Security

As data breaches grow costlier, ungoverned AI creates new risks

IBM says average cost of an incident jumped 12% over 2025
Pro
Image: Miguel Á. Padriñán via Pexels

31 July 2026

Half of organisations that experienced a data breach in 2025 are using AI agents to hunt for threats, but fewer than one in five of those organisations are using agents for the task for which they’re most suited: scanning for and managing vulnerabilities on a network.

That data point comes from IBM’s 2026 Cost of a Data Breach Report, which also found that 85% of breached organisations plan to spend more money on “security tools and governance”.

The report also covered businesses’ use of AI agents in security operations centres, organisations’ post-quantum cryptographic migrations and ways to reduce breach costs.

 

advertisement



 

Data breaches now cost businesses an average of $5 million, according to the new report, a 12% increase over the figure from IBM’s 2025 research. Some attacks on AI tools cost businesses much more – inversion and prompt-injection attacks cost organisations an average of roughly $6 million.

“Unlike traditional exploits that compromise systems, these behavioural attacks undermine how AI models reason and respond,” IBM researchers wrote, “expanding remediation beyond technical recovery into trust and governance.”

The vast majority (92%) of organisations that suffered attacks on their AI models failed to properly control access to those tools, even as businesses describe identity management as one of their best defences against costly breaches. Only four in 10 organisations said they limited access to their AI systems.

Identity controls “have failed to keep pace” with AI’s sprawl across corporate networks, IBM researchers said. “The outcome is predictable: expanded attack paths, higher financial impact and incidents driven by basic enforcement gaps that don’t even require attacker sophistication.”

Even as AI increasingly attracts corporate executives’ attention, basic cybersecurity principles still define the attack landscape. On-premises systems experienced more breaches than private cloud, public cloud, or hybrid environments, and most victims failed to encrypt their data, making it more attractive to thieves.

Governance is the missing piece when it comes to AI, according to the report, whose findings echoed a long line of research showing that companies are adopting AI before they know how to manage it. The share of security incidents involving shadow AI more than doubled year over year, to 43%, with the average cost of those breaches also increasing. More than two-thirds of organisations said they didn’t have governance processes in place to limit shadow AI, a slight uptick from the 2025 figure.

IBM’s report was based on a study of 602 organisations that experienced data breaches between March 2025 and February 2026, with respondents representing 17 industries in 16 countries.

Cybersecurity Dive

Read More:


Back to Top ↑