Business

IBM finds 92% of AI-breached firms lacked access controls.

A new IBM study reveals that 92 percent of organizations hit by AI-related security breaches lacked basic access controls, highlighting a critical vulnerability in modern enterprise AI deployments.

The Decoder3 Aug 2026Business
Image: The Decoder

According to IBM's Cost of a Data Breach Report 2026, which analyzed research conducted by the Ponemon Institute across 602 companies, a staggering 92 percent of organizations that suffered an AI-related security incident lacked fundamental access controls for their artificial intelligence systems. These security failures rarely stemmed from vulnerabilities within the AI models themselves. Instead, approximately one in five affected enterprises experienced breaches through compromised application programming interfaces (APIs), connected software applications, or misconfigured cloud services. Notably, the report found that whether a business deployed an open-source or a proprietary model had virtually no impact on its vulnerability level.

The financial consequences of these oversights are severe. Security incidents involving artificial intelligence cost organizations an average of $5.33 million, representing a significant premium over the $4.70 million average for breaches that did not involve an AI component. This trend comes amid a broader rise in cybersecurity expenses, with the global average cost across all data breaches climbing 12 percent to reach $4.99 million. Furthermore, when malicious actors leveraged AI tools to execute their attacks, the average cost of a breach surged to $6.04 million, compared to $5.03 million when attackers did not use AI.

For AI practitioners and enterprise security teams, these findings shift the focus of AI safety from highly theoretical model-level threats to foundational IT hygiene. Instead of over-indexing on complex adversarial attacks against the neural networks themselves, engineers and administrators must prioritize securing the surrounding infrastructure. This means implementing strict identity and access management policies, auditing API integrations, and ensuring cloud environments are properly configured. Because basic oversights are driving multi-million-dollar losses, securing the data pipeline and application entry points is now just as critical as optimizing the models.

This is our own summary of reporting by The Decoder

More in Business