# Shadow AI Watch > Independent coverage of workplace AI usage, governance, and compliance. ## About Shadow AI Watch is an independent publication covering how businesses manage AI tools in the workplace. We publish research, guides, and practical resources for IT leaders, compliance officers, and business owners. ## Topics Covered - **Shadow AI**: What it is, statistics, risks, and industry-specific impacts - **AI Governance**: Frameworks, policies, checklists, and implementation guides - **Compliance**: EU AI Act, GDPR, Australian Privacy Act, UK AI frameworks - **Tools & Monitoring**: Independent comparison of AI governance tools and approaches ## Key Facts - Independent publication, not affiliated with any AI governance vendor - Focus on small and mid-sized businesses (5-500 employees) - Original research based on real-world AI usage data - Practical, actionable content for business leaders - Founded: 2026 - Location: Global coverage ## Sections - [Shadow AI](https://shadowaiwatch.com/shadow-ai/): Unsanctioned AI tool use in the workplace - [Compliance](https://shadowaiwatch.com/compliance/): Regulatory frameworks and AI compliance - [Governance](https://shadowaiwatch.com/governance/): AI governance policies and frameworks - [Research](https://shadowaiwatch.com/research/): Research and analysis on AI governance ## Articles - [California Wants to Ban Employers From Using Worker Data to Train AI That Replaces Their Jobs. The Bill Just Cleared Committee.](https://shadowaiwatch.com/compliance/california-ab-2027-worker-data-ai-training-ban-2026/): AB 2027 would bar employers from using worker data to train AI that replaces their jobs. It cleared committee on 22 April and is now in Appropriations. - [A Federal Judge Fined Two Oregon Lawyers USD 110,000 for AI-Fabricated Citations. US Courts Imposed at Least USD 145,000 in AI Sanctions in Q1 2026 Alone.](https://shadowaiwatch.com/compliance/oregon-ai-sanctions-fabricated-citations-legal-governance-2026/): US courts imposed at least USD 145,000 in AI sanctions in Q1 2026. Oregon's record penalty and per-citation fine formula make AI hallucination costs scalable. - [Researchers Scanned 380,000 Vibe-Coded Apps. 5,000 Were Leaking Medical Records, Bank Data, and Corporate Documents to the Open Web.](https://shadowaiwatch.com/shadow-ai/vibe-coded-apps-data-exposure-shadow-ai-2026/): RedAccess found 5,000 AI-built apps with no authentication leaking patient records, bank data, and corporate documents. Axios and Wired verified the findings. - [Half of All AI Systems Pen Tested by CyberCX Had a Severe Vulnerability. Web Apps Were Half That Rate.](https://shadowaiwatch.com/research/cybercx-hack-report-2026-ai-pen-test-severe-findings/): CyberCX analysed 70,000+ findings from 7,500+ pen tests. AI systems had severe vulnerabilities at double the rate of web apps. Social engineering won 77%. - [AI Just Overtook Immigration and DEI as the Top Workplace Policy Concern for US Employers. 84% Expect Regulatory Impact This Year.](https://shadowaiwatch.com/research/littler-employer-survey-2026-ai-regulation-governance-gap/): Littler's 14th Annual Employer Survey: AI is the top policy concern for 84% of US employers, up from 42% in 2025. Only 55% review AI tools pre-deploy. - [47% of Workers Are Using AI to Finish Early and Spending the Rest of Their Paid Hours on Personal Activities. Their Employers Have Not Caught On.](https://shadowaiwatch.com/shadow-ai/novoresume-ai-generated-work-undisclosed-governance-2026/): Novorésumé surveyed 1,000 US workers. 47% use AI to finish early then spend freed time on personal activities. 53% hide their AI use from employers. - [Google Chrome Is Silently Installing a 4GB AI Model on Corporate Laptops. Most IT Teams Have No Idea.](https://shadowaiwatch.com/shadow-ai/chrome-gemini-nano-silent-install-corporate-governance-2026/): Chrome downloads a 4GB Gemini Nano model to eligible devices without consent, re-downloads it if deleted, and powers AI features most users have never enabled. - [Bots Now Generate More Internet Traffic Than Humans. AI-Driven Attacks Jumped From 2 Million to 25 Million Per Day in a Year.](https://shadowaiwatch.com/research/thales-bad-bot-report-2026-ai-agentic-traffic/): Thales' 2026 Bad Bot Report: 53% of web traffic is automated, bad bots are 40%, AI-driven attacks grew 12.5x, and financial services bore 46% of account takeovers. - [Five Eyes Cyber Agencies Just Published the First Multinational Playbook for Securing