Shadow AI Showed Up in 43% of Breaches: 5 Signs It’s in Your Company

Shadow AI risk: business team discovering unapproved AI tools on company laptops, with one approved secure AI tool

Shadow AI is when employees use AI tools for work without approval from IT or leadership. Think personal ChatGPT, Claude, or Gemini accounts, free AI browser extensions, or AI note-takers that join meetings on their own. It usually starts with good intentions. The risk is that company and customer data ends up in tools nobody is managing. This is no longer a fringe problem. In IBM’s Cost of a Data Breach Report 2026, security incidents involving shadow AI more than doubled in one year, to 43% from 20%. IBM also found that 68% of the breached organizations it studied lacked the AI governance needed to manage AI or detect shadow AI. Below are five signs shadow AI is already inside your company, why it matters for small and mid-sized businesses, and a practical plan to bring it under control without banning the tools your team relies on. What is shadow AI? Shadow AI is the AI version of shadow IT. Shadow IT means software or cloud services that employees adopt without the company’s knowledge. Shadow AI means the same thing for AI tools, AI features inside other apps, and AI agents or automations that connect to company data without review. Common examples of shadow AI in a small or mid-sized business include: None of this means your employees are doing something malicious. In most companies, shadow AI is a sign that people found AI useful before the business gave them a safe, approved way to use it. That is good news, because the fix is about guardrails, not punishment. Why shadow AI security matters for small businesses The behavior is widespread. In Okta’s AI Agents at Work 2026 research, 52% of employees admitted to using AI tools without approval, often through personal accounts. Okta also found that workers using unapproved AI tools were more likely to share sensitive information with them. Most small businesses have not caught up on policy yet. The Pax8 SMB AI Pulse report for Q2 2026 found that only 23% of small and mid-sized businesses have a documented AI use policy, with another 24% working on one. Security and privacy were the top barrier to AI adoption in the same research. Lean teams make it harder to see. IDC research from June 2026 notes that 40% of small and mid-sized businesses have no full-time IT employee. When nobody owns technology full time, nobody is watching which AI tools get adopted, which accounts they use, or what data flows into them. Insurers are starting to ask about it. According to CBIZ’s September 2026 guidance on cyber insurance controls, carriers are evaluating AI policies and may restrict coverage where AI governance is missing. CBIZ recommends an AI acceptable-use policy, an approval process for AI tools, employee training, and visibility into AI activity. One caution on the numbers: IBM’s breach research covers organizations of all sizes, not only small businesses. But the pattern is the same at every size. When AI adoption moves faster than oversight, data leaves the building in ways nobody planned for. 5 signs shadow AI is already in your company 1. Nobody can list every AI tool your team uses Ask your managers a simple question: which AI tools does your team use every week, and under which accounts? If the answers are vague, different from department to department, or include “I’m not sure,” you have shadow AI. An accurate AI inventory is the starting point for every other control, and most businesses do not have one until they go looking. 2. Employees use personal AI accounts for company work Personal accounts are the most common path for shadow AI. They sit outside your single sign-on, outside your data-retention settings, and outside your offboarding process. When someone leaves the company, their chat history, uploaded files, and saved prompts can leave with them. Consumer accounts are also not designed for confidential business or client data. 3. AI note-takers and browser extensions show up without review If AI meeting bots appear on client calls, or staff install AI extensions to speed up email and research, those tools may be recording conversations or reading documents. Nobody has checked where that information is stored, how long it is kept, or whether it is used to train a model. These tools are easy to install and easy to forget, which is exactly why they need an approval step. 4. Company or client data appears in AI prompts Watch for signs that sensitive information is being pasted into public tools: contract language, HR details, financial records, customer lists, source code, or patient and donor information. Even a single upload can create a disclosure problem with clients, regulators, or your cyber insurer. Your team may not realize that “just summarizing” a document still means sharing it with an outside service. 5. You have no written AI policy or approved-tools list If your company has not written down which AI tools are approved, what data can and cannot go into them, and who approves new tools, every employee is making those decisions alone. That is the definition of shadow AI. A short, plain-language policy plus a list of approved tools removes the guesswork for everyone. If two or more of these signs sound familiar, assume shadow AI is already part of how your business runs. That is common, and it is fixable. How to bring shadow AI under control without banning AI Banning AI outright rarely works. People keep using the tools on their phones and personal laptops, and the business loses even more visibility. A better approach is to make the safe path the easy path. Here is a practical sequence most small and mid-sized businesses can start this month: Access control deserves special attention. IBM found that 92% of organizations that experienced an AI-related breach lacked proper AI access controls, such as role-based access and multifactor authentication. Getting identity and permissions right before you scale AI is one of the most effective steps you can take. Shadow AI Governed AI

