A quick, directional sense of the exposure you're carrying by running AI without governance — so you can decide how urgent this is.
Five inputs. You'll get a directional figure and the main drivers behind it.
Estimated annual exposure from ungoverned AI
How this figure is calculated — and the basis for it
Expected annual exposure = likelihood of an AI-related incident × the typical cost of an SMB incident. Likelihood starts near 8%/year — about 40% of small businesses are attacked each year, and roughly 20% of breaches now involve “shadow AI” (40% × 20% ≈ 8%). It rises with ungoverned tools and no policy, and falls when governance is in place. Cost per incident is placed inside Verizon's documented typical-SMB range of $120,000–$1.24M, scaled by your headcount, data sensitivity, and regulation. The exact likelihood and incident cost used for your number are shown in the line above.
Sources: Verizon 2025 Data Breach Investigations Report — typical SMB incident range and annual attack rate · IBM Cost of a Data Breach 2025 — shadow-AI breaches cost ≈ $670K more, ~20% of breaches involve shadow AI, 63% of organizations have no AI governance.
Note on bias: IBM and most breach-cost publishers are security vendors with an interest in larger figures — so this model deliberately anchors on Verizon's lower, incident-level SMB range and a conservative likelihood. It aims to under- rather than over-state.
A 45-minute session to pressure-test these numbers against your actual operations and prioritize where to start.
Directional estimate for prioritization, not a formal risk quantification. Real exposure depends on facts unique to your business.
This site uses privacy-friendly Google Analytics to understand anonymous traffic and tool usage. No personal data, and nothing you type into the tools is tracked. See our privacy note.