HIPAA Compliance Checklist for 2025
The security team's slide says shadow AI adds $670,000 to the cost of a breach. The CFO reads it twice and asks the only question a budget cares about: is that per year?
It isn't. That number, from IBM's 2025 Cost of a Data Breach report, is the extra cost of one breach, paid only if you have one. It is also a year out of date.
The annual bill is a different animal. It runs on five lines, and most never appear in a breach report: AI bought on expense reports, staff moving data into tools nobody approved, the manual hunt before every audit, and the access AI agents keep after their owners leave.
Add those up for an illustrative 5,000-person company and you get roughly $2.5M a year, before a breach ever happens. The biggest line isn't the breach at all; it's the steady drip of well-meaning mistakes.
Below is that ledger, line by line, with the math shown and the assumptions you can swap for your own.
Why Is $670K the Wrong Answer to the Shadow AI Cost Question?
Go back to that slide. The number on it has three problems, and each one changes the budget conversation.
- It measures one breach, not one year. IBM compared breaches at organizations with high shadow AI against those with little or none; it says nothing about how often you'll have one.
- It has already moved. IBM's 2026 report puts breaches involving shadow AI at $5.39M, up from $4.63M, and the share of incidents involving shadow AI more than doubled, from 20% to 43%, according to summaries by Kiteworks and ComplexDiscovery. The global average breach hit a record $4.99M.
- It's conditional. A premium you pay only in a bad year is a risk estimate, and a CFO budgets for the years that actually happen.

The governance picture moved the wrong way too. Two-thirds of the breached organizations in IBM's 2026 study had no AI governance policy in place, per ComplexDiscovery's reading of the report.
Our take: the $670K slide answers a security question (how bad is a breach?) in a finance question's vocabulary. The finance question needs a ledger.
What Goes Into the Annual Cost of Shadow AI?
Treat shadow AI as a ledger with five lines. Three are cash, one is risk priced as an expected loss, and one can only be counted; that last one is the line that grows.

Line 1: Leaked Spend on AI Tools Bought Outside Procurement
Open last month's corporate card statement. Somewhere between the airline and the catering, there's a line from OpenAI, and probably one from a transcription tool nobody in IT has heard of.
Zylo's 2026 SaaS Management Index found expense-based software spend grew 267% in a year, with ChatGPT now the most expensed app. Spend on AI-native apps rose 108% on average and nearly 400% at large enterprises.
The waste isn't the $20 subscription. It's paying retail, seat by seat, for what could be one contract, without the admin controls, audit logs and data terms an enterprise plan includes.
Line 2: Negligent Incidents When Staff Move Data Into Unapproved AI
This is the biggest line, and it rarely gets a headline. The DTEX and Ponemon 2026 Cost of Insider Risks report puts negligent insiders at $10.3M a year per organization: 13.8 incidents, averaging $747,107 each.
The report ties rising negligence to unauthorized AI use, and 92% of respondents say generative AI is changing how employees share information. It doesn't isolate an AI-only figure, though, so the $10.3M is a ceiling. At least one top-ranking page quotes the whole amount as shadow AI; it isn't.
None of these people are malicious. They're fast: a contract pasted in for a summary, a customer list uploaded for a cleanup, the night before a deadline.
Line 3: Breach Expected Loss, Where the $670K Slide Belongs
Here the breach figure earns its place, as one line of five. The annual version is simple: your probability of a material breach this year, times the 43% share involving shadow AI, times the $5.39M such a breach costs.
IBM doesn't publish an annual breach probability, so pick one you can defend to your board and show it.
Line 4: Orphaned AI Access That Outlives Its Owner
Every leaver gets a checklist: laptop returned, SSO disabled, badge deactivated. The checklist has no line for the AI agent they wired into the CRM last spring.
No one can price this line credibly yet, so count it instead: live AI connections and tokens with no current owner. The agents section below explains why this is the one to watch.
Line 5: Discovery and Audit Labor
Audit week, same drill. One person exports SSO logs, another chases finance for card data, a third emails department heads asking which AI tools their teams use.
The answers come back late and incomplete, and the snapshot is stale on arrival. Then the whole exercise repeats next cycle.
What Does Shadow AI Cost a 5,000-Person Company in a Year?
About $2.5M at the midpoint, with a range of $1.35M to $3.8M, before any breach. This is our model, not a survey result, and every input is below so you can swap in your own.

