GROW YOUR STARTUP IN INDIA
Image generated by The Tech Panda using Nano Banana 5

SHARE

facebook icon facebook icon

The major threat of AI security within a company may not even be the most sophisticated cyberattack, but an employee putting confidential data into an AI tool that the IT department does not know exists.

The purpose is not about getting rid of AI from the workplace, but rather about eliminating the hidden AI technology.

The phrase “shadow AI” describes the use of AI applications, assistants, extensions, or agents that are not approved by IT or have not gone through a proper risk assessment. While the usual shadow IT involves applications that do not use business information directly, AI tools can process data and come up with outputs making it more difficult for companies to keep track of sensitive data leaks.

The statistics show the rapid increase of the problem. According to IBM’s Cost of a Data Breach 2025 report, 63% of organizations that suffered a data breach had zero AI governance policies or were in the process of developing them, while only 37% of companies had some kind of AI policies for compliance with shadow AI. The companies that made the most use of shadow AI had average breach-related losses of $770,000 more than companies with little or no shadow AI.

This type of danger is of special concern in India. According to IBM, India’s average cost of a data breach stood at INR220 million in 2025, an increase of 13% as compared to the previous year. Shadow AI ranked among the top three breach-related cost items, costing almost ?17.9 million. Nevertheless, only 42% of companies had a policy in place to manage or detect shadow AI and only 37% reported having policies for AI access.

Employee behavior plays an important role in exposing organizations. As per a TELUS Digital 2025 survey, 57% of enterprise staff using generative AI said they had shared confidential or sensitive information with open-access AI products. About 68% of respondents said they used open access AI through their private accounts which complicates monitoring this activity for corporate security.

Problems related to data being shared by employees arise with the integration of AI applications with cloud infrastructure, enterprise software, programming environment and company databases. A poorly configured AI agent can become a source of identity fraud gaining access to enterprise systems. Prompt injection, malicous directives as well using a compromised third party AI allows for taking advantage of this connection without need for a standard perimeter breach.

As a result, organizations should treat the application of AI as an integral component of their cybersecurity strategy rather than merely a tool for improving productivity. Having tools such as AI inventory, identity and access management, data loss prevention, application monitoring and clear regulations on what information can be transferred to external AI tools has increasingly started to be viewed as a necessity. Additionally, training employees should incorporate information on AI-related risks, rather than focusing solely on general cybersecurity principles.

The purpose is not about getting rid of AI from the workplace, but rather about eliminating the hidden AI technology. In this case, once organizations find out what AI solutions are used, what data is available to them and what actions they can perform, it will enable them to have result-oriented control of their technology, rather than letting it function as an uncontrolled cybersecurity weak point.

Guest contributor Manish Mohta is the Managing Director of Learning Spiral, an online examination solution provider for online assessments, exams for universities. Any opinions expressed in this article are strictly those of the author.

SHARE

facebook icon facebook icon
You may also like