IBM Says AI-Enabled Breaches Cost Companies $6 Million on Average
- Martin Chen

- 3 hours ago
- 12 min read
IBM put AI security at the center of google news after finding that more than 20% of studied organizations suffered breaches targeting AI models or applications. The headline figure is unsettling, but it captures only half the conflict. Attackers are also using AI to make conventional intrusions faster, cheaper, and harder for defenders to contain.
IBM’s 2026 breach report separates those two problems. One concerns attacks against AI systems, including their APIs, plug-ins, cloud workloads, models, and training data. The other concerns AI-enabled attacks, where criminals use deepfakes, malware, or automated workflows against a broader target.
That distinction matters because the most quoted numbers describe different groups. In its official announcement of the findings, IBM says one in four malicious breaches were AI-enabled, a 56% increase from the previous year. Separately, more than 20% of organizations reported a breach that targeted an AI model or application.
The United Kingdom results add another measure. According to reporting on the study, 22% of UK companies experienced an AI-related security breach during the preceding year. Treating all three percentages as interchangeable would exaggerate what the research establishes.
The deeper finding is harder to dismiss. Enterprise AI has created more identities, interfaces, data flows, and automated actions for security teams to govern. Attackers do not always need to compromise the model itself. They can exploit the ordinary systems surrounding it.
That makes this a contest between rapid AI deployment and the slower work of establishing control. The same technology also strengthens defense, giving organizations a reason to deploy more AI rather than retreat from it.
What IBM’s 2026 Numbers Actually Show
AI now appears on both sides of the breach equation, as a target for attackers and as an instrument they use.
IBM released its 2026 Cost of a Data Breach Report on July 29. Ponemon Institute conducted the underlying research, while IBM sponsored and analyzed it. The dataset covers breaches experienced by 602 organizations worldwide between March 2025 and February 2026.
The report places the global average breach cost at $4.99 million. That represents a 12% annual increase and a record for the study. IBM attributes the rise to higher detection, escalation, and lost-business costs.
AI-enabled malicious breaches were more expensive still. IBM reports an average cost of $6 million, about $1 million above the overall global figure. These incidents represented one in four malicious breaches and increased 56% from the previous year.
AI-enabled means the attacker used AI during the operation. Deepfake impersonation was the most frequently reported form, appearing in 45% of this category, according to the UK-focused coverage. AI-enabled malware and phishing also contributed to the increase.
Attacks targeting AI systems form a related but separate category. More than 20% of organizations reported a breach aimed at an AI model or application. The most common entry points were not exotic attacks on model mathematics.
Compromised APIs, applications, or plug-ins accounted for 27% of the reported causes. Cloud misconfigurations affecting AI workloads also accounted for 27%. The symmetry points toward a familiar security problem: new AI services often inherit old weaknesses in access, integration, and infrastructure management.
An API, or application programming interface, lets software systems exchange requests and data. A plug-in gives an application access to another service or capability. Both can become high-value pathways when an AI application receives broad permissions or handles sensitive corporate information.
The initial coverage also highlighted the UK results. It reported that 22% of UK firms experienced an AI-related security breach in the previous year. The average UK breach cost fell from £3.29 million in 2025 to £3.13 million in 2026, even as the reported breach count increased from 29,000 to 29,870.
Those national figures complicate the global story. Breaches became more frequent in the UK sample, but their average cost declined. Financial services still faced an average of £5.46 million, while energy companies averaged £4.03 million.
The point is not that every fifth breach everywhere has the same cause. IBM’s research uses several overlapping measures across global and national samples. The defensible conclusion is that AI-related exposure is no longer an edge case within enterprise security.
Why the Google News Headline Needs Careful Reading
The phrase “AI-related breach” covers several distinct events, and each one demands a different defensive response.
A reader finding the story through google news might reasonably assume that criminals directly hacked an AI model in one out of every five breaches. IBM’s data does not support that simplified interpretation.
An organization can experience an attack targeting its AI system. An attacker can use AI against a conventional system. An employee can expose data through an unauthorized AI service. Those events overlap, but they are not identical.
This measurement problem is more than a technical caveat. It determines which controls an organization needs and where security teams should place their limited attention.
A model-targeting attack can pursue training data, credentials, prompts, or confidential information available through retrieval systems. It can also manipulate a model’s inputs or exploit excessive permissions granted to an autonomous agent.
