IBM finds 92% of companies hit by AI security breaches lacked basic access controls
92% of companies experiencing AI-related security breaches lacked adequate access controls for their AI systems AI-involved incidents cost an average of $5.33 million, exceeding the $4.70 million average for non-AI breaches Attackers leveraging AI drove costs to $6.04 million, compared to $5.03 million without AI assistance Entry points were rarely the models themselves; approximately 20% of incidents originated from compromised APIs, connected applications, or misconfigured cloud services The t
Analysis
TL;DR
- 92% of companies experiencing AI-related security breaches lacked adequate access controls for their AI systems
- AI-involved incidents cost an average of $5.33 million, exceeding the $4.70 million average for non-AI breaches
- Attackers leveraging AI drove costs to $6.04 million, compared to $5.03 million without AI assistance
- Entry points were rarely the models themselves; approximately 20% of incidents originated from compromised APIs, connected applications, or misconfigured cloud services
- The type of model (open-source vs. proprietary) had virtually no impact on breach risk
Why It Matters
This finding underscores that AI security failures are predominantly rooted in foundational infrastructure gaps rather than sophisticated model-level vulnerabilities, making them both widespread and preventable. For AI practitioners and security teams, it signals that investing in basic access controls and cloud configuration hygiene delivers outsized returns in risk reduction. The cost differential also makes a compelling business case for prioritizing AI-specific security governance.
Technical Details
- Study scope: IBM's Cost of a Data Breach Report 2026, conducted by the Ponemon Institute across 602 companies globally.
- Access control gap: 92% of firms with AI-related incidents had inadequate access controls, indicating a systemic deficiency rather than an isolated problem.
- Attack vectors: Roughly 20% of breaches entered through compromised APIs, connected applications, or misconfigured cloud services — not through the AI models directly.
- Cost breakdown: AI-involved breaches averaged $5.33M vs. $4.70M for non-AI breaches; when attackers used AI tools, costs rose to $6.04M vs. $5.03M without AI.
- Model type irrelevance: Open-source and proprietary models showed no meaningful difference in breach likelihood, suggesting the threat landscape is agnostic to model provenance.
Industry Insight
- Organizations should treat AI access control as a non-negotiable baseline, not an optional enhancement — the 92% failure rate indicates this is an industry-wide blind spot that attackers are actively exploiting.
- Security budgets should prioritize API governance, cloud configuration audits, and application-layer hardening, as these represent the most common entry points rather than model-level defenses.
- The cost premium associated with AI-assisted attacks ($6.04M) suggests that defensive AI capabilities and threat detection systems should also be considered, as the attack surface is evolving faster than many organizations' security postures.
Disclaimer: The above content is generated by AI and is for reference only.