A five day campaign from Exec x AI. 7 to 11 September 2026.
Say No to Shadow AI
Five confessions from people who were only trying to get the job done.
Day 1But Chat Me Tee told me to do it!- Day 2
Tuesday
Unlocks Tuesday 09:00 Gulf Standard Time
- Day 3
Wednesday
Unlocks Wednesday 09:00 Gulf Standard Time
- Day 4
Thursday
Unlocks Thursday 09:00 Gulf Standard Time
- Day 5
Friday
Unlocks Friday 09:00 Gulf Standard Time
The problem is not your people
At Exec x AI we are focussing on the dangers of shadow AI and what it costs companies in fixes, fines and repairs to their IT systems.
The weakest link is the employee. Not through malice. Employees try to do the right thing and end up using shadow AI because their employer has not sanctioned a safer alternative.
The result?
- Data breach
- Loss of confidentiality
- Trade secret exposure
- Privacy breach
- Regulatory penalties
- Customer claims
- Privilege and confidentiality waiver
- Incorrect legal advice
- Litigation exposure
- IP leakage
- Vulnerable code
- Malicious dependencies
- Security compromise
- Unauthorised actions
- Mass data access and exfiltration
- Account compromise
- Materially wrong decisions
- Financial misstatement
- Market and regulatory exposure
- Discrimination claims
- Employment litigation
- Regulatory breach
- Loss of IP advantage
- Patent and trade secret complications
- Bad contracts
- Incorrect reports
- Erroneous decisions
- Operational failures
- Supply chain compromise
- Credential theft
- Data exfiltration
The ban that did not work
Somewhere in your organisation this morning, someone competent pasted something confidential into a chat window.
They were not being reckless. They were being quick.
The deadline was real. The approved tool was not. So they used what was already on their phone. It worked. They will do it again tomorrow.
That is shadow AI. It is rarely sabotage. It is usually initiative.
Nobody in your company set out to leak anything.
The number your CFO will recognise
IBM put a price on it. In the 2025 Cost of a Data Breach report, breaches involving shadow AI carried an extra USD 670,000 against the global average. The global average itself was USD 4.44 million, down 9 percent on the previous year.
Sixty three percent of surveyed organisations reported no AI governance policies in place. Of those that suffered an AI related security incident, 97 percent said they lacked proper AI access controls.
Freshworks surveyed 1,000 IT decision makers at United States mid market companies and published in April 2026. Eighty six percent reported at least one negative incident tied to unapproved AI in the previous year. Twenty three percent reported more than three.
Then the awkward finding. Seventy nine percent of those same leaders said the employees using unapproved tools are more productive. Thirty five percent called the gains substantial.
Shadow AI is not a technology failure. It is a procurement failure.
What the damage actually looks like
The harm rarely arrives labelled as an AI incident. It arrives as something else.
Legal finds out when privilege is contested. Finance finds out when a figure is restated. Engineering finds out when a dependency nobody approved starts calling home. HR finds out when a rejected candidate asks how the decision was reached, and nobody can answer.
By then the tool has been in use for a long time. Reco's usage research puts the average life of an unsanctioned AI application inside an organisation at more than 400 days.
Shadow AI added USD 670,000 to the average cost of a breach.
Verified against the publisher's own page
Shadow AI added an extra USD 670,000 to the global average breach cost.
The global average cost of a data breach was USD 4.44 million, down 9 percent on the previous year.
Sixty three percent reported no AI governance policies in place.
Of breached organisations that experienced an AI related security incident, 97 percent said they lacked proper AI access controls.
Eighty six percent of IT leaders reported at least one negative incident tied to unapproved AI in the past year. Twenty three percent reported more than three.
Seventy nine percent said employees using unapproved tools are more productive, including 35 percent who described the gains as substantial.
Freshworks surveyed United States mid market IT decision makers. Treat the figures as indicative for EMEA and APAC, not as measured there.
Vendor research, published figures
Unsanctioned AI applications persist inside organisations for more than 400 days on average.
Companies with 11 to 50 employees averaged 269 shadow AI tools per 1,000 employees.
Reported by the source named, not independently verified
These accounts were supplied by the campaign owner and were assembled in an AI chat conversation. A conversation is a route to a source, not a source.
Each underlying publication is a vendor marketing article carrying an anonymous executive account. Searches on 6 September 2026 did not independently locate the specific articles or corroborate the accounts.
Reported by the source named, not independently verified
A chief compliance officer at a mid sized Saudi financial institution reported that a company wide ban on a public AI chatbot had not stopped the credit risk team using personal accounts, and that client financial data had reached the chatbot vendor's systems.
Reported by the source named, not independently verified
A head of security at a mid market company reported that, before any AI feature existed in the product, customer information had already been placed into several AI tools adopted independently by employees.
"customer data sitting in several AI tools"
Reported by the source named, not independently verified
A security review described a CISO who estimated three or four unapproved AI tools in the organisation. The investigation found nineteen, fourteen of which had been in active use for more than six months.
"The actual number was nineteen."
Reported by the source named, not independently verified
A former biotechnology executive told Business Insider that he had knowingly worked around his employer's AI restrictions, judging the risk of falling behind a competitor to outweigh the risk of data leaving the company.
"the chance of you being eclipsed by a Chinese peer"
Five confessions
This week we publish one a day. Every line is invented. None of them will be unfamiliar.
Select a card to see why that sentence should worry the person who owns the risk, and what to do about it before Friday.
You cannot ban your way out of a productivity gap.
What to do about it
Start with discovery. Find what is already in use through network and SaaS telemetry, expense claims and browser extension inventories. An amnesty week will surface more than any scan.
Then classify. Decide which data classes may never leave the organisation, and write that down in language a non specialist can apply without ringing the legal team.
Then sanction. Give people a licensed alternative for the tasks they are actually doing. If the approved route is slower than the unapproved one, nothing has been fixed.
Then control. Scope tokens, enforce least privilege, and put an approval gate in front of any connection between two systems.
Then evidence. Log prompts, outputs and approvals so a decision can be reconstructed months later.
Then train on the specific failure rather than on AI in general.
The tool your staff chose is now your data processor.
Speak to an Exec x AI consultant about what is already running inside your organisation.
One page. Run it yourself before you speak to anyone.
Shadow AI exposure checklist
We use your details to send you the exposure checklist and to answer any question you raise about it.