AI-Enabled Data Breaches Cost Organizations $6 Million on Average

News Room

Cybercriminals are using AI to move faster, and companies are paying a premium when those attacks lead to data breaches.

IBM found that AI played a role in one in four malicious breaches examined for its 2026 Cost of a Data Breach Report, a 56% increase from the previous year. These incidents cost organizations an average of $6 million — about $1 million more than the global average breach cost of $4.99 million.

Conducted by the Ponemon Institute, the study examined breaches experienced by 602 organizations between March 2025 and February 2026.

The findings also reveal a growing imbalance for security teams: Many organizations are using AI to detect attacks already underway, but far fewer are deploying it to find vulnerabilities before attackers can exploit them.

ā€œWhat’s changing is the economics of cyberattacks. AI is making attacks faster and cheaper, while breaches keep getting more expensive,ā€ said Suja Viswesan, vice president of IBM Security Software. ā€œWhen organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs.ā€

Companies are using AI, but not where attackers are moving fastest

Organizations that used AI and automation extensively in security operations reported breach costs averaging $1.93 million less than organizations that did not use the technologies, according to IBM.

However, IBM found that many companies are still using AI mainly after attacks begin. More than half of breached organizations reported using AI agents for threat detection and containment, but only 18% used agents for vulnerability management.

That gap could become increasingly consequential as attackers use AI to accelerate vulnerability discovery and exploitation.

IBM found that more than 20% of organizations experienced breaches involving AI models or applications. The most common causes were weaknesses around AI systems rather than the models themselves, including compromised APIs, applications or plug-ins, as well as cloud misconfigurations affecting AI workloads.

Critical industries face higher AI-related risks

Critical infrastructure organizations experienced the majority of reported AI-driven attacks, accounting for 62% of incidents. Financial services and energy companies saw some of the highest concentrations of AI-related attacks.

Financial services breaches averaged $6.3 million, while energy breaches averaged $5.2 million, highlighting the potential for cyber incidents to affect essential services, supply chains and broader economies. Healthcare remained the most expensive industry for breaches for the 13th consecutive year, with average costs reaching about $6.6 million, according to IBM’s findings.

Must-read security coverage

AI governance remains a weak point

While companies are increasing AI adoption, many are struggling to control how the technology is used internally. Shadow AI — the use of AI tools or systems without organizational approval or oversight — was involved in 43% of the incidents IBM studied, more than twice the previous year’s share.

IBM also found that 92% of organizations affected by AI-related breaches lacked proper access controls for their AI systems. The finding suggests that weak identity management, limited governance and poor oversight may be leaving AI systems unnecessarily exposed.

The report also identified gaps in basic data protection. Only 37% of breached organizations said they encrypted sensitive data both at rest and in transit, while many lacked a complete inventory of encryption keys, certificates and other cryptographic assets.

Security teams face a race against AI-powered attackers

The report suggests that businesses cannot rely only on traditional security improvements. AI is speeding up attacks, but it can also help organizations respond faster if deployed correctly.

The challenge is deciding where AI should be applied. Many companies are using AI to investigate alerts after suspicious activity appears, but fewer are using it to proactively identify vulnerabilities before attackers find them.

Also read: The Biggest Data Breaches of 2026, Ranked by Impact.

Read the full article here

Share This Article
Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *