Data breaches now cost organizations an average of $5 million, a 12 percent increase over the figure in IBM's 2025 research, according to the 2026 Cost of a Data Breach Report published on July 29, 2026. Attacks aimed at AI systems ran higher still, with model inversion and prompt-injection attacks costing organizations roughly $6 million on average.

The share of security incidents involving shadow AI more than doubled year over year to 43 percent, and the average cost of those breaches also rose. More than two-thirds of organizations said they had no governance process in place to limit shadow AI, a slight increase over the 2025 figure.

Access control emerged as a common gap. IBM found that 92 percent of organizations hit by attacks on their AI models had failed to properly control access to those tools, and only four in 10 organizations said they restricted access to AI systems. IBM researchers wrote that identity controls have failed to keep pace with the spread of AI across corporate networks, producing expanded attack paths and higher financial impact.

Half of the organizations breached in 2025 are using AI agents for threat hunting, while fewer than one in five apply agents to vulnerability scanning and management. Eighty-five percent of breached organizations plan to increase spending on security tools and governance.

US organizations faced higher breach costs than counterparts abroad, and healthcare recorded the costliest attacks. On-premises systems experienced more breaches than private cloud, public cloud, or hybrid environments. The study covers 602 organizations that suffered breaches between March 2025 and February 2026, spanning 17 industries in 16 countries.

Source: Cybersecurity Dive - https://www.cybersecuritydive.com/news/data-breach-costs-ai-governance-ibm/826463/