Enterprise & Industry

IBM: AI-driven breaches cost $6M, up 56% as attackers speed ahead

AI attacks behind 1 in 4 breaches, and the price tag is $1M higher.

Deep Dive

IBM's 2026 Cost of a Data Breach Report, conducted by the Ponemon Institute, reveals that AI-enabled data breaches now cost organizations $6 million on average—about $1 million more than the global average of $4.99 million. AI played a role in one in four malicious breaches examined, a 56% increase from the previous year. The study, which analyzed 602 organizations from March 2025 to February 2026, highlights a dangerous imbalance: many firms use AI to detect attacks already underway, but far fewer deploy it to find vulnerabilities before attackers exploit them. Only 18% of breached organizations used AI agents for vulnerability management, while more than half used them for threat detection and containment.

The report also exposes critical governance gaps. Shadow AI—unsanctioned AI tool usage—was involved in 43% of incidents, more than double the previous year. A stunning 92% of organizations hit by AI-related breaches lacked proper access controls for their AI systems. Critical infrastructure bore the brunt, accounting for 62% of AI-driven attacks, with financial services breaches averaging $6.3 million and energy $5.2 million. Healthcare remained the costliest sector for the 13th straight year at $6.6 million. IBM's security VP Suja Viswesan warns that AI is making attacks faster and cheaper while breaches keep getting more expensive, urging companies to close the gap between discovery and remediation.

Key Points
  • AI-enabled breach costs average $6M, $1M above the global average of $4.99M
  • AI involved in 25% of malicious breaches, a 56% jump from prior year
  • Only 18% use AI agents for vulnerability management; shadow AI in 43% of incidents

Why It Matters

Businesses must deploy AI for prevention, not just detection, or face mounting breach costs.

📬 Get the top 10 AI stories daily