An AI-enabled attack uses the technology on the attacker’s side. A deepfake voice call can impersonate an executive. Generative tools can help produce convincing phishing messages, translate lures, or adapt malware more quickly.
Shadow AI creates a third path. The term describes AI tools used without formal approval, visibility, or governance. Employees might paste customer records into a consumer chatbot, install an unreviewed browser extension, or connect a meeting assistant to internal documents.
IBM’s 2025 research on the AI oversight gap provides useful historical context. It found that 13% of studied organizations had experienced a breach involving an AI model or application. Another 8% did not know whether such a compromise had occurred.
Among organizations reporting an AI-related compromise, 97% lacked appropriate AI access controls. Sixty percent of those incidents compromised data, while 31% caused operational disruption.
The same research found that one in five organizations reported a breach connected to shadow AI. Organizations with high levels of shadow AI experienced $670,000 more in average breach costs than those with little or none.
Governance was already lagging. Sixty-three percent of breached organizations either had no AI governance policy or were still developing one. Among those with a policy, only 34% regularly audited for unauthorized AI use.
These earlier results make the 2026 increase more plausible. Companies spent another year connecting models to data, applications, and business processes. Many started from a weak control baseline.
However, the year-to-year comparison still needs caution. IBM introduced deeper AI measurements recently, and changing definitions can affect reported prevalence. Better detection can also make the problem appear to grow because organizations finally recognize incidents that previously went unclassified.
IBM’s sample deserves the same scrutiny applied to any breach-cost study. It covers organizations that experienced breaches, not a random census of every business. Its averages should not be read as a prediction of what a specific company will lose.
The research is nevertheless valuable because it exposes recurring patterns. AI incidents cluster around weak access controls, insecure integrations, cloud configuration errors, and poor visibility. Those are actionable findings even when the headline percentage requires context.
AI Makes Attacks Cheaper While Defense Remains Expensive
The central tradeoff is economic: attackers can automate more of their work, while defenders still pay for investigation, containment, recovery, and lost business.
IBM describes AI as changing the economics of cyber risk. The technology can reduce the labor needed to build a lure, impersonate a trusted person, or test variations of an attack. The victim still faces the full organizational cost of responding.
Mark Hughes, global managing partner for IBM Cybersecurity Services, said advanced frontier models let attackers execute operations “in minutes rather than days.” The claim reflects IBM’s interpretation of the threat, but the underlying direction is credible even when an exact acceleration rate varies by attack.
Deepfakes illustrate the imbalance. A criminal does not need to reproduce an executive perfectly in every context. The synthetic voice or video only needs to create enough urgency and familiarity to push one employee past a control.
Traditional phishing filters also evaluate messages, links, and known malicious infrastructure. A carefully personalized request delivered through voice, video, or an established collaboration account can bypass those familiar signals.
AI agents increase the stakes on the enterprise side. An agent is software that can plan and perform actions across systems with limited human intervention. It might search documents, update customer records, execute code, or initiate a workflow.
Each action requires an identity and permissions. If an agent receives broad access, a stolen token or manipulated instruction can produce effects beyond a single chatbot response. The security boundary moves from the model interface into every system the agent can reach.
IBM’s report says more than half of organizations used agents for threat detection and containment. Only 18% applied them to vulnerability management. That gap leaves known weaknesses unresolved while attackers gain faster ways to locate or exploit them.
Critical infrastructure carries a disproportionate share of the risk. IBM says 62% of AI-driven attacks in the study targeted critical infrastructure sectors. Financial services and energy recorded the greatest concentrations.
The global average cost for financial-services breaches was $6.3 million. Energy breaches averaged $5.2 million. An incident in either industry can extend beyond the victim through payment networks, suppliers, customers, or essential services.
Ransomware adds another economic pressure. IBM reports that ransomware incidents rose from 34% to 39% of the studied breaches. Attackers increasingly used reputation as leverage, cited in 41% of ransomware cases, followed by employee data at 35% and intellectual property at 31%.
This strategy changes the recovery calculation. Restoring systems does not erase leaked information or reputational damage. A company may contain the technical intrusion while continuing to face notifications, investigations, litigation, and customer losses.
AI can assist with scale, but it does not remove the attacker’s need for access. Credentials, exposed services, unpatched software, and social manipulation remain central. The new tools amplify those routes rather than replacing them.
