Shadow AI Adds $670K To Breach Costs. Employees Will Use Whatever They Want. Set Guardrails.
An article from Innovative Human Capital frames AI adoption for small businesses around the tension between personal service and response speed. It cites a specific figure: breaches increase by $670,000 when unmanaged shadow AI usage is high. The recommended approach is to document rules for tasks like priority callback suggestions, test results across customer groups, and keep a human employee in charge of final routing decisions.
The underlying principle is that unmanaged tool adoption creates systemic risk that dwarfs the productivity gains. The mechanism is shadow IT, which is when employees use unsanctioned tools because the sanctioned ones are too slow or absent. The lesson: you cannot prevent usage, but you can constrain it with documented rules and human checkpoints. Governance is cheaper than breach remediation.
Innovative Human Capital, publishing advice for small business owners. The $670,000 breach cost figure is cited but no specific company examples or named practitioners are provided.
- Write a one-page AI usage policy that lists three allowed tools, three prohibited uses, and one rule for when a human must review AI output before it reaches a customer.
- Ask ChatGPT to draft a priority callback rule for your customer base, something like "customers who mention a deadline in their subject line get called within 2 hours."
- Apply that rule to 15 recent customer emails, mark which ones the rule would have correctly prioritized, and assign one team member as the final human approver before any routing happens.