According to an IBM report, the average cost of a data breach is now $5 Million This is compared to 2025.12% increase Has been seen.
The greatest damage was seen in attacks that directly targeted AI tools. By Prompt-Injection and Inversion AttacksThese advanced cyberattacks affecting AI models cost companies on average $6 Million Had to suffer huge losses.
IBM researchers say that while traditional cyberattacks compromise systems, behavioral attacks on AI alter how AI models think and make decisions. This requires companies to address not just technical recovery but also data governance and trust restoration.
2. The Growing Threat of Ungoverned AI and Shadow AI
As quickly as companies are adopting AI technologies, they are failing to pay enough attention to their security and access controls. Access control failure is seen.
Among the companies whose AI models were attacked, 92% of companies completely fail to implement proper access controls।
Only 40% of companies studied admitted to restricting access to their AI systems.AI tools used by employees without the permission of the IT department, i.e.Shadow AI The number of security incidents involving the 43% Reached till.
Currently, more than two-thirds (68%) of organizations do not have a clear governance framework in place to prevent or control Shadow AI.
3. Use of AI Agents
In Security Operations Centers (SOCs) AI AgentsThe use of has increased rapidly, but the report shows that companies are failing to use them properly.50% breached organizations used AI agents for threat hunting.
Although, Less than 20% (1 in 5) Companies have used AI agents to scan and manage vulnerabilities on networks, which is where AI agents are considered most suitable and effective.
4. Ignoring Basic Cybersecurity
Amid the buzz around AI and advanced technologies, companies were forgetting the basics of cybersecurity.
Companies’ on-premises infrastructure was targeted the most compared to the cloud (Public, Private or Hybrid Cloud).
Most of the companies that fell victim to the data breach did not even encrypt their sensitive data, making it extremely easy for hackers to steal the data.
The US had the highest data breach costs compared to other countries, while the industry Healthcare sector has suffered the most costly attacks.
Read More:
5. Focus on governance and IAM is essential
Presenting the findings of this IBM report, it is important to understand that simply purchasing new technology does not guarantee security.Identity & Access Management (IAM) And AI Governance Unless the government is strengthened, financial losses will continue to increase.
The good thing is that considering the gravity of the situation, 85% breached organizationshas announced that they will increase their budget on “security tools and governance” in the coming time.
What steps should companies take?
- Implementing AI Governance Policy,Clear guidelines need to be created regarding which AI tools are being used in the organization and who can access them.
- By banning Shadow AI, keep strict vigil on the use of unauthorized AI apps.
- Strengthening Identity Controls,Mandate role-based access (RBAC) and multi-factor authentication for AI models and data repositories.
- Prioritizing data encryption,Store data in encrypted form both on-premises and in the cloud.
The IBM Cost of a Data Breach Report 2026 is a wake-up call for the cybersecurity world. While AI can increase security teams’ speed, without governance, it opens up new and easy avenues for hackers. Success today lies not only in adopting new AI technologies, but also in using them in a safe and controlled manner.