IBM Report: 92% of AI-Related Breaches Hit Firms With Weak Access Controls

ibm report 92 of ai related breaches hit firms with weak access controls Of the companies breached by way of their AI systems, nine in 10 had never put in place the access controls that would have made such an attack difficult. There is nothing subtle about that finding. It is a plumbing problem.

Of the companies breached by way of their AI systems, nine in 10 had never put in place the access controls that would have made such an attack difficult. There is nothing subtle about that finding. It is a plumbing problem.

The figure comes from IBM’s Cost of a Data Breach Report 2026, which draws on Ponemon Institute research spanning 602 companies. It pegs the share at 92 percent: among organizations hit by an AI-related incident, that many had inadequate access controls.

The model isn’t where the trouble starts

For the most part, attackers were not targeting the model itself. In roughly one in five of the affected companies, the entry point was a compromised API, a connected application or a cloud service left misconfigured.

Exactly the sort of item a security team logs in a ticket and then leaves untouched for a quarter.

As for the open-source versus proprietary debate that consumes so much oxygen in AI procurement meetings, it barely registered. Running an open model rather than a closed one made almost no difference to whether a company was breached.

What the failures cost

Incidents with an AI component carried an average price tag of $5.33 million, compared with $4.70 million for those without one. Across all data breaches, the global average climbed 12 percent to $4.99 million.

That gap grows once the attackers arrive with AI of their own. Where attackers used AI, breaches averaged $6.04 million, versus $5.03 million where they did not.

Call it about a million dollars between an attacker with tooling and one without.

No sophisticated adversary required

IBM pins the gaps on basic oversights that require no sophisticated attacker to take advantage of. That framing carries more weight than the dollar figures, because it shifts who the report is really addressing.

If the doors being opened are exposed APIs, over-connected apps and cloud services that nobody locked down, then no new AI security product is the answer. The remedy is the access control work that was sitting on the backlog well before anyone shipped a model.

Treat the 92 percent as a checklist, not a headline. Go and track down every service account, API key and integration touching your AI stack, then count how many you can actually name. Should that list be longer than you anticipated, you already belong to the same group as the 602 companies Ponemon surveyed.