Skip to content
← Back to Insights Cybersecurity

Insider threats and shadow AI: what IT leaders should know

SysGroup · · 4 min read
IT security professional reviewing data activity alerts on a laptop screen, representing insider threat and shadow AI monitoring.

In the first half of 2026, the Identity Theft Resource Center tracked 21 insider wrongdoing incidents. In all of 2025, there were three. That’s not a gradual rise, it’s a different threat altogether, and the ITRC points to two drivers: tech-sector layoffs and nation-state recruitment schemes targeting employees with access to sensitive systems.

For IT and security leaders already stretched thin on ransomware, patching and compliance, insider risk has always been the uncomfortable one. It’s harder to build a perimeter around a person than a network. And in 2026, that person has a new tool: generative AI.

Netwrix’s 2026 Data and Identity Security Report found that only 20% of organisations fully monitor or govern employee use of shadow AI, and just 21% have full visibility into which sensitive data flows into AI tools, models and copilots. IBM’s 2025 Cost of a Data Breach Report puts a price on that blind spot: breaches involving high levels of shadow AI cost an extra $670,000 on average, and 63% of the organisations studied had no AI governance policy at all. The distance between “using it” and “watching it” is where most of the damage happens.

What shadow AI looks like inside your business

Shadow AI is an employee pasting a client contract into ChatGPT to summarise it, an analyst uploading a customer list to a tool that promises faster segmentation, a developer feeding proprietary code into an assistant with no enterprise data controls. None of it has to be malicious. Almost all of it is invisible to a security team still watching data the way it did in 2023, at the email gateway and on the endpoint, and nowhere else.

What real visibility looks like

The technology to close this gap has moved fast. The current generation of data loss prevention and insider risk tooling tracks movement across email, endpoint, cloud, browser and now AI agents, and scores that activity for risk rather than relying on blunt, all-or-nothing blocking. Instead of shutting a tool down and pushing staff to find a workaround, it can prompt, warn or ask for justification, and only escalate to a hard block when the behaviour genuinely warrants it.

That’s the technology layer. It only earns its keep when it’s configured against your actual data, your actual policies and your actual risk appetite, and that’s where most DLP programmes stall. We see it often: a tool bought, switched on and left on default settings that either miss real exfiltration or bury the security team in false positives until they stop reading the alerts.

SysGroup’s own data loss prevention work starts there, regardless of what’s already in your estate, whether that’s Microsoft Purview, a CASB, or something else entirely. We discover where sensitive data actually sits, classify it, build policies around how the business really operates, and tune the rules so staff don’t spend their week working around the controls. That last part matters more than the tooling. A DLP platform generating so much noise that your team stops looking at it isn’t protecting anything.

Why insider risk is now a board-level compliance issue

The Cyber Security and Resilience Bill and a separate Ransomware (Reporting) Bill are both moving through Parliament in 2026, and together they push insider risk and data protection out of the IT team’s inbox and into the boardroom. Regulators and auditors increasingly want evidence, not assurances: who had access to what, what left the building, and how quickly you knew about it. A programme that can answer those questions in an audit is doing a different job to one that just ticks a box.

If you don’t currently know whether your organisation’s data is moving into AI tools nobody approved, that’s the first question worth answering, not the last. It’s the conversation we have with IT directors and CISOs most weeks: not “do you have a tool”, but “do you know what’s actually happening to your data today”.

Get in touch at info@sysgroup.com if you want to talk through what visibility looks like for your environment.

S

Written by

SysGroup

insider threatshadow AIdata loss prevention (DLP)insider risk managementinsider threat detection

Want to discuss this topic?

Our team is happy to talk through what this means for your organisation.

Speak to a Specialist