AI Incidents Cost Enterprises $2M or More, and the Biggest Shadow AI Culprit Is IT
AI incidents top $2M per enterprise—and IT, the supposed governance owner, leads shadow AI violations.
AI incidents top $2M per enterprise—and IT, the supposed governance owner, leads shadow AI violations.
More than 40% of enterprise decision-makers report AI-related incidents exceeding $2M in the past year, yet adoption accelerates with worker AI access up 50% in 2025. The sharpest irony: IT departments, nominally responsible for AI governance, are the leading source of unsanctioned AI use. Risk ownership remains contested across the C-suite, and a confidence gap separates executives from VP-level peers on AI visibility. Governance spending is rising, but without clear accountability it isn't translating into control.
Action: Audit AI tool usage within IT before expanding governance programs to other business units—credibility requires the governing function to comply first.
This audio is auto-generated. Please let us know if you have feedback. As high-profile security events like OpenAI’s rogue AI hackermonopolize the news cycle, enterprise leaders are facing their own AI dilemma: how to balance rapid adoption with mounting security risks. Security incidents are costing enterprises serious capital. Over 40% of respondents said AI-related incidents cost their organizations $2 million or more in the past year, according to a survey of 300 enterprise decision-makersby security platform provider WitnessAI. Meanwhile, 91% reported concerns that AI agents are increasing their financial risk exposure, and 86% of respondents said they had investigated one or more AI-related security or operational incidents in the last 12 months. Yet enterprises are pushing ahead on adoption, with worker access to AI surging by 50% in 2025, according to Deloitte’s “State of AI in the Enterprise” report. “This seems like the first time that I can think of where risk isn’t slowing anybody down,” Rick Caccia, CEO of WitnessAI, told Channel Dive. “Typically, you’d see risk, and security would put the brakes on, and the brakes would actually work. And this is an example where the brakes aren’t being put on, and if they are, they’re not working. So, you’re seeing adoption happen really quickly, despite all these risks.” Shadow AI, the unsanctioned use of AI tools by individuals working for a corporation, is among the biggest security risks for enterprises. “Every prompt, upload, or query is a potential breach,” Aditya Patel, cloud security specialist at AWS,wrote in a Cloud Security Alliance blog post. “The problem isn’t just volume — it’s velocity. AI’s self-learning nature means risks compound faster.” Strikingly, respondents said IT/infrastructure departments are the biggest source of shadow AI activity. The department most responsible for governing AI use within the organization is also the department most likely to be operating outside its own policies, according to WitnessAI. Amid this chaos, companies are allocating significant portions of their AI budgets to risk management and governance — more than half dedicate between 21% and 45% of AI spending to these efforts — yet risk ownership remains unclear, Caccia said. “Is it the CFO? Is it the CEO? Is it legal? Who the heck owns control of AI risk?” he said. The survey also revealed a significant perception gap between enterprise executives and VP-level decision-makers. While 68% of C-suite respondents expressed confidence in their visibility into AI tools, models and agents accessing company data, only 46% of VPs shared that confidence. For enterprises grappling with security incidents, AI visibility is the top priority. You can’t control what you can’t see, according to Caccia. For channel partners, the enterprise AI security challenge represents a significant business opportunity. Keep up with the story. Subscribe to the CIO Dive free daily newsletter “This is a generational opportunity for channel partners because your client base is trying to figure all of this stuff out,” Caccia said. “This is a chance to help your clients with real strategy and real solutions.”
- 01More than 40% of enterprise decision-makers report AI-related incidents exceeding $2M in the past year, yet adoption accelerates with worker AI access up 50% in 2025.
- 02The sharpest irony: IT departments, nominally responsible for AI governance, are the leading source of unsanctioned AI use.
- 03Risk ownership remains contested across the C-suite, and a confidence gap separates executives from VP-level peers on AI visibility.
- 04Governance spending is rising, but without clear accountability it isn't translating into control.
Don't miss tomorrow's
The Daily Pulse in your inbox each morning — sourced and linked.