach Report 2026 found shadow AI in 43% of security incidents, roughly double the previous year, and 68% of breached companies had no AI-use policy. Days later, Article 50 of the EU AI Act became binding, requiring companies to disclose when someone interacts with an AI system. Compliance means knowing which systems are in use, and most companies do not.

Yakir Golan, CEO of risk quantification firm Kovrr, estimates that 70 to 75% of AI risk is usage risk how employees and agents interact with tools and data rather than inherent model flaws. He advises companies to manage as if this figure were 90-95%, because the top models already face heavy scrutiny while internal usage is neglected.

Why builders should pay attention to usage risk

Most enterprise AI products are wrappers around the same handful of foundation models. The real exposure sits a layer down: bad permissions, data leakage to third-party vendors, and agent access that persists long after the original user leaves. Among breached companies whose AI systems came under attack, 92% had failed to control access to those tools properly. These are access control failures, not model failures.

For teams shipping AI products or deploying internal agents, the lesson is direct. You need asset-level visibility across browsers, endpoints, network traffic, and third-party model activity before you can quantify or remediate. A company that maps only approved tools is blind to most of its attack surface.

What practical governance looks like

Effective governance starts with a complete asset inventory and real-time telemetry. Golan recommends pulling data from browsers, secure browser extensions, endpoints, identity and data governance systems, then separating approved assets from shadow ones before any risk modeling begins. One large manufacturer used this approach to support a NIS2 assessment and sequence remediation by financial weight across two quarters.

On the insurance side, ISO form CG 40 47 01 26 now provides a standard generative AI exclusion for commercial general liability policies. Carriers are starting to attach it selectively. Affirmative coverage exists through Munich Re's aiSure line and Armilla at Lloyd's, but it remains hand-built and small. Underwriters cannot price an unmapped AI estate, and Golan expects mass-market AI insurance scaling will take about two years, requiring confident visibility first.

The limits of quantification

The NSTAC, which advises the US president on communications policy, warned in 2024 that the security industry suffers from weak metrics literacy and often runs mathematical operations on subjective judgments as though they were hard data. The critique lands harder on AI risk quantification, which has far less loss history than cyber. As Golan himself concedes, quantification is the layer on top of asset mapping and usage monitoring. Without complete visibility, any board report builds confidence on a partial foundation.

FAQs

Shadow AI refers to unsanctioned AI tools and workflows that staff adopt without approval, such as pasting corporate data into a public chatbot or running an unapproved code assistant. It is a governance gap because these tools bypass security controls, access permissions, and data governance policies. IBM's 2026 report found shadow AI in 43% of security incidents, and 68% of breached companies had no AI-use policy. The risk sits primarily in data leakage, bad permissions, and third-party vendor exposure, not in model flaws.

Sources

Latest Tech News