Access Controls Missing in Nearly All AI Security Incidents
IBM
IBM's Cost of a Data Breach Report 2026 reveals that in 92% of companies with AI-related incidents, access controls were inadequate. AI-related breaches cost on average $5.33 million, compared to $4.70 million without AI.
According to IBM's Cost of a Data Breach Report 2026, compiled by the Ponemon Institute from a study of 602 companies, almost every AI-related security incident involved missing or insufficient access controls for AI systems. Specifically, 92% of firms that experienced an AI-related incident had inadequate access controls. The root cause is rarely the model itself; in about one in five affected companies, the entry point was compromised interfaces, connected applications, or misconfigured cloud services. The report found no significant difference between open-source and proprietary models. IBM attributes these gaps to fundamental oversights that do not require sophisticated attackers. AI-related incidents cost on average $5.33 million, while those without AI involvement cost $4.70 million. The global average cost of all data breaches rose by 12% to $4.99 million. When attackers themselves used AI, the costs reached $6.04 million, compared to $5.03 million without AI.
- Abbreviations
- IBM = International Business Machines — International Business Machines
Source: The Decoder (DE) —
original
