The average US data breach cost reached an all-time high of $10.22 million, roughly 2.3 times the global average, according to the IBM Cost of a Data Breach Report. The global average fell to $4.44 million, a 9 percent decline and the first decrease in five years, with the US figure driven upward by regulatory fines and escalation costs.

Unsanctioned AI tools carry a measurable price. One in five studied organizations, 20 percent of the sample, experienced breaches linked to shadow AI, defined as AI tools adopted by employees without IT or security oversight. Those incidents added as much as $670,000 to average breach cost.

Defensive AI use moved the number in the opposite direction. Organizations deploying AI security tools extensively saved $1.9 million per breach and identified incidents 80 days sooner than organizations without them.

Detection and containment timelines improved overall. The average breach lifecycle fell to 241 days, split between 181 days to detect and 60 days to contain, the shortest measured span in nine years.

Research from IBM and the Ponemon Institute found AI adoption outpacing security and governance controls, with ungoverned AI systems more likely to be breached and more expensive when breached.

Healthcare remained the costliest industry at $7.42 million per breach, its fifteenth consecutive year in that position.

Source: IBM - https://www.ibm.com/reports/data-breach