IBM Report: 13% of Firms Suffer AI Breaches Due to Poor Controls

IBM's 2025 report reveals 13% of organizations suffered AI system breaches, with 97% lacking proper access controls. Global breach costs fell to $4.44M but US costs hit $10.22M. Only 49% of breached firms plan security investments.

ibm-report-ai-breaches-poor-controls
Facebook X LinkedIn Bluesky WhatsApp
de flag en flag es flag fr flag nl flag pt flag

AI Security Crisis Exposed

IBM's 2025 Cost of a Data Breach Report reveals critical security gaps in AI implementation across organizations. The study found that 13% of companies experienced breaches targeting AI models or applications, with 97% of compromised organizations lacking proper access controls.

Key Findings

Among affected organizations, 60% suffered data compromise while 31% faced operational disruption. The research highlights a dangerous trend where AI adoption outpaces security governance - 63% of breached entities either lack AI governance policies or have incomplete frameworks.

Shadow AI Threat

One in five organizations reported breaches from unauthorized "shadow AI" usage. Companies with high shadow AI usage incurred $670,000 higher breach costs on average. Attackers increasingly weaponize AI too, with 16% of breaches involving AI-powered phishing or deepfakes.

Financial Impact and Response

While global breach costs decreased to $4.44 million, US costs hit a record $10.22 million. Healthcare remains the most expensive sector at $7.42 million per breach despite a $2.35 million year-over-year reduction.

Concerning Security Trends

Only 49% of breached organizations plan security investments post-incident - a significant drop from 63% in 2024. Among those investing, less than half prioritize AI-driven security solutions. Ransomware costs remain high at $5.08 million when attackers disclose incidents.

Operational Consequences

Nearly all breached companies experienced operational disruption, with recovery typically exceeding 100 days. Nearly half of organizations increased product/service prices due to breaches, with 31% implementing hikes of 15% or more.

Historical Context

This 20th anniversary report shows how breach causes evolved from physical device loss (45% in 2005) to sophisticated AI-targeted attacks today. The global breach lifecycle improved to 241 days - 17 days faster than 2024.

Related

ai-agents-business-risks-2026
Ai

AI Agents Explained: Autonomous Business Systems & Emerging Risks | 2026 Guide

AI agents are transforming business with 79% adoption but bring significant risks. The market grows 45.8% annually...

ai-cybercrime-threats-guide-2025
Ai

AI-Powered Cybercrime: The Next Wave of Threats Explained | Complete Guide

AI-powered cybercrime increased 72% in 2025, with 87% of organizations facing AI-enabled attacks. Criminals use AI...

cmo-ai-role-disruption-skill-gap
Ai

CMO AI Blind Spot Guide: 65% Expect Role Disruption, Only 32% Upgrade Skills

65% of CMOs expect AI to disrupt their roles by 2028, yet only 32% believe they need significant skill upgrades....

ai-model-leaks-governance-overhaul
Ai

AI Model Leaks Trigger Enterprise Governance Overhaul

AI model leaks are exposing critical governance gaps in enterprises, with 13% of organizations reporting breaches....

ai-security-prompt-injection
Ai

How Safe Is Your AI Model? Inside the Prompt Injection Arms Race

Prompt injection attacks manipulate AI models by exploiting their inability to distinguish between instructions and...

ai-chip-export-controls-us-china-2026
Ai

AI Chip Export Controls: Why the U.S. Withdrew Global Licensing Rules | Strategic Analysis

The U.S. withdrew global AI chip export licensing requirements in March 2026, shifting from broad restrictions to...