Agentic AI](https://shadowaiwatch.com/governance/five-eyes-agentic-ai-security-guidance-2026/): Six cyber agencies from the US, UK, Australia, Canada and NZ released joint agentic AI security guidance on 1 May 2026, covering five risk categories. - [APRA Just Told Every Bank, Insurer and Super Fund in Australia That Their AI Controls Are Not Good Enough](https://shadowaiwatch.com/governance/apra-ai-risk-industry-letter-step-change-2026/): APRA's 30 April 2026 industry letter warns AI governance is not keeping pace. The regulator named Mythos and called for a step-change from all regulated entities. - [Senior Leaders at Santander, Lloyds and Revolut Say the UK Has No Shared AI Governance Standard for Financial Services](https://shadowaiwatch.com/governance/uk-financial-services-ai-governance-gap-zango-2026/): A Zango AI report draws on 27 C-suite interviews and four roundtables with 60 practitioners from major UK and European banks. The US and Singapore have published sector-specific AI governance frameworks. The UK and EU have not. - [The Workers Using AI the Most Are the Ones With the Most Access to Sensitive Data. That Is a Governance Problem.](https://shadowaiwatch.com/shadow-ai/ft-focaldata-ai-adoption-divide-high-earners-governance-2026/): An FT-Focaldata poll of 4,000 US and UK workers found over 60% of top earners use AI daily versus 16% of lowest earners. The people with the most autonomy, the most seniority, and the broadest access are adopting AI fastest, with the least oversight. - [The DOJ Just Backed Elon Musk's xAI Against Colorado's AI Discrimination Law. Compliance Teams Should Keep Building Anyway.](https://shadowaiwatch.com/compliance/doj-xai-colorado-ai-act-constitutional-challenge-2026/): The US Department of Justice intervened in xAI's constitutional challenge to Colorado SB24-205 on 24 April 2026, calling the state's algorithmic discrimination requirements unconstitutional. The law's 30 June 2026 compliance date has not changed. - [EU AI Act Delay Talks Collapsed. The 2 August 2026 High-Risk Deadline Is Back.](https://shadowaiwatch.com/compliance/eu-ai-act-omnibus-collapse-august-2026-deadline-2026/): Twelve hours of EU trilogue negotiations broke down on 28 April 2026 without agreement on the Digital Omnibus reforms. The original 2 August 2026 deadline for high-risk AI systems and Article 50 transparency obligations is still in force. Compliance teams that were banking on an extension need to change course. - [The FTC Has Quietly Built an AI Enforcement Playbook. A Dozen Cases in 2025 Show What Comes Next.](https://shadowaiwatch.com/compliance/ftc-ai-enforcement-playbook-section-5-2026/): The FTC brought at least 12 AI-related enforcement actions in 2025, targeting deceptive capability claims, undisclosed automated decisions, and AI-generated fake content. Section 5 of the FTC Act is doing the work that AI-specific legislation has not. - [The UK Just Made an AI Code of Practice a Legal Requirement. The ICO Has No Choice but to Write One.](https://shadowaiwatch.com/compliance/uk-ico-ai-adm-code-of-practice-si-2026-425/): A new statutory instrument requires the UK Information Commissioner to produce a formal code of practice on AI and automated decision-making. SI 2026/425 comes into force on 12 May 2026 and includes mandatory guidance on children's data. - [A Vercel Employee Installed a Consumer AI Tool. It Cost the Company a Supply-Chain Breach Now on Sale for USD 2 Million.](https://shadowaiwatch.com/shadow-ai/vercel-context-ai-breach-shadow-ai-supply-chain-2026/): Vercel was breached through Context.ai, a consumer AI productivity tool connected to a single employee's Google Workspace with 'Allow All' OAuth permissions. Stolen data is now listed on BreachForums for USD 2 million. The kill chain started with a Roblox cheat download. - [Canada Is Spending $890 Million to Build a Sovereign AI Supercomputer. The Governance Signal Is Bigger Than the Hardware.](https://shadowaiwatch.com/governance/canada-sovereign-ai-compute-infrastructure-program-2026/): Canada's AI Sovereign Compute Infrastructure Program opened applications on 15 April 2026. The $890 million investment turns data residency and provider jurisdiction from abstract risks into funded infrastructure decisions. - [The FBI's 2025 Internet Crime Report Puts AI-Enabled Fraud at USD 893 Million. That Number Is a Floor, Not a Ceiling.](https://shadowaiwatch.com/research/fbi-ic3-2025-ai-enabled-fraud-893-million/): The FBI's IC3 