AI is not only a productivity gain. It is a growing attack surface, and organizations are not prepared for either side of that.

The 2025 Cost of a Data Breach Report shows how shadow AI, meaning AI tools adopted without IT approval, is already driving breach costs higher. Beyond the risk from inside, attackers use AI to accelerate phishing, impersonation and automation, making campaigns faster and harder to detect. Most organizations still lack the governance and access controls to keep pace.

Shadow AI, the risk from inside

When employees adopt AI tools without governance, the company loses visibility. One in six breaches now involves shadow AI. IBM estimates these incidents add about $670,000 in cost for a large organization. The figure varies by company size; the impact, meaning disruption, regulatory exposure and loss of trust, does not discriminate.

What starts as a productivity shortcut often opens a path for an attacker. The main risks:

  • Data leakage. Sensitive company or customer data uploaded into an unmanaged tool.
  • Loss of control. IT cannot see or govern which tools are in use.
  • Compliance gaps. No approval, no audit trail, and therefore regulatory exposure.

How attackers use AI against you

From phishing to deepfake impersonation to large-scale automation, attackers lean on AI to make campaigns faster, harder to detect and more convincing. Three use cases dominate:

  • AI-generated phishing. Highly personalized email and messages that are harder to spot.
  • Deepfake impersonation. Convincing voice or video scams aimed at executives and customers.
  • Attack automation. Generating variations, automating tasks, and writing code to run attacks at scale.

When you cannot tell what is real

Deepfakes strike at something more fundamental than cost. They strike at trust. If you cannot believe the voice on the phone or the face on a video call, how do you decide what is real? Attackers can impersonate executives, trick employees, and mislead customers with alarming ease.

Employees, meanwhile, place too much trust in AI output. They assume the model’s answer is correct, overlooking that it can be biased, incomplete or manipulated.

External trust breaks, and internal trust is misplaced. Both directions fail at once.

Why governance matters

The larger problem is readiness. According to IBM, nearly two-thirds of organizations have no formal AI governance in place, and almost every AI-related breach occurred where proper access controls were missing.

When governance is absent, access controls rarely follow. The risk shows up in three shapes:

  • Unmanaged AI in workflows. Tools adopted without oversight, often with sensitive data uploaded into them.
  • Insecure AI setup. Systems built without security in mind, open to manipulation or data leakage.
  • Excessive access. AI given too much reach into systems and data, with no limit on what it can do.

AI rarely sits in isolation. It is wired into ticketing systems, knowledge bases, APIs and databases. Without governance and access control, an attacker can manipulate an AI interaction into a route toward business-critical systems.

What to do now

AI will keep spreading across workflows. The question is whether your organization treats it as an IT surface that needs hardening, or as a tool left unchecked.

  • Define AI policy. Clear rules on which tools are allowed and how they are used.
  • Raise awareness. Make sure people understand both the risk and the policy.
  • Test AI for weaknesses. Include it in penetration testing. Chatbots, plugins and copilots are all entry points.
  • Enforce access controls. Restrict AI system permissions so a compromise stays small.

Written by Sander Rurup, GRC & IT architecture

Cybersecurity consultant with close to a decade of consulting experience in enterprise architecture, information security management and security auditing across regulated European industry. Sander translates exposure into business requirement, governance and ownership.

TOGAF · ISO 27001 · CISM