← Back to blog

The boardroom number: putting a rupee figure on shadow AI

Boards approve AI governance budgets when shadow AI stops being an IT anecdote and becomes a number on a slide. Here are the four numbers that turn an invisible risk into a quantified one.

Sakthi Thangavelu·Co-founder, AramGRC·May 19, 2026·8 min read

Boards approve AI governance budgets when shadow AI stops being an IT anecdote and becomes a number on a slide. So here is the number — or rather, the four numbers that turn an invisible risk into a quantified one.

One: prevalence.

This is not a fringe behaviour. Across 2025–2026 surveys, the share of organisations with employees using unsanctioned AI runs from a strong majority to near-universal; large enterprises report it at the high end, and the average firm runs roughly 14 AI tools while IT can see only a third of them. Whatever your institution's real figure is, the honest planning assumption is that it is already happening at scale and you cannot currently see it.

Two: breach cost.

IBM's 2025 research found shadow AI carried a clear cost premium on top of an already expensive baseline breach, and industry trackers now put the average shadow-AI-linked breach in the multi-million range. For a regulated financial institution, add the regulatory layer: DPDP penalties in India, and in the UAE a New CBUAE Law exposure reaching up to AED 1 billion with a September 2026 deadline. 'We didn't know our staff were using AI' is not a defence anywhere.

Three: the deal and insurability tax.

AI governance maturity now shows up in tender outcomes — in the Gulf, certification is becoming a gate before go-lives — and in cyber-insurance terms. Weak control over AI data flows raises premiums, narrows coverage, and slows enterprise sales cycles where customers demand evidence of AI governance before signing.

Four: the cost of the fix is lower than the cost of the breach.

The interventions that work are unglamorous and affordable: an AI inventory, discovery telemetry, a clear data-handling policy, and a sanctioned alternative tool. The evidence shows the sanctioned-alternative move alone collapses shadow usage — and it costs a fraction of a single breach. The board framing that lands: shadow AI is not a productivity question, it is an uninventoried third-party data-processing risk running across the institution without a control owner. Name an owner, fund the inventory, provide the safe tool. The ROI case writes itself the moment the first number goes on the slide.

Shadow AIBusiness CaseBFSIGovernance
WhatsApp