Three things stand out once the lines sit side by side.
- The recurring bill is about half a breach, every year, whether or not you ever have one.
- Negligent incidents make up roughly 60% of it. The breach line, the one on every slide, is under 10%.
- The model leaves out regulatory fines, customer churn after an incident, and the value employees get from these tools. The first two push the number up; the third is why a ban is the wrong fix.
If you want to size line 4 properly, start with an inventory; this guide on how to govern every agent walks through the discovery sources.
Why Do AI Agents Make Shadow AI Costs Compound?
Shadow chat is a recurring cost: a person, a browser tab, a session that ends. Agents run on a schedule with standing access, and they don't leave when their owner does. That turns line 4 from a rounding error into the line that grows every quarter.
The Ghost Workflow: What Offboarding Misses
Picture a sales-ops analyst who builds a lead-enrichment agent on an automation platform. She grants it OAuth access to the CRM and her inbox, and the pipeline team loves it.
Eight months later she leaves. HR closes the ticket, IT disables her SSO, the laptop comes back. The agent keeps running every night, reading customer records with a token stored on someone else's platform. Nobody offboarded it, because nobody knew it existed.
That scenario is a composite, but each piece is documented. In August 2025, attackers stole OAuth tokens from the Salesloft Drift AI chat agent and reached Salesforce data at more than 700 organizations, The Hacker News reported. Drift was a sanctioned tool with a vendor who could take it offline. A ghost workflow has no contract, no vendor contact and no owner to pull the plug.
Why Security Teams Keep Finding Agents They Didn't Know About
Visibility is improving, and some of it deserves credit. Microsoft now ships a Shadow AI page in the Microsoft 365 admin center that lists and blocks unmanaged local agents, and network tools can fingerprint agent traffic. Each helps; each sees one source.
The gap shows up in the numbers:
- The Cloud Security Alliance found 68% of organizations claim high visibility into agents, yet 82% discovered one they didn't know about in the past year.
- AuthMind's deployment data, published in September 2026, puts roughly one in five running agents outside sanctioned control.
- Only 19% of organizations treat AI agents as equivalent to human insiders, per DTEX and Ponemon.
- The credentials are already circulating. SOCRadar found AI logins and sessions tied to 80,000+ corporate domains in infostealer logs, and flagged automation platforms' standing OAuth grants as the worst case, BleepingComputer reports.
Cloudeagle.ai take: every leaver is a chance to add a row to line 4, and nothing on the standard checklist removes it. That's what compounding means here, and it's why offboarding misses agents unless someone inventories them first.

Is Banning AI Cheaper Than Paying for Shadow AI?
No, and the data on why is fairly blunt.
MIT's Project NANDA found only 40% of companies had bought official LLM subscriptions, while employees at more than 90% of companies use personal AI tools for work, Fortune reported. The same study says shadow AI often delivers better returns than formal initiatives. A ban doesn't delete that value; it hides it.
And hiding gets rewarded. An HEC Paris study found employees who secretly used ChatGPT often received better evaluations than colleagues who disclosed it. Ban AI, and you've built an incentive to conceal the exact thing you most need to see.
So the realistic goal isn't zero shadow AI; it's conversion. Find what people use, sanction the tools that earn it, and close the access that outlives its purpose.
Back to the $670K slide. The conversation it should start isn't ‘how do we stop this?’ It's ‘can we read our own bill?’
How Do You Cut Each Line of the Shadow AI Bill?
Each line has its own lever and its own number to watch. If a lever doesn't move its metric within a quarter, it's the wrong lever.
Where CloudEagle.ai Fits
Most discovery tools see one source. CloudEagle.ai correlates seven discovery sources, including SSO, finance and card data, firewall logs and a browser extension, against its EagleIQ inventory of AI apps. That single view is what makes each lever above work.
- For leaked spend, it tracks AI subscriptions and token usage the way it tracks licenses, then flags duplicate copilots and idle seats for harvesting.
- For negligent incidents, it can monitor or block sensitive content shared with AI tools, and send people who open an unsanctioned tool to an approved one.
- For breach exposure, it risk-scores every AI app it finds, drawing on Netskope's Cloud Confidence Index alongside its own data.
- For orphaned access, it tracks non-human identities (service accounts, API keys, AI agents) with owner, status and permissions, and removes access automatically when someone leaves.
- For audit labor, it records approvals and revocations as they happen, so the evidence already exists when the auditor asks.
If the $670K slide is the only shadow AI number your leadership has seen, start with an inventory instead. CloudEagle.ai builds one across apps, agents and spend in days, not quarters.
See how AI governance works on your own stack.
Frequently Asked Questions About Shadow AI Costs
How Much Does a Shadow AI Breach Cost?
IBM's 2026 Cost of a Data Breach report puts breaches involving shadow AI at $5.39M on average, up from $4.63M in 2025, against a global average of $4.99M for all breaches.
What Is the Biggest Hidden Cost of Shadow AI?
Negligent incidents: employees moving company data into tools nobody approved. DTEX and Ponemon put negligent insider costs at $10.3M a year per organization; in our 5,000-person model, AI-linked incidents make up about 60% of the annual shadow AI bill.
How Do You Calculate the Annual Cost of Shadow AI?
Add five lines: AI spend outside procurement, AI-linked negligent incidents times their average cost, annual breach probability times the shadow AI share times the breach cost, discovery and audit labor, and a count of AI access with no owner. For an illustrative 5,000-person company, the first four total about $2.5M a year.




.avif)




.avif)
.avif)




.png)




.avif)
.avif)
.avif)

