HomeFree Tools › Cost-of-Inaction Estimator

Cost-of-Inaction Estimator

A quick, directional sense of the exposure you're carrying by running AI without governance — so you can decide how urgent this is.

What is ungoverned AI costing you?

Five inputs. You'll get a directional figure and the main drivers behind it.

Estimated annual exposure from ungoverned AI

How this figure is calculated — and the basis for it

Expected annual exposure = likelihood of an AI-related incident × the typical cost of a business incident. Likelihood starts near 17%/year — about 40% of small businesses face a cyberattack each year, and 43% of breaches now involve “shadow AI” — more than double a year ago (40% × 43% ≈ 17%). It rises with ungoverned tools and no policy, and falls when governance is in place. Cost per incident is placed inside Verizon's documented typical-business range of $120,000–$1.24M, scaled by your headcount, data sensitivity, and regulation. The exact likelihood and incident cost used for your number are shown in the line above.

Sources: Verizon 2026 Data Breach Investigations Report — business attack exposure and typical incident range · IBM Cost of a Data Breach 2026 — 43% of breaches involve shadow AI (more than double the prior year), close to 70% of breached organizations lack AI governance, AI-driven attacks cost ≈ $1M more, and the global average breach reached $4.99M.

Note on bias: IBM and most breach-cost publishers are security vendors with an interest in larger figures — so this model deliberately anchors on Verizon's lower, incident-level business range and a conservative likelihood, and ignores IBM's much larger $4.99M average. It aims to under- rather than over-state.

Illustrative only. This figure is a rough, directional model meant to prompt a conversation and prioritize effort — not an actuarial calculation, a prediction of loss, or a guarantee of any outcome. Actual exposure depends on facts unique to your business.

Turn this estimate into a plan

A 45-minute session to pressure-test these numbers against your actual operations and prioritize where to start.

Directional estimate for prioritization, not a formal risk quantification. Real exposure depends on facts unique to your business.

Build a plan to close the gap →