Free Tool

Shadow AI Risk Calculator

Answer seven questions and get your estimated annual financial exposure to shadow AI in dollars, the regulatory penalties you are exposed to, your control gaps, and the recommended next steps. Grounded in IBM breach-cost data and real HIPAA, GDPR, PCI, and CCPA penalties. Runs entirely in your browser. No inputs leave your device.

How the estimate works

Methodology

The headline figure is a modeled expected annual loss: the estimated likelihood of a shadow-AI-driven data incident in the next year, multiplied by the estimated cost if one occurs.

Likelihood runs from about 8% per year when all five foundational controls are in place, up to a cap of 40% for an unprotected organization in a regulated industry. This is anchored to IBM’s 2025 Cost of a Data Breach Report, which found 20% of breaches involved shadow AI and that 97% of AI-related breaches hit organizations lacking AI access controls.

Cost per incident combines a breach-remediation figure — anchored to IBM’s $4.63M average for breaches where shadow AI was involved, scaled by organization size — with a conservative regulatory-penalty figure for your industry. The penalty figures sit well below the statutory maxima (HIPAA up to ~$2.1M per violation category per year; GDPR up to 4% of global turnover; PCI $5K–$100K per month); those maxima are what appears in the penalty list, while the expected-loss math uses the lower, settlement-scale numbers.

The five controls assessed — written AUP, technical monitoring, blocking of sensitive data, AI vendor inventory with DPAs, and employee training — map cleanly to SOC 2 CC6.1 / CC7.2 / CC9.2 and to HIPAA and GDPR equivalents. The secondary control-maturity score summarizes how many of them are missing.

This is a directional estimate built from published averages, not a formal audit or an actuarial prediction of your specific loss. Use it to size the risk and prioritize your roadmap. For a formal assessment, consult a qualified auditor or your cyber-insurance underwriter.

Sources

Frequently asked

Calculator FAQ

What is a shadow AI risk assessment?

A shadow AI risk assessment evaluates an organization's exposure to data leakage and compliance failures from employee use of unsanctioned AI tools. This calculator turns that exposure into a dollar figure: it estimates how likely a shadow-AI-driven data incident is in your environment (driven by org size, industry, and how many of five foundational controls you have) and what such an incident would cost (breach remediation plus regulatory-penalty exposure for your industry).

How is the financial exposure estimate calculated?

Expected annual exposure = the modeled annual likelihood of a shadow-AI-driven data incident multiplied by the modeled cost of that incident. The likelihood runs from about 8% per year (all five controls in place) up to a cap of 40% (no controls, regulated industry), grounded in IBM's 2025 finding that 20% of breaches involved shadow AI and 97% of AI-related breaches hit orgs lacking AI access controls. The incident cost combines a breach-remediation figure anchored to IBM's $4.63M shadow-AI-involved average (scaled by org size) with a conservative regulatory-penalty figure for your industry (HIPAA, PCI, GDPR, CCPA). The result is shown as a range because it is directional, not a point prediction.

Are these dollar figures a guarantee of what a breach would cost us?

No. They are a modeled, directional estimate built from published averages (IBM, HHS, GDPR, PCI, CCPA), not a prediction of your specific loss. Actual cost depends on the data involved, the number of records, your jurisdiction, and your response. Use the figure to size the risk for a board conversation and to prioritize which controls to close first, not as an actuarial number. For a formal assessment, consult a qualified auditor or your cyber-insurance underwriter.

What penalties could we actually face from shadow AI?

It depends on your industry and the data involved. Healthcare faces HIPAA civil penalties up to roughly $2.1M per violation category per year plus corrective action. Any organization holding EU personal data faces GDPR fines up to €20M or 4% of global turnover. Card-handling businesses face PCI fines of $5,000–$100,000 per month. California residents' data triggers CCPA penalties up to $2,500 per record ($7,500 if intentional). The calculator lists the specific regimes you are exposed to alongside your estimate.

How do we lower our exposure?

Close the five control gaps in order: written policy first (low effort, high impact), then technical monitoring, then blocking of the highest-risk data categories, then vendor inventory with DPAs, then training. The calculator shows how much modeled annual exposure each set of controls removes. ShadowLock customers typically move from critical to moderate within a single quarter.

Does this calculator store my inputs?

No. The entire calculation runs in your browser. No inputs are sent to ShadowLock or any third party. Refresh the page and the inputs are gone. Feel free to use it for sensitive internal risk conversations.

From exposure to a working program

Knowing the dollar figure is the first step. ShadowLock closes the technical control gap, in under an hour.