Verizon's 2026 Data Breach Investigations Report, published May 19 and built on 2025 incident data, found that employee use of unapproved AI tools jumped from 15% to 45% in a single year, making shadow AI the third most common source of non-malicious data leakage the report tracks. The same report found breaches involving a third party climbed 60% year over year to 48% of all confirmed breaches. California's ADMT risk assessment rule asks a business to name every automated tool that makes a significant decision about a person and document what it does with their data. It has no line for the free resume-screening tool a hiring manager found last month and never mentioned to IT.
This is a builder's read, not legal advice. Your counsel decides what your risk assessment has to cover. This is what the inventory it depends on is actually missing.
What the risk assessment already requires
Most coverage of California's privacy rules points at January 1, 2027, when Article 11 gives consumers the right to notice, opt-out and access for automated decisionmaking technology (ADMT) used on a significant decision. Article 10 moves faster. It requires a risk assessment before a business processes personal information in a way that presents significant risk, and using ADMT for a significant decision, one that affects employment, housing, lending, healthcare access or a similar outcome, is one of the triggers the regulations name. That obligation took effect January 1, 2026, a full year ahead of the consumer rights everyone is watching.
The recordkeeping isn't casual. Under California's privacy regulations (Cal. Code Regs. tit. 11), a business has to retain each risk assessment, original and every updated version, for as long as the processing continues or five years after completion, whichever is later. Starting with the first attestation cycle in 2028, a business has to certify annually, under penalty of perjury, that the assessments got done. An attestation under oath about an inventory nobody actually built is not the kind of gap you want discovered by an auditor rather than by your own team.
Shadow AI is the blind spot the rule doesn't anticipate
Verizon's own language for the trend is blunt: "Shadow AI, referring to employees using unapproved AI tools at work, is now the third most common non-malicious data leakage-related activity," and usage rose from 15% to 45% of employees in the twelve months the 2026 report covers. The tools people reach for are the ones nobody procured: a browser extension that drafts email, a free tool that flags resumes worth a second look, a note-taking bot that joins a call and summarizes it against a candidate's answers. None of that shows up in a vendor list built from contracts and purchase orders, because no contract or purchase order exists.
Most shadow AI isn't ADMT, and it's worth saying plainly rather than treating every unsanctioned tool as a compliance event. Summarizing a meeting isn't a significant decision about anyone. The exception is the one that matters for this rule: a tool an employee adopts on their own that screens, scores or ranks people, resumes, tenants, loan applications, becomes ADMT the moment it drives a real outcome, whether or not anyone in legal or IT signed off on it. A risk assessment built from procurement records will miss precisely that tool, because procurement never saw it arrive.
A vendor gap is now a breach statistic, not just a paperwork one
The 48% third-party figure and the shadow AI figure are describing the same blind spot from two directions. Verizon reported third-party involvement in breaches up 60% year over year, with most of the high-profile incidents tracing back to authentication failures rather than novel exploits: missing multi-factor enforcement, credentials that were never rotated, access nobody revoked when a project ended. A tool an employee signed up for with a work email and no security review is exactly the kind of access that shows up in that count. It has none of the cooperation terms a vetted vendor's contract would carry, the kind that require a vendor to support a business's own risk assessment and cybersecurity audit under Article 4 of the same regulations. Nobody negotiated those terms because nobody knew there was a vendor to negotiate with.
A worked example
Picture a 180-person regional lender that licenses an underwriting model from a vetted vendor, with a signed contract, a completed risk assessment and a clean line in the compliance register. A branch manager separately starts using a free AI tool to pre-screen loan applications for missing documents and obvious red flags before routing them to underwriters, and finds it saves real time. The tool never goes through security review. It isn't in the vendor contract inventory. It is, within a few weeks, quietly influencing which applications get flagged for closer scrutiny and which sail through, which is a significant decision the moment it changes who gets escalated or delayed.
When compliance builds the year's Article 10 risk assessment, the underwriting vendor is on it. The browser tool isn't, because nobody told compliance it existed, and the branch manager never thought of a browser tab as something that needed disclosing. The gap surfaces later, in an audit, a rejected applicant's complaint, or a breach notice tracing back to an account nobody remembered existed. Either way, the attestation the lender files under Article 10 was true of the register it built and false of what was actually processing applicant data.
What actually closes the gap
- Ask people directly. A single sign-on log or a network scan misses most browser-based AI tools, because they run through a personal login on a company laptop and never touch the identity provider.
- Treat "does it screen, score or rank a person" as the trigger question for the inventory, not "did we buy it." Ownership and procurement are irrelevant to whether a tool counts as ADMT.
- Don't inflate the scope. A shadow AI tool used only for drafting or summarizing internal work is a data-security question, not an ADMT-inventory gap, and treating every unsanctioned tool as a compliance event burns a compliance team's time on the wrong artifact.
- This sits upstream of what actually goes in a risk assessment and what counts as ADMT in the first place. Once a tool is confirmed in scope, the vendor relationship still needs the contract terms California's rules now require, which an unvetted shadow tool almost never has.
If your compliance team is building this year's risk assessment from a vendor contract list and you're not sure it matches what your employees are actually using, that's a short, concrete conversation. Tell us what the discovery process looks like today and we'll tell you where the gap probably is, or get in touch to talk through a specific tool.
Sources
- Verizon: 2026 Data Breach Investigations Report key findings
- California Privacy Protection Agency: CCPA updates, cybersecurity audits, risk assessments, ADMT and insurance regulations