That is why the primary conflict is not humans against machines. It is rapid automation against fragmented control. Attackers can concentrate their effort on one opening, while defenders must understand every identity, integration, data store, and agent action.
The Same AI Tools Can Cut Breach Costs
IBM’s warning is not an argument against defensive AI because the report also associates extensive security automation with major savings.
Organizations using AI and automation extensively in security operations recorded $1.93 million in average cost savings compared with organizations using none. IBM’s 2025 study reported a similar $1.9 million difference and an 80-day reduction in the breach lifecycle.
A breach lifecycle measures the time needed to identify and contain an incident, including service restoration in IBM’s methodology. Shorter lifecycles can reduce investigation expense, business interruption, and the time available for attackers to move through a network.
The finding creates a genuine tradeoff. Companies need AI-enabled detection to respond at machine speed, but every defensive agent also becomes another identity requiring control. Deployment without inventory, permission limits, and audit trails can create the exposure it is meant to reduce.
Automation works best on tasks with clear evidence and bounded authority. A security system can correlate an unusual login with a suspicious token request, isolate an endpoint, or prioritize a known vulnerability. Those actions become riskier when an agent can change production systems without review.
IBM recommends dynamic, identity-based access controls for agents. In practical terms, an agent should receive only the permissions needed for its current task. Its actions should remain attributable to a responsible person or service, and security teams should be able to reconstruct what happened.
Data controls are equally important. Organizations need to know where sensitive records reside, which models can retrieve them, and where generated outputs travel. Classification and real-time monitoring help connect an AI interaction to the data risk it creates.
Cloud configuration remains a priority because AI workloads rarely operate alone. They depend on object storage, databases, identity services, model endpoints, and third-party APIs. A perfectly secured model cannot compensate for a public data bucket or an exposed administrative credential.
Encryption is another unresolved weakness. Only 37% of breached organizations in IBM’s sample said they encrypted sensitive data both at rest and in transit. Just 34% had visibility into their cryptographic assets.
Those figures sit outside the AI headline, but they show why ordinary controls still matter. AI can accelerate an intrusion, yet the consequences depend on whether data was protected, access was segmented, and abnormal behavior was detected.
Security teams also need an accurate inventory of AI systems. That inventory should include sanctioned models, embedded AI features, agents, service accounts, plug-ins, data connections, and employee-accessible consumer services.
A policy document alone cannot supply that visibility. IBM’s earlier finding that only 34% of organizations with AI governance policies performed regular shadow AI audits illustrates the gap between stated governance and operational enforcement.
The most credible response therefore combines governance with engineering. Policy defines acceptable use and ownership. Technical controls discover systems, restrict permissions, monitor behavior, and preserve evidence.
Incident response exercises should include AI-specific scenarios. A company should know how to revoke an agent’s credentials, disable a compromised integration, preserve prompts and logs, and determine which data the system accessed.
That preparation should not become a blanket ban on AI. Prohibitions can push employees toward less visible tools. Approved alternatives, clear data rules, and usable review processes give employees a safer route while preserving security visibility.
What IBM’s Warning Does Not Prove
The report establishes a serious exposure pattern, but it does not show that AI caused every incident labeled as AI-related.
Security statistics often combine cause, target, and enabling technology. A compromised plug-in surrounding an AI application might involve ordinary credential theft. A cloud misconfiguration might have exposed the same data even if the workload served conventional analytics.
Calling those events AI-related is reasonable because the affected system processes AI workloads. It does not mean the model introduced the original defect.
The same caution applies to AI-enabled attacks. An attacker may use a language model to draft a phishing email, but the decisive failure can still be weak authentication or an employee approving a fraudulent request.
Attribution presents another problem. Victims may identify the use of a deepfake because they receive synthetic audio or video. Proving that malware was developed, modified, or directed by AI can be harder.
Organizations also differ in their ability to detect AI involvement. A mature security team might identify a compromised agent token and classify the incident accurately. A less prepared company might record the same behavior as generic unauthorized access.
This creates a reporting paradox. Stronger monitoring can increase the measured number of AI-related incidents even while reducing their severity. Rising prevalence does not automatically mean every defensive measure is failing.
IBM’s commercial position also warrants transparency. The company sells security software, consulting, identity, data-protection, and AI-governance services. Its report can contain useful research while also supporting demand for those products.