logged 22,364 AI-related complaints with losses exceeding USD 893 million in 2025. It is the first time the annual report includes a dedicated AI section. Enterprise risk frameworks need to catch up. - [Stanford's 2026 AI Index: Incidents Up 55%, Transparency Index Falls 18 Points, and Adoption at 88%. The Governance Maths Are Getting Worse.](https://shadowaiwatch.com/research/stanford-ai-index-2026-incidents-transparency-governance/): Stanford HAI's 2026 AI Index shows AI incidents rose from 233 to 362, the Foundation Model Transparency Index dropped from 58 to 40, and organisational adoption hit 88%. The gap between capability and accountability is widening. - [Grant Thornton Finds 78% of Leaders Doubt They'd Pass an AI Governance Audit](https://shadowaiwatch.com/governance/grant-thornton-ai-proof-gap-governance-audit-2026/): Grant Thornton surveyed 950 senior US leaders. 78% lack confidence they could pass an AI governance audit in 90 days. Only 12% say their workforce is AI-ready. The gap between AI spend and AI proof is widening. - [ASIC and APRA Are Now Monitoring Anthropic's Mythos. Every Regulated Firm Should Be Asking What That Means for Them.](https://shadowaiwatch.com/governance/asic-apra-anthropic-mythos-cybersecurity-risk-2026/): Australian and Asian financial regulators have confirmed they are monitoring Anthropic's Claude Mythos Preview, an AI model that can autonomously find and exploit zero-day vulnerabilities at scale. ASIC expects licensees to be on the front foot. - [WalkMe Says 80% of Enterprise Workers Are Dodging AI Tools. That's a Governance Failure, Not a Tech Problem.](https://shadowaiwatch.com/research/walkme-enterprise-ai-rejection-governance-gap-2026/): WalkMe surveyed 3,750 enterprise workers across 14 countries. 54% bypass company AI, 33% never use it, 78% of executives want to discipline shadow AI use, only 21% of workers have ever been warned about AI policy. The numbers describe a governance gap, not a training gap. - [UK and EU Regulators Just Drew a Target Around Agentic AI. Consumer-Facing Bots Are Now a Compliance Problem, Not an Innovation Story.](https://shadowaiwatch.com/governance/uk-eu-agentic-ai-consumer-law-cma-drcf-2026/): The UK CMA, the cross-regulator DRCF, and the ICO published cluster guidance on agentic AI in March 2026. The CMA can fine up to 10% of global turnover under the DMCC Act. The EU AI Act caps manipulation penalties at 35M EUR or 7% of turnover. - [The EU Just Moved the AI Act's High-Risk Deadline. Systems Deployed Before It May Never Have to Comply.](https://shadowaiwatch.com/compliance/eu-ai-act-high-risk-delay-omnibus-2026/): The EU is pushing back high-risk AI obligations from August 2026 to late 2027 or 2028. Non-retroactivity means systems deployed before those dates may never have to comply. - [DOJ Is Using Existing Law to Police AI-Generated Job Ads. Employers Are Still Treating It as a Tech Problem.](https://shadowaiwatch.com/compliance/doj-ai-job-ads-citizenship-discrimination-2026/): Two DOJ settlements in six weeks have put AI-assisted recruitment squarely inside federal anti-discrimination enforcement. The vendor did not draft the ads, the AI did, and the employer still paid. - [Canada's Privacy Act Review Puts AI Transparency and Mandatory PIAs on the Statutory Agenda](https://shadowaiwatch.com/compliance/canada-privacy-act-review-ai-pia-2026/): Canada has opened the first comprehensive review of its 1983 Privacy Act in 43 years. The proposed reforms would write AI transparency and mandatory privacy impact assessments into statute. - [Twelve US States Just Launched the First Coordinated AI Insurance Examination. The Template Will Spread.](https://shadowaiwatch.com/governance/naic-ai-insurance-evaluation-tool-pilot-2026/): Twelve US states have launched the first coordinated examination of AI claims decisions using a structured evaluation tool. Regulators want technical evidence, not policy statements. - [Australia's Draft Children's Online Privacy Code Quietly Sets a New Baseline for AI Data Handling](https://shadowaiwatch.com/compliance/oaic-childrens-online-privacy-code-ai-2026/): Australia's OAIC has released the draft Children's Online Privacy Code. The rules target children's data, but the AI design baseline they set will likely become the expectation for every AI system. - [Connecticut's Attorney General Just Showed How Existing Laws Already Regulate AI](https://shadowaiwatch.com/compliance/connecticut-ag-existing-laws-regulate-ai-2026/): Connecticut's