What Is a Fractional CTO? When Your Startup Needs One

Fractional CTO presenting a technology roadmap to a startup leadership team

You have a product idea, a pitch deck, or a business that runs on software you didn’t build. And sooner or later, a technical decision lands on your desk that you aren’t sure how to make. Which platform do we build on? Is this developer quote fair? Is our customer data actually secure? Can we use AI without handing our data to someone else? Most founders think they have two options: hire a full-time CTO they can’t afford yet, or wing it. There’s a third option, and for many early-stage startups and small businesses it’s the right one: a fractional CTO. Here’s what that actually means, what it costs, and how to tell whether you need one. What is a fractional CTO? A fractional CTO is an experienced Chief Technology Officer who works with your company part-time, usually on a monthly retainer, instead of as a full-time employee. You get senior technology leadership—strategy, architecture, security, and vendor oversight—for a fraction of the time and cost of a full-time executive hire. The key word is leadership. A good fractional CTO isn’t a contractor who writes code when asked. They sit on your side of the table, own technology decisions, and are accountable for outcomes. At JR Secure Design, we describe it this way: we’re operators who own outcomes, not outside consultants on the clock. A member of your team for strategy and execution. What does a fractional CTO actually do? The job changes with your stage, but it usually covers some mix of the following: For a non-technical founder, the biggest value is simpler: someone you trust to tell you the truth about your technology. Fractional CTO vs. full-time CTO vs. agency or freelancer These options solve different problems. Here’s a plain comparison: Fractional CTO Full-time CTO Agency or freelancer Role Part-time executive who owns technology strategy and outcomes Full-time executive and usually a leader of an in-house team Builds what you specify Commitment Monthly retainer, flexible Salary, benefits, often equity Per project or per hour Best for Pre-seed to growth stage, SMBs without a tech leader Funded companies with a growing engineering team Well-defined builds where you already know what you need Whose side are they on? Yours Yours Their own scope and invoice Main risk Limited hours if you need someone full-time High fixed cost, slow and expensive to hire wrong Nobody owning the big picture The comparison founders often miss is the last one. An agency or freelancer can be a great way to build, but someone still has to decide what to build, check the work, and own security and architecture. A fractional CTO fills that gap. A full-time CTO makes sense once technology is a full-time leadership job: an engineering team to manage, a complex product, and funding for an executive salary. Until then, a fractional CTO can get you there. Signs you need a fractional CTO You probably need one if any of these sound familiar: What does a fractional CTO cost? Pricing varies widely depending on how many hours you need and how hands-on the role is. As a market reference point, Go Fractional’s rate benchmark (based on fractional job posts and candidate profiles over a rolling 90-day window, checked October 5, 2026) puts the average fractional CTO rate at about $211 per hour, with the middle 50% between $160 and $250 per hour. At a typical scope of about 15 hours a week, that works out to roughly $9,600 to $15,000 per month. For comparison, the U.S. Bureau of Labor Statistics reports a median annual wage of $175,140 (May 2025) for computer and information systems managers, the occupation group that includes CTOs. That’s before benefits, payroll taxes, equity, and recruiting costs. Go Fractional estimates the fully loaded cost of that full-time hire at about $250,000 a year. How JR Secure Design structures fractional CTO engagements We built our fractional CTO pricing so founders can start small and scale up as the business grows. Your first month is free. After that, monthly tiers are: Start with a strategy call to scope what you need. From there we match a tier to your stage and technical priorities. How to pick a fractional CTO Ask these questions before you sign: For context on our side: James DeCrescenzo Jr. founded JR Secure Design in 2020. Before that, he owned and ran Internet Area Network for 16 years, an early cloud and internet data storage pioneer that built data centers, and then sold the company. Our team brings 25+ years of experience and more than 1,000 projects across government, healthcare, finance, telecom, retail, and startups. We work with founders nationwide from our home base in Fort Lauderdale, Florida. Alongside fractional CTO leadership, JR Secure Design offers other fractional C-suite advisors as a member of your team—including fractional CMO, CSO (Chief Savings Officer), CFO (Chief Fundraising Officer), CAO, and COO—plus Private AI for business and an AI Strategic Advisor platform with 50+ AI agents. See our services for the full picture. Frequently asked questions What is a fractional CTO? A fractional CTO is a senior technology executive who works with a company part-time, usually on a monthly retainer. They provide CTO-level strategy, architecture, security, and vendor oversight without the cost of a full-time executive hire. How much does a fractional CTO cost? Market rates vary by scope. Go Fractional’s October 5, 2026 benchmark shows an average of about $211 per hour and roughly $9,600 to $15,000 per month for about 15 hours a week. JR Secure Design offers a free first month, then tiers from $99 to $9,700 per month, plus a BOOM tier (contact us for details). What is the difference between a fractional CTO and a full-time CTO? A full-time CTO is a salaried employee dedicated to your company. A fractional CTO provides the same level of leadership part-time and on a flexible retainer. Fractional usually fits pre-seed, seed, and small or midsize businesses; full-time fits once you have a sizable engineering team and the budget

Pitch Deck Competition: October 28 at 8 PM ET

Startup founder presenting a pitch deck to fractional C-suite advisors at the JR Secure Design pitch deck competition

JR Secure Design is hosting a pitch deck competition on Wednesday, October 28, 2026 at 8:00 PM Eastern (EDT). Startup founders: submit your PDF deck via our Startups page for feedback from fractional C-suite advisors and AI strategic review.

© 2026 All Rights Reserved.