Shadow AI Use Exposes Corporate Data: Unapproved Chatbots and Extensions Threaten Governance
What Happened — A Malwarebytes Labs analysis shows 71 % of UK employees have used AI chatbots, browser extensions, or other unapproved AI features at work to speed tasks. IBM’s 2025 Cost of a Data Breach study found one in five organizations suffered a breach linked to this “shadow AI,” while only 37 % had policies to detect or manage it.
Why It Matters for Trust & Control Assurance
- Highlights a gap in AI‑governance controls: without approved‑tool policies, data leaves the organization’s control.
- Demonstrates the need for continuous monitoring of AI tool usage and evidence collection for audit readiness.
- Aligns with the AI governance control objective in the NIST AI RMF, which maps to dozens of other frameworks via the Verisq Common Framework.
Who Is Affected – Any sector that handles confidential or regulated data (finance, healthcare, technology, professional services, etc.).
Recommended Actions – Define an enterprise‑wide AI usage policy, deploy monitoring to detect unapproved AI traffic, and run security‑awareness training focused on AI risks. Source: Malwarebytes Labs
Technical Notes – Risk vector: data exfiltration via public AI services or insecure browser extensions; no specific CVE. Potential exposure of customer details, intellectual property, and regulatory‑protected information. Source: same as above