Some 88.4 percent of organizations experienced at least one AI related security incident over the past year, according to AvePoint research covering 750 enterprise leaders across the Americas, EMEA, and Asia Pacific. The figure places AI security events closer to universal than to exceptional among surveyed enterprises.
A separate study from the Cloud Security Alliance and Token Security published in April 2026 found 65 percent of organizations had at least one cybersecurity incident caused by AI agents operating on corporate networks. Another measure put the share reporting an AI driven cyberattack at 87 percent.
The failure modes cluster in identifiable places. Third party dependencies inside AI workflows accounted for security incidents at 44 percent of companies. Roughly 73 percent of AI systems assessed in 2026 security audits showed exposure to prompt injection. Between 40 and 62 percent of AI generated code contained security vulnerabilities or design flaws, and 38 percent of organizations reported accidental data exposure through AI generated code.
Unauthorized internal AI use adds a separate cost line. Some 73 percent of organizations report concern that unsanctioned AI tools are creating data loss paths outside monitoring, and shadow AI adds roughly $670,000 to average breach cost.
Source: SecurityBrief - https://securitybrief.com.au/story/most-firms-hit-by-ai-security-incidents-study-finds
![[Data] 88.4 Percent of Organizations Reported an AI Related Security Incident in the Past Year](https://securitybrief.com.au/uploads/story/2026/07/03/compatible_chris-shaw-director-of-channel-uk-i-at-avepoint.jpg)