Security

Shadow AI Tripled on Corporate Devices, and Two Thirds of It Runs Through Personal Accounts

Verizon's 2026 DBIR found regular AI use on company devices jumped from 15% to 45% of employees in a year, with 67% signing in through non-corporate accounts. Source code is the most commonly uploaded asset.

September 2, 2026 · Security
An open laptop left running on a desk in an empty open-plan office, its screen turned away

Key Takeaways

  • Verizon's 2026 Data Breach Investigations Report found 45% of employees are now regular AI users on corporate devices, up from 15% the year before.
  • 67% of those users reach AI services through non-corporate accounts on corporate hardware, placing the activity outside enterprise identity and logging.
  • Shadow AI is now the third most common non-malicious insider action detected, a fourfold increase in percentage terms year over year.
  • Company source code is the most frequently uploaded data type, ahead of images, research documentation and technical specifications.

Three times as many employees are regular AI users on corporate devices as a year ago. Verizon's 2026 Data Breach Investigations Report puts the figure at 45%, up from 15%. Adoption at that rate, in a single year, on tooling that was never centrally procured, is the fastest behavioural change most enterprise security teams will see in their careers.

The number that should shape the response is the second one. 67% of those users are reaching AI services through non-corporate accounts on corporate hardware. Not through an enterprise tenant with retention controls and audit logging, but through a personal login on a company laptop. Whatever governance exists at the tenant level is simply not in the path, and the activity produces no record an enterprise can query.

The Account, Not the Application, Is the Exposure

This is the distinction most shadow AI policy gets wrong. A great deal of effort has gone into deciding which AI tools are approved, and comparatively little into whether employees are signing into the approved ones with the right identity. The Verizon data suggests the second question is where the risk actually sits. An enterprise account on a sanctioned assistant is a governable event: it is logged, retention is configurable, and the data does not train anything by default.

A personal account on the same assistant, on the same machine, is invisible. The organisation cannot tell what left, cannot produce a record of it during an investigation, and has no contractual basis for asking the provider to delete it. Two employees using identical software in identical ways can sit on completely different sides of a data protection obligation, and the only difference is which credential they used at the login screen.

Source Code Is the Leading Export

Verizon found shadow AI has become the third most common non-malicious insider action detected, a fourfold increase in percentage terms from the previous year. What moves is instructive: company source code is the single most frequently uploaded data type, ahead of images, structural data, research documentation and technical specifications. This is intellectual property exposure rather than a privacy incident, and it does not look like an incident.

The mechanics are entirely benign in intent. A developer pastes a failing function into an assistant to find the bug. An analyst drops a contract in to get a summary before a meeting. Nobody is exfiltrating anything, and nobody triggers a data loss alert designed around bulk transfers to unusual destinations, because the volume is small, the destination is a well-known website, and the action looks exactly like the hundred other useful things that employee did that day.

The scale of the underlying dataset is worth noting, because shadow AI findings are often drawn from small self-reported surveys where social desirability suppresses the numbers. Verizon's report draws on roughly 13,000 polled organisations alongside its breach corpus, and it is detecting this activity through data loss prevention telemetry rather than by asking people whether they paste confidential material into chatbots. The 45% is observed behaviour, not an admission.

Blocking Is Not Available as a Strategy

The temptation is to block. It rarely survives contact with a 45% adoption rate, because the tooling is genuinely useful and the people using it are the productive ones. Blocking also moves the activity rather than stopping it: onto a personal phone beside the corporate laptop, where there is no telemetry at all and the same source code gets photographed instead of pasted.

The more workable path is to make the sanctioned route the easy one and the personal account the friction. That means an enterprise tenant that is actually pleasant to use, single sign-on that does not add steps, and a clear, non-punitive statement about what may and may not go into a model. It also means accepting that the goal is to move 67% of usage onto a governed identity rather than to drive 45% adoption back down to 15%.

There is a device management dimension here that tends to get missed. Verizon's wider findings this year put exploited vulnerabilities at the top of the initial access table for the first time in the report's history, at 31% of breaches, up from 18%. A fleet where patch state and browser profile are centrally known is also a fleet where enterprise AI identity can be enforced. The organisations struggling most with shadow AI are usually the ones whose device estate was already only loosely managed.

Shadow AI stopped being a governance question about tools somewhere around the point it hit 45% of the workforce. It is now an identity problem wearing a productivity badge.

Share

More in Security

All Resources →