Shadow AI and Verizon's 2026 DBIR: Designing the Approved Path

Monochrome line illustration on white: arrows slipping past a gate-like frame, a metaphor for usage flowing outside the approved path

AI & Software · 2026-08-22 · 8 min

Verizon's 2026 DBIR documents AI use spreading on corporate devices, alongside extensive use of non-corporate accounts. We separate what the report shows from our own view on what to design.

Verizon’s “2026 Data Breach Investigations Report” (DBIR, 19th edition), published on May 19, 2026, documents a sharp rise in AI use on corporate devices. It separately reports extensive use of non-corporate accounts and unapproved browser extensions.

In the report’s dataset, the share of “regular users” — people who access an AI platform at least once every 15 days from a company device — rose from 15% the previous year to 45%.

The 45% includes regular use of both authorized and unauthorized AI services. It is not an unauthorized-use rate.

Separately, the report states that 67% of people using AI services were accessing them through non-corporate accounts, even while using a company-issued device.

When presented together without their denominators, the two figures can be misread as meaning that 45% of employees use AI without authorization. That reading is not accurate.

The 45% is a usage rate that does not distinguish authorized from unauthorized use. The 67% uses AI-service users as its denominator and describes the type of account used. It should not be read as 67% of the 45% regular-user figure.

These figures also come from Verizon’s own DLP (data loss prevention) service and telemetry from corporate devices, not from a random survey of all companies or all employees.

The data behind the Shadow AI analysis is drawn mainly from 2025.

Some IT and business leaders may assume that approval processes and blocklists are sufficient to contain AI-related risk.

This article separates the report’s findings from MIF’s interpretation. It then presents our view on how approved AI pathways should be designed.

Two Numbers That Measure Different Things: 45% and 67%

Following the DBIR’s own framing, it’s worth confirming what each of these two numbers is actually measuring.

The first is the share of “regular” AI users.

The DBIR defines a “regular user” as someone who accesses an AI platform from a company device at least once every 15 days, and reports that this share rose from 15% the previous year to 45%.

What matters here is that the DBIR itself notes this figure is “authorized or not.” The 45% includes regular use of both authorized and unauthorized AI services. It is not a rate of unauthorized use.

The second is the share of usage through non-corporate accounts.

The DBIR reports that, among people using AI services, 67% were accessing them through a non-corporate account while using a company-issued device (down slightly from 72% the previous year).

The 67% is the share of observed AI-service users who accessed those services through non-corporate accounts on corporate devices. It is not a subset that should automatically be calculated from the 45% figure. It describes what kind of account was used, not how often access occurred, and it is not limited to personal email addresses specifically.

The DBIR also states that Shadow AI — use of unapproved generative AI services — was the third most common category of non-malicious insider behavior in its 2025 DLP dataset, a fourfold increase in its percentage share from the previous year.

It’s worth noting that this “third most common” figure sits on a different axis of measurement (a classification of behaviors detected by DLP) than either the 45% or the 67%.

The 45% shows broader AI adoption. The 67% and the Shadow AI DLP category separately show that a substantial amount of observed use occurred through channels outside corporate account management. Each figure measures a different part of that picture.

What the 858,440 DLP Events Contained

The DBIR also analyzed the types of data involved in 858,440 DLP events tied to unapproved or untrusted generative AI tools.

That figure counts detected events — not the number of users involved, and not confirmed instances of a data breach.

By data type, source code was by far the most common, followed by images and other structured data.

The report also found that research and technical documents were uploaded to unapproved AI systems in 3.2% of these DLP events, which the DBIR frames as an intellectual-property leakage risk.

Browser extensions are another area worth attention.

According to the DBIR, at the average organization, over 15% of users had installed an unapproved AI browser extension.

This is an organization-level average reported by the DBIR, not a rate that applies uniformly to every company.

The DBIR explains that one of the main functions of this kind of extension is to collect and retain the content a user is browsing, as context.

So the accurate way to put it is: if an employee is browsing an internal company site, non-public data could end up captured by that extension. The DBIR does not go so far as to say these extensions collect login credentials or authentication information directly.

”Non-Malicious” Describes a Data Category, Not a Motive

The DBIR places Shadow AI in a category it calls “non-malicious insider behavior,” distinct from deliberate, malicious data exfiltration.

An important distinction is that “non-malicious” describes how the behavior was classified within the DLP data — nothing more.

The DBIR does not investigate or substantiate the underlying motive for that usage — whether it was “to get the work done faster” or “because the approved tool was hard to use.”

In this article, the explanation that follows — why employees choose that path in the first place — is our interpretation, not a finding from the DBIR’s own research.

From Here, This Is Our View

The DBIR’s findings support the points above: AI use on corporate devices is spreading; a substantial share of observed use runs through non-corporate accounts or unapproved browser extensions; and it identifies the types of data appearing in those DLP events.

