Shadow AI is the AI staff use without security approval. The EU AI Act's disclosure rule took effect four days after IBM's 2026 breach report named the gap.
Shadow AI showed up in 43% of security incidents last year, roughly double the year before, and 68% of the companies that were breached had no policy governing AI use. That pair of numbers comes from IBM's Cost of a Data Breach Report 2026, published July 29 and built from 602 organizations breached between March 2025 and February 2026. Four days later, the EU AI Act's Article 50 transparency rule became binding, turning the 68% no-policy figure from a measurement problem into a disclosure liability.
Shadow AI is the term for AI tools that staff adopt on their own, outside the procurement and security review a sanctioned vendor would clear. The wire covered the doubling. The under-covered part is the layer the number points to: staff use, not the model.
Incidents involving an organization's own AI models and applications rose to 21% from 13% year over year, also from the IBM dataset. That is the layer risk committees have spent two years on: model behavior, hallucination, bias, poisoning, misalignment, plus the guardrails and red-teaming budgets aimed at the three to five large model vendors that supply most enterprise tools. The work is real. The IBM data says the breach cost is landing one layer up, in how staff actually use these tools inside the company.
Yakir Golan frames the split as roughly 70 to 75% usage risk and 25% model risk, based on his read across years of client calls rather than a measured dataset. The number he tells companies to plan against is closer to 90 to 95% usage and 5 to 10% model, because top models get heavy scrutiny while internal enterprise use is neglected. The 90/5 is a practitioner's read, not a benchmark. The claim worth testing is that the place to put guardrails has moved from the model to the workflow.
Article 50 makes the test concrete. The provision requires that a person know they are dealing with a machine, and the European Commission's guidance says the obligation is satisfiable with a short line of text on a chat window or a comparable surface. The rule carries a one-line requirement on the user side and a discovery requirement on the operator side: knowing which systems need the disclosure. The IBM 2026 cohort without an AI policy is the cohort least likely to have that inventory.
Cybersecurity Dive and Kiteworks both read the IBM data as a governance gap rather than a model-quality gap. Forkast reports the shadow-AI share roughly doubled to 43% and that AI-driven attacks added about $1 million per incident, against the IBM 2026 backdrop.
The question for the next risk-committee agenda is narrow. Which AI tools did staff adopt without procurement, and is there a written line of text on each one telling a user they are talking to a machine. If the first answer is "we don't know" and the second is "no," the disclosure clock under Article 50 has already started, and the IBM 2026 cohort is the same group the data just put on the page.