A new report from IBM finds that most companies hit by AI-related security incidents were missing a basic defense. The Cost of a Data Breach Report 2026, published Aug. 3, 2026, shows that 92% of companies experiencing AI-related security incidents lacked basic access controls for their AI systems.
The research, conducted by the Ponemon Institute across 602 companies, points to a pattern that has little to do with the sophistication of the AI itself. In about 1 in 5 affected companies, the entry point was a compromised API, connected application, or misconfigured cloud service. The problem rarely starts with the model itself.
Access Controls Are the Missing Link
IBM traces the gaps back to basic oversights that don't require sophisticated attackers to exploit. Access controls, the fundamental security measure that governs who can reach a system, were simply not in place for many AI deployments.
The report notes that whether a company ran an open-source or proprietary model made almost no difference. Security outcomes did not hinge on the choice of model type. Instead, the surrounding infrastructure, such as APIs and cloud configurations, proved to be the weak points.
The Cost of AI Incidents
The financial impact of these breaches is significant. Incidents involving AI cost an average of $5.33 million. That compares to $4.70 million for incidents without an AI component.
The gap widens when attackers themselves use AI. When attackers used AI, costs jumped to $6.04 million. Without AI use by attackers, costs were $5.03 million.
Stay ahead of the AI curve
The most important updates, news, and content — delivered weekly.
No spam. Unsubscribe anytime.
Global Breach Costs Rise
The broader picture shows a steady climb in breach expenses. The global average across all data breaches rose 12% to $4.99 million. That figure covers every type of incident in the study, not just those tied to AI.
The report, an annual industry benchmark, underscores a growing concern in enterprise environments. AI security incidents are no longer a niche problem. They are becoming a routine part of the threat landscape.
Simple Fixes, Big Consequences
The findings suggest that many organizations are skipping the basics. IBM traces the gaps back to basic oversights that don't require sophisticated attackers to exploit. A misconfigured cloud service or an exposed API can be enough to open the door.
The report does not blame the models themselves. It points instead to the systems around them. Companies that fail to lock down access controls are leaving their AI investments exposed.
For organizations running AI, the lesson is straightforward. The model is only part of the equation. The infrastructure that supports it needs the same rigor as any other critical system.