Attorney General has mapped AI uses to existing privacy, civil rights and consumer protection laws. The message: regulators do not need new AI laws to come after you. - [Two-Thirds of Organisations Are Approving AI Despite Known Security Risks](https://shadowaiwatch.com/research/ai-rollout-pressure-outrunning-governance-2026/): Two global studies from TrendAI and Deloitte, surveying nearly 7,000 leaders between them, find the same pattern: organisations are deploying AI faster than they can govern it. Only 38% have comprehensive policies. - [Your Staff Are Using Unapproved AI Tools. Here Is the CISO's Runbook for What Happens Next.](https://shadowaiwatch.com/shadow-ai/ciso-shadow-ai-runbook-2026/): Every CISO has discovered shadow AI. The question is what to do next. A practical runbook for triage, response and formalisation when staff use unapproved AI tools with sensitive data. - [NSW Has Passed Australia's First AI Workplace Safety Law. Here Is What Employers Need to Do Before It Starts.](https://shadowaiwatch.com/compliance/nsw-whs-digital-work-systems-ai-2026/): NSW has passed Australia's first law putting AI explicitly inside the WHS Act. Both duties await proclamation. Employers using AI-driven rostering, monitoring or performance tools should be preparing now. - [Agentic AI Is Now a Regulatory Category, Not Just a Security Buzzword](https://shadowaiwatch.com/governance/agentic-ai-regulatory-category-finra-gdpr-ico-2026/): Four regulators across three continents have published formal guidance naming agentic AI as a distinct risk category. FINRA, Spain's AEPD, Turkey's KVKK, and the UK's ICO all say existing rules already apply. - [Australia's Fair Work Commission Writes New Rules After AI-Generated Claims Push Its Workload Up 70%](https://shadowaiwatch.com/shadow-ai/fair-work-commission-ai-generated-claims/): The FWC has released draft AI disclosure rules after AI-generated employment claims drove its caseload up 70% in three years. What employers need to know about documentation, AI audits, and the December 2026 Privacy Act deadline. - [Industrial AI Runs Into a Cybersecurity Wall: Cisco's 2026 Data Shows Governance Is the Bottleneck, Not Budgets](https://shadowaiwatch.com/research/industrial-ai-cybersecurity-governance-bottleneck-cisco-2026/): Cisco surveyed 1,000+ industrial decision-makers across 19 countries. 40 per cent cite cybersecurity as the top barrier to AI adoption. IT/OT collaboration is the missing governance layer. - [AI Transparency Is Now a Legal Requirement: New York, Utah, and the EU Are Writing the Rules](https://shadowaiwatch.com/compliance/ai-transparency-new-york-utah-eu-labelling-rules-2026/): New York requires generative AI accuracy warnings. Utah enacts provenance standards. The EU proposes a standard AI icon. These are hard UI requirements, consent obligations, and penalty regimes. - [Federal AI Preemption Moves From Executive Order to Legislative Blueprint](https://shadowaiwatch.com/compliance/us-federal-ai-preemption-legislative-framework-2026/): A White House legislative framework and a competing Senate draft both target state AI law pre-emption. Colorado's AI Act takes effect 30 June 2026. What compliance leads should do while federal and state laws collide. - [EU AI Act Enforcement Is Behind Schedule: Only 8 of 27 Member States Have Named AI Authorities](https://shadowaiwatch.com/compliance/eu-ai-act-enforcement-member-states-behind-schedule-2026/): Member States were required to designate AI Act enforcement authorities by August 2025. Seven months late, only eight have done so. High-risk obligations start in August 2026. - [The AI Your Organisation Is Already Using Without Knowing It](https://shadowaiwatch.com/research/ambient-ai-exposure-saas-vendors-default-data-processing-2026/): 89 per cent of enterprise AI use is invisible to IT. SaaS vendors are processing your data through AI by default. Ambient AI exposure is a governance blind spot most organisations have not mapped. - [COSO Has Spoken: Generative AI Now Sits Inside Your Internal Control Framework](https://shadowaiwatch.com/governance/coso-generative-ai-internal-control-framework-2026/): COSO published its first GenAI-specific internal control guidance in February 2026. Eight capability types, five COSO components mapped to AI, and a six-step implementation roadmap. - [The Bot Joined Before the Agenda: Shadow AI Inside Meetings and Collaboration Tools](https://shadowaiwatch.com/shadow-ai/shadow-ai-meetings-collaboration-governance-2026/): 75 per cent of professionals use an AI note-taker in work meetings. 