AI News AI资讯 13h ago Updated 11h ago 更新于 11小时前 49

IBM finds 92% of companies hit by AI security breaches lacked basic access controls IBM发现92%遭遇AI安全漏洞的公司缺乏基本访问控制

92% of companies experiencing AI-related security breaches lacked adequate access controls for their AI systems AI-involved incidents cost an average of $5.33 million, exceeding the $4.70 million average for non-AI breaches Attackers leveraging AI drove costs to $6.04 million, compared to $5.03 million without AI assistance Entry points were rarely the models themselves; approximately 20% of incidents originated from compromised APIs, connected applications, or misconfigured cloud services The t IBM 2026年数据泄露报告显示,92%遭受AI安全事件的公司缺乏基本访问控制 AI安全攻击入口多为API、连接应用或配置错误的云服务,而非模型本身 AI相关安全事件平均成本达533万美元,高于非AI事件的470万美元 攻击者使用AI时成本飙升至604万美元,凸显AI安全威胁的严重性 开源与专有模型在安全性上差异不大,核心问题在于基础访问控制缺失

68
Hot 热度
72
Quality 质量
70
Impact 影响力

Analysis 深度分析

TL;DR

  • 92% of companies experiencing AI-related security breaches lacked adequate access controls for their AI systems
  • AI-involved incidents cost an average of $5.33 million, exceeding the $4.70 million average for non-AI breaches
  • Attackers leveraging AI drove costs to $6.04 million, compared to $5.03 million without AI assistance
  • Entry points were rarely the models themselves; approximately 20% of incidents originated from compromised APIs, connected applications, or misconfigured cloud services
  • The type of model (open-source vs. proprietary) had virtually no impact on breach risk

Why It Matters

This finding underscores that AI security failures are predominantly rooted in foundational infrastructure gaps rather than sophisticated model-level vulnerabilities, making them both widespread and preventable. For AI practitioners and security teams, it signals that investing in basic access controls and cloud configuration hygiene delivers outsized returns in risk reduction. The cost differential also makes a compelling business case for prioritizing AI-specific security governance.

Technical Details

  • Study scope: IBM's Cost of a Data Breach Report 2026, conducted by the Ponemon Institute across 602 companies globally.
  • Access control gap: 92% of firms with AI-related incidents had inadequate access controls, indicating a systemic deficiency rather than an isolated problem.
  • Attack vectors: Roughly 20% of breaches entered through compromised APIs, connected applications, or misconfigured cloud services — not through the AI models directly.
  • Cost breakdown: AI-involved breaches averaged $5.33M vs. $4.70M for non-AI breaches; when attackers used AI tools, costs rose to $6.04M vs. $5.03M without AI.
  • Model type irrelevance: Open-source and proprietary models showed no meaningful difference in breach likelihood, suggesting the threat landscape is agnostic to model provenance.

Industry Insight

  • Organizations should treat AI access control as a non-negotiable baseline, not an optional enhancement — the 92% failure rate indicates this is an industry-wide blind spot that attackers are actively exploiting.
  • Security budgets should prioritize API governance, cloud configuration audits, and application-layer hardening, as these represent the most common entry points rather than model-level defenses.
  • The cost premium associated with AI-assisted attacks ($6.04M) suggests that defensive AI capabilities and threat detection systems should also be considered, as the attack surface is evolving faster than many organizations' security postures.

TL;DR

  • IBM 2026年数据泄露报告显示,92%遭受AI安全事件的公司缺乏基本访问控制
  • AI安全攻击入口多为API、连接应用或配置错误的云服务,而非模型本身
  • AI相关安全事件平均成本达533万美元,高于非AI事件的470万美元
  • 攻击者使用AI时成本飙升至604万美元,凸显AI安全威胁的严重性
  • 开源与专有模型在安全性上差异不大,核心问题在于基础访问控制缺失

为什么值得看

这份报告揭示了AI安全领域的关键盲区——企业往往过度关注模型本身的安全性,却忽视了基础的访问控制和API安全管理。对于AI从业者而言,这是一次重要的警示:AI安全威胁正在快速演变,且成本远高于传统数据泄露。

技术解析

  • 访问控制缺失是首要因素:92%的受影响企业缺乏基本的AI系统访问控制机制,这是导致AI安全事件的核心原因
  • 攻击向量分析:约20%的案例通过API、连接应用或配置错误的云服务入侵,而非直接攻击模型本身
  • 成本对比数据:AI事件平均533万美元 vs 非AI事件470万美元;攻击者使用AI时成本达604万美元 vs 503万美元
  • 模型类型无关性:开源与专有模型在安全性上差异不大,基础安全措施才是关键
  • 研究规模:基于Ponemon研究所对602家公司的调研数据

行业启示

  • 安全策略需重新聚焦:企业应将AI安全投入从模型层面向基础设施层(API管理、访问控制、云配置)转移
  • AI安全成本正在攀升:攻击者利用AI工具使安全事件成本增加约20%,行业需建立针对性的防御机制
  • 基础安全被忽视:大多数AI安全事件源于"不需要 sophisticated attackers 就能利用"的基本疏忽,企业应优先完善基础安全措施

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究