AI Governance · Shadow AI
You can't govern the AI tools you don't know exist.
A 2023 leak, a 2026 SEC filing, and a supply-chain breach through a browser extension all trace back to the same gap: AI tools employees adopted that security never approved — and in most cases never even knew existed. A look at how widespread that gap actually is, the market racing to close it, and the guardrails that would have caught each incident before data left the building.
THE EVIDENCE · THREE INCIDENTS, ONE PATTERN
This didn't start as a theory
Three documented incidents across three years and three failure patterns, all tracing back to a tool nobody approved.
2023 · Samsung ChatGPT leaks. Within twenty days of allowing staff to use ChatGPT, Samsung's semiconductor division suffered three separate confidential data leaks — source code pasted in while debugging, an internal meeting transcript turned into notes, and code used to optimize chip-yield testing. Samsung banned generative AI company-wide days later.
— per Bloomberg and multiple contemporaneous reports
April 2026 · Vercel breach via a browser extension. An employee had self-adopted a consumer-grade AI browser extension — Context.ai — under a corporate identity, entirely outside any sanctioned deployment. When the vendor was breached, attackers moved downstream into Vercel, pulled customer environment variables nobody had flagged as sensitive, and used the data to fuel an extortion campaign on BreachForums.
— per Security Affairs and public breach disclosures
May 2026 · CB Financial Services SEC filing. An employee ran non-public customer data — names, Social Security numbers, dates of birth — through an AI application the bank had never approved. CB Financial filed the first-ever SEC Form 8-K triggered by unauthorized employee AI use rather than a cyberattack, even while disclaiming any financial loss.
— per SEC filings and legal analysis
Three incidents, three failure patterns — direct leakage, supply-chain compromise, regulatory exposure — and one identical root cause: a tool adopted outside every review process security relies on to know it exists.
— the pattern across all three