Thirteen percent of organizations reported breaches of their artificial intelligence models or applications, according to IBM's Cost of a Data Breach research. Of those organizations, 97 percent said they lacked proper AI access controls, pointing to a gap between rapid AI adoption and the security practices needed to protect it.

The governance picture compounds the risk. IBM found that 63 percent of breached organizations either had no AI governance policy or were still developing one. That absence of formal oversight leaves many companies without clear rules for how AI tools may be used, who may access them, and how the data they touch should be protected.

The findings describe a security gap opening as AI moves into production. Organizations have deployed models and AI-powered applications quickly, but controls governing access to those systems have not kept pace. When attackers reach an AI model or its supporting data, weak access management can widen the scope of what is exposed.

The data frames AI security as a governance challenge as much as a technical one. IBM's results suggest that the organizations most exposed are those that adopted AI without first establishing access controls and oversight policies. As deployment broadens across business functions, the report points to access management and formal governance as the practices that separate protected systems from vulnerable ones.

Source: IBM - https://newsroom.ibm.com/2025-07-30-ibm-report-13-of-organizations-reported-breaches-of-ai-models-or-applications,-97-of-which-reported-lacking-proper-ai-access-controls