The methodology helps readers evaluate the claims. Ponemon Institute studied 602 breached organizations worldwide, and IBM sponsored and analyzed the work. The follow-up survey in May 2026 included 456 of those organizations.
In that follow-up, 85% said awareness of advanced frontier AI capabilities would prompt them to increase security spending. By comparison, 64% in the initial research planned to spend more after experiencing a breach.
The comparison suggests that frontier AI reports influence budgets before incidents occur. It does not prove that every planned investment will reduce risk or that autonomous defense is always the best use of funds.
Organizations still need to decide where controls produce measurable benefits. More security tools can create duplicated alerts, competing dashboards, and unclear accountability. An agent that identifies a weakness offers limited value if no team owns remediation.
The most useful interpretation avoids both extremes. AI is neither a magical new class of attack that invalidates existing security nor a marketing label attached to familiar breaches.
It is an accelerant connected to a growing enterprise attack surface. It increases the speed and scale of some attacks while creating new identities, interfaces, and stores of sensitive context.
That conclusion remains consequential without treating every IBM number as universal. It directs attention toward access control, integration security, cloud configuration, data visibility, and response speed.
Three Signals to Watch After the Google News Cycle
The next test is whether organizations convert concern into faster remediation, tighter agent permissions, and lower incident costs.
The first signal is adoption of AI for vulnerability management. IBM found that more than half of organizations used agents for detection and containment, while only 18% used them to manage vulnerabilities.
Detection finds suspicious activity after or during an intrusion. Vulnerability management addresses weaknesses before attackers exploit them. If the 18% figure rises, organizations will be applying automation earlier in the security chain.
That would strengthen IBM’s argument that defense must operate closer to attacker speed. If adoption stays concentrated in alerting, the remediation gap will remain, regardless of how many AI tools security teams purchase.
The important measure is not the number of deployed agents. It is the time between discovering a weakness and fixing it. Organizations should track whether automation reduces that interval without creating unauthorized changes or operational instability.
The second signal is the quality of agent identity controls. Companies are connecting agents to development environments, customer systems, document repositories, and operational tools. Those connections need narrowly scoped permissions, short-lived credentials, and reliable attribution.
A meaningful improvement would appear in inventories and access reviews. Security teams should know which agents exist, who owns them, what data they can reach, and which actions they can perform.
Evidence that organizations are enforcing runtime controls would support IBM’s proposed response. Continued reliance on static service accounts with broad permissions would weaken it.
Incident reviews will offer another clue. When an agent contributes to a security event, companies should be able to reconstruct its instructions, tool calls, identity transitions, and data access. Missing records would show that adoption still exceeds governance.
The third signal is next year’s breach economics. The clearest comparison will be whether AI-enabled incidents continue to cost more than the global average and whether defensive automation maintains its reported savings.
IBM’s 2026 figures establish a demanding baseline: $4.99 million for the average global breach, $6 million for an AI-enabled malicious breach, and $1.93 million in savings associated with extensive security automation.
A narrowing cost gap would suggest that controls are catching up. A widening gap would indicate that attacker efficiency and enterprise complexity continue to outrun defensive gains.
Readers should also watch whether future reports preserve the same categories. Stable definitions for AI-enabled attacks, attacks against AI systems, and shadow AI will make year-to-year comparisons more credible.
The current google news headline will fade, but the operational questions will remain. Can a company identify every AI agent acting inside its environment? Can it revoke access quickly? Can it determine what information a compromised system reached?
Those questions matter to developers, security leaders, enterprise buyers, and knowledge workers. Developers determine which permissions and logs an AI application exposes. Buyers decide whether vendors provide usable security evidence. Employees influence where sensitive information travels.
Teams should preserve those decisions, system inventories, incident records, and access assumptions in a searchable knowledge base. Documentation cannot replace technical enforcement, but missing context makes investigation and accountability slower.
IBM’s most important warning is not the one-in-five figure by itself. It is the expanding gap between how quickly organizations connect AI to real work and how slowly they establish visibility around those connections.
The practical response starts with one action: map every model, agent, plug-in, identity, and data source already in use. Then ask which connection creates the largest unmonitored path into sensitive systems.
What would your organization discover if it performed that inventory before the next breach forced the question?