84 per cent change how they speak when one is present. UC platforms are the largest ungoverned AI surface in the enterprise. - [Agentic Shadow AI Is Already an Incident Category, Not a Thought Experiment](https://shadowaiwatch.com/shadow-ai/agentic-shadow-ai-agent-security-incidents-2026/): 88 per cent of organisations report confirmed or suspected AI agent security incidents. Only 14.4 per cent of agents went live with full security approval. Agentic shadow AI is a structural risk most organisations have not begun to govern. - [Employees Still Do Not Know What Data They Can Put Into AI Tools](https://shadowaiwatch.com/shadow-ai/employees-ai-data-training-gap-2026/): Nearly 40 per cent of data flowing into AI tools is sensitive, yet most organisations lack clear rules. The grey zone where employees draw their own lines is where risk concentrates. - [AI Sovereign Risk Is Now a Board-Level Decision](https://shadowaiwatch.com/research/ai-sovereign-risk-cloud-act-provider-jurisdiction-2026/): US-headquartered AI providers face CLOUD Act jurisdiction that makes data location irrelevant. How sovereign risk, provider politics, and regulatory conflict create board-level exposure. - [The First Australian Judicial Guidance on Directors and AI: ASIC v Bekier, Explained](https://shadowaiwatch.com/governance/asic-bekier-directors-ai-governance-2026/): Justice Lee's judgment in ASIC v Bekier contains the first substantive Australian judicial commentary on directors using generative AI. What boards need to know about formal AI governance policies. - [UK AI Governance Is Arriving for SMEs Through Procurement, Data Law, and Regulators. Not a Single AI Act.](https://shadowaiwatch.com/governance/uk-ai-governance-smes-procurement-data-law-2026/): The UK has no AI Act but businesses are already regulated through data protection reform, sector regulators, and procurement. How obligations reach SMEs through supply chain pressure. - [Microsoft Copilot Does Not Break Security. It Shows Where It Was Already Broken.](https://shadowaiwatch.com/shadow-ai/microsoft-copilot-oversharing-permissions-risk-2026/): Microsoft 365 Copilot exposes existing SharePoint permission failures rather than creating new ones. How oversharing, permission sprawl, and MSP incentive structures create data exposure risk. - [EU AI Act Compliance Tools Move to Two-Layer Transparency and Zero-Storage Design](https://shadowaiwatch.com/compliance/eu-ai-act-compliance-tools-transparency-zero-storage-2026/): A March 2026 update to an EU AI Act compliance tool shows how monitoring platforms are encoding the EU AI Office's emerging expectations: two-layer transparency, Article 14(4) automation bias checks, mandatory change-log tracking, and zero-storage documentation handling. - [Canada's AI Governance Patchwork: What CIOs Must Do Without a Federal AI Law](https://shadowaiwatch.com/governance/canada-ai-governance-patchwork-2026/): Canada has no comprehensive federal AI law and will not have one in the near term. What it does have is a set of real expectations: regulators now expect AI inventories, impact assessments, and clear accountability structures, even without legislation that mandates them explicitly. - [AI Data Privacy in 2026: How EU AI Act, GDPR and US State Laws Now Collide](https://shadowaiwatch.com/compliance/ai-data-privacy-2026-gdpr-eu-ai-act-us-collision/): AI data privacy is a live enforcement risk in 2026, not a forward-looking concern. GDPR already applies to AI systems that process personal data. The EU AI Act adds a second layer from August 2026. US states added 145 more obligations in 2025 alone. - [GenAI Value Drift: How AI Is Quietly Changing Workplace Standards Nobody Voted to Change](https://shadowaiwatch.com/governance/genai-value-drift-workplace-governance/): Most AI governance frameworks are designed to catch failures. University of Auckland researchers identify a different problem: when GenAI generates the language of management, workplace standards can shift without any single failure to point to. - [Federal AI Preemption Push: Which State Laws Are Safe and Which Aren't](https://shadowaiwatch.com/compliance/us-federal-state-ai-collision-2026/): Washington is pushing to invalidate state AI laws but cannot do it overnight. A breakdown of which laws face real federal risk, which are effectively untouchable, and