The IBM Cost of a Data Breach Report 2026 reveals that 92 percent of organisations suffering AI security incidents failed to implement basic access controls. This finding comes from research by the Ponemon Institute involving 602 companies. The breach rarely originates from the AI model itself. Instead, one in five affected firms experienced an entry point through a compromised API, a connected application, or a misconfigured cloud service. The type of model used, whether open-source or proprietary, made almost no difference to the outcome.
The financial impact of these oversights is significant. Incidents involving AI cost an average of $5.33 million, which is higher than the $4.70 million average for breaches without an AI component. When attackers themselves employed AI tools, costs jumped to $6.04 million. The global average for all data breaches rose 12 percent to $4.99 million. These figures highlight that sophisticated attacks are not always the primary driver of loss. Fundamental security gaps allow attackers to exploit systems easily.
- Most breaches stem from misconfigured cloud services or compromised APIs
- AI-related incidents cost $5.33 million on average
- Attacks using AI tools cost $6.04 million on average




