The AI your company does not know it uses.
Shadow AI is the use of AI applications outside the knowledge of the people accountable for a company’s data. IBM’s 2026 breach study puts it at 43% of studied incidents, up from 20% a year earlier, and the Swiss evidence suggests the gap is one of accounts and rules rather than of tools.
Gli Insights sono pubblicati in inglese.
IBM published the 2026 edition of its Cost of a Data Breach Report on 29 July 2026. Security incidents involving an organisation’s shadow AI — in the report’s words, cases where workers use unapproved AI — more than doubled to 43% this year from 20% last year. Those incidents cost an average of USD 5.39 million, against USD 4.63 million a year earlier and a global average of USD 4.99 million.
The study covers breached organisations, not the economy: Ponemon Institute examined 602 organisations across 17 industries in 16 countries, for breaches between March 2025 and February 2026. It measures not how many companies have a shadow AI problem, but how often unapproved AI appears when things go wrong.
The exposure is contractual before it is technical
Shadow AI is the use of AI applications without the knowledge or oversight of those accountable for a company’s data — the AI-era successor to shadow IT. An early measurement came from Microsoft and LinkedIn’s 2024 Work Trend Index, a survey of 31,000 people in 31 countries: 78% of employees using generative AI at work brought their own tools, 80% in small and medium-sized companies.
Between a sanctioned and an unsanctioned tool the technical difference is often nil: the same model, reached through a different door. The legal difference is not. Business agreements are written differently: Anthropic’s commercial terms, effective 17 June 2025, state that it may not train models on customer content and that such content is the customer’s confidential information. A personal account is a contract between an employee and a provider: the company is not a party to it, holds no record of what was submitted, and controls neither retention nor deletion.
In the University of Melbourne and KPMG global study — 48,340 respondents in 47 countries including Switzerland, surveyed between November 2024 and January 2025 — 70% of employees who use AI at work said they use free, publicly available tools, against 42% using tools provided by their employer. Forty-eight per cent reported uploading company information — financial, sales or customer data — into public AI tools, and 56% had used AI at work without knowing whether it was allowed. Only two in five said their organisation had any policy on generative AI.
The 2026 breach data moves unapproved use from footnote to mainstream
In 2025, IBM counted one in five studied organisations with a breach linked to shadow AI, adding up to USD 670,000 to its cost; 63% had no AI governance policy. The 2026 consequences are more operational than reputational: data loss or compromise in 49% of shadow AI incidents, disrupted operations in 42%, and a fine paid in about one in five, measured for the first time this year.
Governance moved in the opposite direction to adoption. Sixty-eight per cent of breached organisations lacked governance to manage AI or detect shadow AI, against 63% a year earlier; the share requiring IT approval for AI deployments fell to 38% from 45%; only 19% reported any coordination between governance and security functions. Where AI systems were themselves attacked — 21% of organisations, up from 13% — 92% lacked role-based access and multi-factor authentication. The same study puts the average German breach at USD 4.93 million, against USD 4.03 million a year earlier; Switzerland is not among the 16 countries sampled.
Swiss employees are not short of sanctioned tools
The Swiss picture changes the diagnosis. In an EY survey of 604 respondents from Swiss companies, published on 27 May 2026, 89% said they use AI in their working day, 70% through integrated tools such as Microsoft Copilot or Google Workspace with Gemini, 35% through enterprise licences for specialised applications. Twenty-nine per cent said external AI tools through private accounts are permitted — and for 8%, they are currently the only way to use AI at work. Only 3% reported a complete ban.
Accenture’s Pulse of Change survey, whose Swiss results appeared on 29 July 2026, points the same way: 49% of employees in Switzerland use AI tools daily, against a European average of 28%, and 88% report full or moderate access to employer-provided tools, against 80% internationally. Its Swiss sample is small — 100 executives, 100 employees — but consistent with EY.
Swiss exposure therefore has a particular shape: intensive daily use, wide official access, a residual private-account channel. Half of EY’s respondents (51%) consider it business-critical that AI systems meet Swiss or European data-protection requirements and process data in Switzerland or the EU — a requirement a private account defeats.
Swiss law already governs this, without using the word AI
The Federal Data Protection and Information Commissioner settled applicability on 9 November 2023, in a statement he updated on 8 May 2025: the Data Protection Act is technology-neutral and therefore directly applicable to AI-supported processing. Four of its provisions, in force since 1 September 2023, do the work here.
Article 8 requires data security appropriate to the risk. Article 9 allows processing to be assigned to a processor by contract and obliges the controller to satisfy itself that the processor can guarantee data security — a consumer account accepted by an employee is not such a contract. Article 16 permits disclosure abroad only where the Federal Council has recognised adequate protection or another listed guarantee applies; for the United States that runs through the Swiss–U.S. Data Privacy Framework, in force since 15 September 2024 and covering certified companies only. Article 24 requires notification to the FDPIC as quickly as possible where a breach is likely to entail a high risk. The Commissioner’s 33rd activity report, published on 30 June 2026, records 484 such notifications in the year to 31 March 2026 against 363 the year before, voluntary ones rising from 26 to 141.
European law adds a duty that reaches Swiss employers directly. Under European Commission guidance updated on 27 July 2026, the AI literacy obligation in Article 4 of the AI Act has applied since 2 February 2025 to providers and deployers, extends to contractors acting on an organisation’s behalf, and covers staff using tools such as ChatGPT for business purposes. The supervision and enforcement rules apply from 3 August 2026, and the framework reaches actors outside the Union where a system is used there or affects people located there.
Outright bans are where rule-breaking is most often reported
In the Melbourne and KPMG data, employees reporting behaviour that contravened company rules were most numerous where generative AI had been banned outright (67%) and where a guiding policy existed (56%), least numerous where none was reported (33%). The comparison is between self-reported groups, and firms with policies also use AI most, so it establishes no causation. The researchers’ reading is narrower: outright bans may be ineffective, and a policy alone does not produce compliance. On that reading a prohibition is unlikely to end the use, but it does end the record of it.
What can be settled without a project
- Build the inventory before the policy. Proxy and single sign-on logs, expense claims for AI subscriptions and browser extensions list the tools faster than a survey.
- Make the sanctioned route the easy one. Where private accounts are the only access, as for 8% of EY’s Swiss respondents, that is a procurement decision, not a discipline problem.
- Read the contract rather than the interface. Business terms normally exclude customer content from training and treat it as confidential; consumer terms are written differently.
- Write one page: what may never be entered — personal data, health data, unpublished figures, third-party documents, credentials — who may authorise an exception, and a line stating that the approved tool is expected, not merely tolerated.
- Apply the controls the breach data identifies: role-based access and multi-factor authentication on the AI the company does run, absent in 92% of organisations with an AI-related breach.
- Rehearse the notification path once: who decides, and how fast, whether an incident meets the Article 24 threshold.
Three things frame the coming months: enforcement of the European AI literacy duty from 3 August 2026; the Swiss legal framework now being prepared, after the Federal Council decided on 12 February 2025 to ratify the Council of Europe’s AI Convention and signed it in March 2025; and the annual measurements — the Commissioner’s report in June, IBM’s study in July — where any movement in the 43% will first show.
