Insider risks are taking a huge financial toll, hitting firms with average losses of $19.5 million last year, a 20% cost spike over two years that has hit hardest at those still lacking basic controls, according to new research from DTEX.
The behavioural intelligence firm’s 2026 Cost of Insider Risks Global Report, produced alongside the Ponemon Institute, found that businesses saw an average of twenty-five insider incidents in 2025, amounting to almost 7,500 separate breaches across the 354 firms polled.
The report found that negligence was the cause of the highest losses, with costs reaching $10.3 million annually – a 17% year-over-year increase – compared to the $4.7 lost to malicious risks such as corporate espionage, fraud, or data theft.
Firms reported an average of around fourteen insider incidents triggered by employee negligence, each costing companies more than $747,000, with containment representing the highest costs at $247,587 per incident, far exceeding escalation costs of $39,728.
However, DTEX argues that these breaches are provoked less by complacency than by the increasingly complex digital environment staff now find themselves in, where misjudgments, process gaps, and unmanaged workflows can quickly spiral into major security issues.
The crux of the problem, according to the study, is employees’ overreliance on unauthorised, shadow AI.
DTEX found that while 92% of organisations report that genAI has changed how their employees access and share information, only 13% have formally integrated these AI workflows into their business strategies, and just 18% have fully integrated AI governance into their insider risk programs.
At the same time, 73% worry that unauthorised AI use is creating invisible paths for data exfiltration. For instance, firms reported that their staff regularly use sensitive internal documents, including legal materials, source code, architecture diagrams, and strategy as prompts for generic AI tools like ChatGPT, Claude, Gemini, Perplexity, and even Grok.
Employees’ willingness to trust these tools comes despite evidence that their chats could become accessible to others due to accidental public indexing or platform design flaws, as was the case with both ChatGPT and Grok last year.
At the same time, employees are using AI notetakers to produce publicly accessible recordings and summaries, which can contain sensitive internal discussions and personally identifiable information regarding other staff – a potential data breach that could land a big fine from the ICO.
While DTEX stressed that this shadow AI use falls short of malice, well-intentioned workers have become dependent on unsanctioned tools. When ChatGPT was restricted, employers said those using it simply migrated to Gemini, Perplexity, or agentic AI browsers.
Recommended reading
- Critical Blindspots in GenAI Adoption CIOs Must Address
- 69% of C-Suite Leaders Choose Fast AI Over Secure AI
- ‘Shadow AI’ Use Is Threatening Enterprise Data Security
AI agents are emerging as another blind spot, with 44% of firms agreeing malicious use of AI agents will increase data theft risk, but nearly half reported minimal or no visibility into agent activity, while just 19% classify AI agents as equivalent to human insiders.
“Today, too few organisations classify AI agents as equivalent to human insiders, even as those agents operate with delegated authority, persistence, and reach,” said Marshall Heilman, DTEX CEO.
“As a result, insider risk management and AI agent security are quickly converging. The same behavioural visibility and accountability that protect against insider risk must extend to AI systems.”





