AI

IBM: 92% of AI Breach Victims Lacked Basic Access Controls

IBM's Cost of a Data Breach Report 2026 finds 92% of companies hit by AI-related breaches lacked adequate access controls. The weak spot isn't the model, it's the plumbing around it.

Faruk TalmaçAugust 4, 20263 min read4 views
IBM: 92% of AI Breach Victims Lacked Basic Access Controls

Ninety-two percent. Of the companies that suffered an AI-related security breach in IBM's newly released Cost of a Data Breach Report 2026, that share had inadequate access controls in place. The study, conducted with the Ponemon Institute across 602 organizations, points to an uncomfortable conclusion: attackers rarely needed sophistication, because permission management had never been done properly in the first place.

Where the attackers got in

Roughly one in five compromised firms was breached through APIs, connected applications, or misconfigured cloud services, the unglamorous plumbing around the model rather than the model itself. One finding deserves particular attention in the ongoing open-versus-closed debate: whether a company ran an open-weights or proprietary model made almost no difference to breach outcomes. Security lived or died on the controls built around the system, not on the vendor logo.

"Access controls" sounds abstract until you translate it into questions: does the chatbot see the entire customer database, or only the record it needs? Whose identity does the automation act under, and does that account hold more privileges than the job requires? Is the API key from an integration someone trialed three months ago still live? According to the report, most incidents start in exactly these forgotten corners.

A breach with AI inside costs more

The report also puts prices on the problem:

  • Breaches involving an AI component averaged $5.33 million, against $4.70 million for those without.
  • When attackers themselves used AI tools, the average climbed to $6.04 million.
  • The global average across all breaches reached $4.99 million, up 12 percent.

One caveat worth keeping in view: these averages come from a 602-company sample that skews toward large enterprises. A small business will see a smaller absolute bill, but relative to revenue the hit is usually harder, because there is no cushion built to absorb it. And in most jurisdictions a breach involving personal data also triggers regulatory notification duties and potential fines, a second bill that arrives independently of the first.

The checklist that beats the security budget

What we see in client work matches the report almost exactly. Companies deploy chatbots, automations, and agents with real enthusiasm, and defer the boring questions: what data can this system reach, whose identity does it act under, where does its authority stop. IBM's data says those deferred questions are the front door of most incidents. Before buying security products, three habits close most of the gap: grant every integration the minimum access it needs to function, expire unused API keys on a schedule, and keep a single up-to-date inventory of what your AI systems can touch. None of that costs money. The average breach in this report costs five million dollars, which makes discipline the best-priced security product on the market.

Sources: The Decoder, IBM

Share This Article

Faruk Talmaç

Written by

Faruk Talmaç

Co-Founder & Editor

Co-founder of YZ Uzman, with 20+ years of experience in web design and software development.

More news

Want to put this technology to work in your business?

Let's talk