how compliance teams should operate in the gap. - [New 2026 AI Security Stats Show Governance Cuts Incidents Nearly in Half](https://shadowaiwatch.com/research/ai-security-statistics-2026-governance-reduces-incidents/): 68% of organisations have experienced AI-linked data leaks, yet only 23% have formal AI security policies. New data shows mature AI governance cuts security incidents by 45% and accelerates breach resolution by 70 days. - [Trade Surveillance Is Not Ready for AI, But Doing Nothing Is the Riskier Choice](https://shadowaiwatch.com/research/trade-surveillance-ai-readiness-2026/): Only 16% of compliance decision-makers have fully deployed AI in trade surveillance, while 69% expect AI adoption to drive new compliance risks within 12 months. The gap between awareness and action is the problem. - [March 11 Federal AI Deadlines: What Businesses Everywhere Need to Watch](https://shadowaiwatch.com/compliance/march-11-federal-ai-deadlines-2026/): Two 90-day deadlines under Trump's December AI executive order land on March 11. The Commerce Department's state law evaluation and the FTC's AI policy statement will shape compliance decisions across US jurisdictions for the rest of 2026. - [Kordia Report: Shadow AI Is Now NZ's Top Cyber Risk, Ahead of External Attacks](https://shadowaiwatch.com/shadow-ai/kordia-shadow-ai-insider-threat-nz-2026/): Kordia's 2026 NZ Business Cyber Security Report puts shadow AI at the top of the cyber risk table. 43% of NZ businesses say their own employees are the biggest AI threat. - [Ontario's IPC-OHRC AI Principles: A Governance Baseline Businesses Cannot Ignore](https://shadowaiwatch.com/compliance/ontario-ipc-ohrc-ai-principles-governance-baseline/): Ontario's Information and Privacy Commissioner and Human Rights Commission published joint AI principles in January 2026. Technically non-binding, they will ground regulatory assessments of AI adoption. Multiple law firms advise treating them as effective requirements. - [Shadow AI as a Data Leak Engine, Not Just a Rogue App Problem](https://shadowaiwatch.com/shadow-ai/shadow-ai-data-leak-engine/): The real shadow AI risk is thousands of employees pasting sensitive data into personal AI accounts every day with no logging, no oversight, and no awareness they have done anything wrong. - [EU AI Act: What Australian Businesses Need to Know](https://shadowaiwatch.com/compliance/eu-ai-act-australia-guide/): The EU AI Act applies to Australian businesses touching EU customers, data, or markets. High-risk AI obligations start 2 August 2026. Here is what to do. - [What Is an AI Governance Framework (And What Does One Actually Contain)?](https://shadowaiwatch.com/governance/ai-governance-framework-guide/): Most organisations deploying AI lack a governance framework. This guide explains what one contains and how to build it using ASIC's maturity model. - [When AI Adoption Outruns Governance: What ASIC Found Inside 23 Australian Lenders](https://shadowaiwatch.com/governance/asic-ai-governance-gap-financial-services/): ASIC reviewed 624 AI use cases across 23 Australian licensees and found governance consistently trailing deployment. The compliance gap is already causing consumer harm. - [AI Compliance Deadlines in 2026: What Every Business Needs to Know](https://shadowaiwatch.com/compliance/ai-compliance-deadlines-2026/): The [EU AI Act](https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai) and Australian Privacy Act amendments both land in 2026 with real penalties. Here is what they require and what needs to happen before they arrive. - [The Real Cost of Shadow AI: What the 2026 Data Shows](https://shadowaiwatch.com/research/cost-of-shadow-ai-2026/): New research from Ponemon, IBM, and Reco puts concrete dollar figures on unmanaged AI usage, with insider incidents averaging US $19.5 million per year and shadow AI adding $670,000 per breach. - [Shadow AI Just Became a Forensics Problem](https://shadowaiwatch.com/shadow-ai/cybercx-shadow-ai-data-spill-forensics/): [CyberCX](https://cybercx.com.au/) confirmed their incident response team was called in for AI data spill cases in 2025. Shadow AI is now a forensics category, not just a risk register entry. - [What Is Shadow AI? The Complete Guide for Businesses](https://shadowaiwatch.com/shadow-ai/what-is-shadow-ai/): Shadow AI is when employees use AI tools at work without approval. This guide covers how common it is, the real risks, what doesn't work, and what to do about it.