Data Security & DLP · 4 min read

“Shadow AI” becomes a top insider data-loss vector in 2026

The 2026 Verizon DBIR found employees routinely pasting source code and sensitive records into AI tools, while malicious-insider incidents rose sharply — opening a data-exfiltration vector most DLP programs haven't caught up to.

Abstract visualisation of data and artificial intelligence

Published 15 June 2026

Generative-AI assistants have quietly become one of the biggest data-loss channels in the enterprise. The 2026 Verizon Data Breach Investigations Report (DBIR) identified “Shadow AI” — staff using unsanctioned AI tools on corporate devices — as among the fastest-growing non-malicious insider actions seen in data-loss datasets.

What the data shows

  • Shadow AI is now one of the most common non-malicious insider actions detected — a fourfold increase year on year.
  • 45% of employees are regular AI users on corporate devices, up from just 15% a year earlier.
  • Source code is the data type most often submitted to external AI models, ahead of customer records and financial data.
  • Mimecast's 2026 report found 42% of organisations saw more malicious-insider incidents (up from 33% in 2024), each estimated to cost about USD 13.1 million.

Why it matters

Generative AI has introduced an exfiltration vector that traditional, network-centric controls were never designed to see. When an employee pastes proprietary code, customer data or a financial model into a chatbot, the data leaves the organisation through an ordinary HTTPS session to a legitimate service — invisible to tools looking only for malware or known bad destinations.

For Thai enterprises, this is also a compliance problem. Personal data flowing into a third-party AI service can breach the Personal Data Protection Act (PDPA), and “we didn't know staff were doing it” is not a defence. The answer is not to ban AI outright — that just drives it further into the shadows — but to gain visibility and apply policy to where sensitive data actually goes.

How iconnet helps

Generative-AI exfiltration is a data problem, not just a network one. Forcepoint DLP discovers and classifies sensitive data, then enforces policy at the endpoint, web and cloud — blocking source code, customer records and financial data from being pasted into unsanctioned AI assistants, while still allowing safe, sanctioned productivity. It gives Thai enterprises PDPA-aligned visibility and control over exactly where regulated data flows.

Talk to a security specialist

Tell us about your environment and goals. Our engineers will help you scope the right solution — no obligation.