45% of employees now regularly use AI tools on work devices, triple 2025's 15%, and unapproved 'shadow AI' has become one of the fastest-growing sources of leaked company data, according to Verizon's 2026 Data Breach Investigations Report.
The surge in shadow AI is driving a sharp rise in leaked company data, and the organisations avoiding it are the ones giving staff a secure, approved alternative, rather than issuing bans.
The report confirms that people remain the weak point in most attacks. Human error or manipulation played a part in 62% of all breaches, while scams targeting people through their phones, by text message or voice call, succeeded at a rate 40% higher than traditional email phishing.
The data being pasted into unapproved tools is far from trivial. Source code was the most common type of information submitted to unauthorised AI tools, and shadow AI use is now the third most common non-malicious insider action recorded in data loss prevention (DLP) datasets, a fourfold increase on the previous year.
The picture is one of staff adopting AI far faster than their employers, feeding client details, code, and sensitive company information into consumer tools that sit entirely outside the organisation's control.
The trend is even starker in the UK. Nearly three-quarters of UK employees (71%) have used unapproved consumer AI tools at work, and just over half (51%) still use them every week, according to a Censuswide survey of more than 2,000 UK employees commissioned by Microsoft. Government data points to the same governance gap. Of the UK businesses using or adopting AI, fewer than a quarter (24%) have cyber security practices in place to manage the risks, according to the Department for Science, Innovation and Technology's latest Cyber Security Breaches Survey.
The instinctive response of banning AI tools outright tends to make the problem worse. Staff simply move to personal devices and private accounts, taking the activity even further out of sight of the IT team. The organisations getting it right are offering an approved alternative instead, such as Microsoft Copilot deployed with proper data controls, so staff keep the productivity benefit and the business keeps its data.
Commenting on the findings, Justin Barker, Head of Modern Work, Comms, and Security at Nasstar, said:
Our advice to IT leaders is to start by understanding what’s being used across your organisation. Until you do, you’re writing policy in the dark. Once you have that visibility, decisions become much easier to make.
Then give people a simple set of rules. Explain which tools they can use and what data must never be shared.
If you’re already on Microsoft 365, staff can use Copilot Chat at no extra cost. Users are covered by Microsoft’s data protections, so conversations aren’t used to train models.
If you want to go further, Microsoft Purview’s Data Security Posture Management (DSPM) can help prevent sensitive data from leaving your organisation. It does require higher-tier licensing, so it won’t be readily available in every estate, but it’s worth discussing with your IT partner.”
If you're keen to explore AI at your organisation but are worried about the security implications, our team can help. Contact us here.






