The average cost of a US data breach reached $10.22 million in 2025, far above the global average of $4.44 million, according to IBM's Cost of a Data Breach report. The higher US figure reflects stricter regulatory requirements, larger litigation costs, and greater notification expenses.
AI-related weaknesses feature prominently in the findings. Among organizations that experienced an AI-related security incident, 97 percent lacked proper AI access controls, and 63 percent of breached organizations had no governance policies for managing AI or detecting unauthorized use. AI was involved in 16 percent of breaches, mostly through phishing and deepfakes.
Unmanaged AI carries a measurable cost. Breaches involving high levels of shadow AI, meaning tools used without organizational approval, added about $670,000 to the average breach cost, pushing those incidents to roughly $4.63 million. Shadow AI played a role in 20 percent of breaches overall.
The global average cost actually declined for the first time in five years, attributed to faster breach containment driven by AI-powered defenses. Healthcare remained the most expensive industry for the fourteenth consecutive year at $7.42 million per breach. The data points to a widening gap between organizations that govern AI use and those exposed by ungoverned deployment.
Source: IBM -- https://www.ibm.com/think/x-force/2025-cost-of-a-data-breach-navigating-ai
![[Data] US Data Breaches Hit $10.22 Million as AI Governance Gaps Widen](https://www.ibm.com/content/dam/worldwide-content/cdp/cf/ul/g/48/32/codb-banners-1200x630px-imageonly.png/_jcr_content/renditions/cq5dam.web.1280.1280.jpeg)