
Shadow AI Risk Governance: Why Asset Mapping and Telemetry Matter Now
Published by AINave Editorial • Reviewed by Ramit
Shadow AI, the unapproved tools and workflows your team is already running, now drives nearly half of security incidents and sets the terms for insurance coverage and regulatory compliance. The risk is not primarily in model hallucinations or bias but in how staff and systems actually use AI tools, a gap most organizations cannot see, let alone price.
The numbers that changed the conversation
IBM's Cost of a Data Breach Report 2026 found shadow AI in 43% of security incidents, roughly double the previous year, and 68% of breached companies had no AI-use policy. Days later, Article 50 of the EU AI Act became binding, requiring companies to disclose when someone interacts with an AI system. Compliance means knowing which systems are in use, and most companies do not.
Yakir Golan, CEO of risk quantification firm Kovrr, estimates that 70 to 75% of AI risk is usage risk how employees and agents interact with tools and data rather than inherent model flaws. He advises companies to manage as if this figure were 90-95%, because the top models already face heavy scrutiny while internal usage is neglected.
Why builders should pay attention to usage risk
Most enterprise AI products are wrappers around the same handful of foundation models. The real exposure sits a layer down: bad permissions, data leakage to third-party vendors, and agent access that persists long after the original user leaves. Among breached companies whose AI systems came under attack, 92% had failed to control access to those tools properly. These are access control failures, not model failures.
For teams shipping AI products or deploying internal agents, the lesson is direct. You need asset-level visibility across browsers, endpoints, network traffic, and third-party model activity before you can quantify or remediate. A company that maps only approved tools is blind to most of its attack surface.
What practical governance looks like
Effective governance starts with a complete asset inventory and real-time telemetry. Golan recommends pulling data from browsers, secure browser extensions, endpoints, identity and data governance systems, then separating approved assets from shadow ones before any risk modeling begins. One large manufacturer used this approach to support a NIS2 assessment and sequence remediation by financial weight across two quarters.
On the insurance side, ISO form CG 40 47 01 26 now provides a standard generative AI exclusion for commercial general liability policies. Carriers are starting to attach it selectively. Affirmative coverage exists through Munich Re's aiSure line and Armilla at Lloyd's, but it remains hand-built and small. Underwriters cannot price an unmapped AI estate, and Golan expects mass-market AI insurance scaling will take about two years, requiring confident visibility first.
The limits of quantification
The NSTAC, which advises the US president on communications policy, warned in 2024 that the security industry suffers from weak metrics literacy and often runs mathematical operations on subjective judgments as though they were hard data. The critique lands harder on AI risk quantification, which has far less loss history than cyber. As Golan himself concedes, quantification is the layer on top of asset mapping and usage monitoring. Without complete visibility, any board report builds confidence on a partial foundation.
FAQs
Sources
- Companies Cannot Price The Shadow AI Risk They Cannot See
- Companies Cannot Price The Shadow AI Risk They Cannot See
- Why Kansas Small Businesses Are More Exposed to AI Risk Than...
- Agentic AI and the Looming Board-Level Security Crisis | Soussane...
- What is Shadow AI? Managing Unauthorized Tools & IT Risks
- BYOAI: Shadow AI takes over the workplace | Cybernews
- The Shadow AI Crisis — Your Employees Are Already Using AI, and You Don’t Know How (Part 2 of 3)
- Off the Radar: How Unapproved AI Is Complicating Healthcare Cyber Risk
- Managing shadow AI: a 10-point governance road map
- 'Shadow' AI agents stalking networks undetected, Okta chief warns
- Shadow AI Risks: Securing Your Startup Effectively - Amplifier One
- You Are the Shadow AI Your Security Team Is... - DEV Community
- Using DeepSeek? Here's why your privacy is at stake | Proton | Proton
- Shadow AI: How to Fix Today’s Leading Data Governance Problem
- Shadow AI: The Risk You Can’t See Coming





