The report does not examine why employees choose that path, or how the strictness of a ban or approval list actually shapes behavior.

From here, we’re drawing on what we’ve seen and heard through our own conversations helping companies adopt AI day to day.

When a company bans using personal email for work, but the approved channel is slow or hard to use, people sometimes end up finishing the work through personal email anyway.

We think a similar pattern can apply to AI tools.

A prohibition alone may be insufficient when employees still have unmet operational needs.

This is not something the data itself measured; we’re presenting it as our own working hypothesis about how these systems should be designed.

One Example: Elements for Designing Shadow AI Countermeasures

Starting from that view, here is a starting point for where to focus design attention in practice.

The following is one example, not a statement of the correct configuration.

It assumes each organization will adapt it to its own line of business, regulatory context, and risk tolerance.

Design areaQuestion to askTypical implementation layer
Approved services and accountsWhich AI services are approved, and which must be accessed through company-managed accounts or SSO? How should non-corporate accounts be handled?Identity provider / SSO / SaaS management / enterprise agreements and usage policies
Permitted data inputsOf public, internal-only, confidential, and regulated data, which data may be submitted to which AI environments?Data classification / usage policy / DLP
Extensions and external integrationsWhich AI browser extensions and external integrations are permitted, and who approves adding or removing them?Managed browser / device management / app permission settings
Detecting data flowsWhere is the outbound transfer of code, images, documents, and similar material logged, flagged, or blocked?DLP / web proxy / monitoring
Usability and request intakeDoes the approved path have the functionality and responsiveness business users need? Is there a channel for requesting a new use case?AI service desk / use-case request process
Exceptions and reviewWho approves an exception, what gets logged, and when is it reviewed?IT / legal / business units

What matters in this table is that many of the areas in the right-hand column cannot be addressed through product settings alone.

Organizations need to assign decision ownership and define provisional data rules internally, then validate that those rules can be implemented in the selected product.

What’s Easy to Miss When Building an Approved Path

Standing up an approved AI path doesn’t mean the risk is handled.

Does the approved tool actually compete with the unmanaged alternative on usability?

If the approved option is slower, more cumbersome, or lacks required functionality, unauthorized use may persist despite the written policy. Design effort should focus not only on restricting unmanaged alternatives, but also on making the approved pathway practical to use.

Watch for “invisible” paths like extensions.

Management needs to cover AI that runs persistently as a browser extension, not only tools people open deliberately as a website.

Keep a record, and revisit it.

Recording what data was approved for which environment, and who signed off on it, makes it possible to check later whether the policy still matches how things actually work.

Conclusion: Don’t Conflate the Two Numbers

The 45% in Verizon’s 2026 DBIR (regular AI users, authorized or not) and the 67% (the share of observed AI-service users on non-corporate accounts) are measurements of two different things.

Conflating them makes the situation sound more dire than the data supports.

What the DBIR directly shows is rapid growth in AI use on corporate devices, alongside extensive use of non-corporate accounts, unapproved AI services, and unapproved browser extensions. These are separate measures and should not be combined into a single unauthorized-use rate.

Whether an organization establishes a ban or approved-tool list, and whether employees actually use the approved pathway, are separate questions — that’s our view.

If you want to check where your own organization stands, these are reasonable places to start:

  • Is the AI usage rate your company tracks measured on the same basis as the DBIR’s definition (regular use, authorized or not)?
  • Is the approved pathway practical enough that business users are likely to choose it over unmanaged alternatives?
  • Does your coverage include harder-to-see paths, like browser extensions?

Stronger restrictions and a usable approved pathway both matter, but neither is sufficient on its own. That is MIF’s interpretation of the operational implications — not a conclusion directly tested by the DBIR.

Sources and Verification

This article was prepared primarily from Verizon’s “2026 Data Breach Investigations Report” (19th edition), published May 19, 2026 — specifically the section “DataGPT: gone, pilfered or transferred” on pages 60–61 of the main report — and the “2026 DBIR Executive Summary,” page 12.

The Shadow AI analysis draws primarily on 2025 data from the DBIR’s DLP and corporate-device telemetry datasets. It is not a random survey designed to represent all companies or all employees.

Under the DBIR’s definition, a “regular user” accessed an AI platform at least once every 15 days. The 45% figure includes both authorized and unauthorized use.

The 67% figure is the share of observed AI-service users who used non-corporate accounts on corporate devices (72% the previous year); it should not be treated as a subset calculated from the 45% figure.

The 858,440 figure counts DLP events targeting unapproved or untrusted generative AI tools. It is not a count of users, unique files, or confirmed data breaches.

The browser-extension figure refers to the rate reported for the average organization in the dataset.

MIF’s view that restrictions and approved-tool lists should be paired with a usable approved pathway, technical monitoring, and an exception process is an operational interpretation. The DBIR did not test the causes of unauthorized AI use or the effect of improving approved tools.

Back to articles