Shadow AI is the leak your CASB will never see
Let me tell you how this usually goes.
A bank CISO blocks ChatGPT at the proxy. Ticks it off in the quarterly review. The board asks "are we safe on AI?" and the answer is "we have blocked the public tools." Everyone nods. The review moves on.
Then a relationship manager pastes a customer's KYC details into a free AI tool on his personal laptop to draft an email. A credit analyst uploads a loan file to summarise it. A developer feeds customer names through a coding assistant to generate test data. None of that goes through your proxy. None of it touches your CASB. All of it is a data breach waiting for the Data Protection Board's definition to catch up to it.
That is shadow AI. It is not the tool. It is the habit.
What shadow AI actually is
Shadow AI is the use of AI tools outside anything IT has sanctioned - free consumer apps, personal accounts, browser extensions, mobile apps. It is the same shape as shadow IT, with one difference that matters: shadow IT left a trail. A SaaS subscription, a login, an API key you could find and shut down. Shadow AI leaves almost nothing. There is no server to discover, no vendor to audit. There is a person, a browser, and a text box.
The numbers, from 2026
One in four malicious breaches last year were AI-enabled - up 56% in a single year - and those breaches cost an average of $6 million, about a million more than the global average. More than 20% of organisations reported a breach that targeted their AI models or applications, and the most common causes were compromised APIs, applications or plug-ins, and cloud misconfigurations around AI workloads. Financial services breaches cost an average of $6.3 million (IBM 2026 Cost of a Data Breach Report, July 2026).
Harmonic Security's 2026 AI Usage Index analysed 1.9 million minutes of classified AI sessions and found that 64.5% of the activity on personal AI accounts is business work (Harmonic Security). Read that again. The sanctioned tools exist, the employees know about them, and the majority of what they do on their own ChatGPT, Gemini or Claude logins is your company's work.
Netskope's 2026 Cloud and Threat Report counted an average of 223 AI data-policy violations per enterprise, per month (Netskope). Not incidents a year. Per month. In one organisation. Before anyone notices.
For the baseline that got us here: LayerX found in 2025 that 77% of employees paste data into GenAI tools, and 82% of those pastes happen from personal, unmanaged accounts. Forty percent of the files uploaded to GenAI tools contained PII or PCI data (LayerX). That is the previous year's measurement, and nothing in the 2026 numbers suggests the line has bent.
Why your stack cannot see it
This is not a budget problem. You already own the tools. They are aimed at the wrong thing.
- Your proxy sees domains, not paste buffers. When data moves as typed text into a TLS session, there is no file, no attachment, no MIME type to classify.
- Your CASB sees managed apps on managed browsers. A personal account in a personal browser, on a home network or mobile data, is not in scope.
- Your DLP matches patterns in stored or transmitted files. A prompt is ephemeral - it exists for a second, in memory, inside a third-party session you cannot inspect.
- Your SIEM correlates what your tools feed it. If nothing flags, there is nothing to correlate.
And the uncomfortable part: the employee is not malicious. They are trying to work faster. The leak is not an attack. It is a productivity tool pointed at your customer data.
The India part
For an Indian CISO this is no longer academic. The DPDP Act makes you responsible for the personal data your organisation holds, and the penalties are fixed sums, not turnover percentages: up to ₹250 crore for failing to implement reasonable safeguards, up to ₹200 crore for failing to notify a breach. The Data Protection Board is operational, and enforcement arrives before most firms are ready.
The RBI has told regulated entities the same thing in different words: know your AI, log it, monitor it in real time. You cannot monitor what you cannot see, and shadow AI is precisely the part you cannot see.
What we keep finding
The pattern in our own assessments is the same failure moved around the organisation: the control a buyer asked for is present and answering, and the data still moves. On one published engagement, a platform with active GRC tooling, enterprise contracts and a working compliance motion still let a single authenticated request pull 95 customer reports - 3.49 MB of cross-tenant data - because the AI-facing endpoint never checked whether the caller owned the record. The compliance program answered the questionnaire. It did not stop the exfiltration.
Shadow AI is that same failure at the employee end. The controls you can name - proxy, CASB, DLP - are all real, and none of them is watching the channel the data actually uses.
What actually works
Banning does not work. Every organisation that has tried a blanket block has watched usage go underground - to phones, to personal laptops, to tools whose names the proxy does not categorise yet. You do not want your employees to stop using AI. You want the data to stay yours.
Three moves, in order:
- Find it first. You cannot govern what you have not inventoried. There is a 7-day discovery process that uses logs you already have - proxy, DNS, IdP sign-ins, expense and CASB telemetry - to map unsanctioned AI without buying anything new.
- Give people a sanctioned path. A fast, approved AI tool with a clear "what you can and cannot paste" rule beats a block, because employees follow the path of least resistance. Make that path the safe one.
- Enforce at the point of use. Put the policy where the leak happens - at the prompt, at the paste, at the session - not four systems downstream in a SIEM correlation that fires three days after the data is gone.
The uncomfortable truth
Shadow AI is the first data-loss channel in your career that you can be fined for before you can see it. The DPDP Act does not care that the leak went through a personal account on a personal phone. It cares that the data left your control and nobody told the Board.
You cannot fix it with the tools you already have, aimed the way they are aimed today. You can fix it by finding the AI first, giving people a safe route, and enforcing at the point where the data actually leaves.