Bottom line: According to an IBM report, data breaches will cost $6 million on average in 2026 (+35%), with one in four attacks AI-driven and only 40 percent of organizations securing their AI models with access controls at all.
The average cost of a data breach has risen to $6 million US dollars according to IBM’s new “Cost of a Data Breach” report, an increase of 35 percent over last year’s figure of $4.44 million. One in four malicious attacks was AI-driven, while security teams simultaneously invest too little in AI-powered defense.
The report, prepared by the Ponemon Institute on behalf of IBM, analyzes data breaches at 600 organizations worldwide over the period from March 2025 to February 2026. According to the report, one in four malicious attacks was AI-driven, with deepfake impersonation and AI-powered malware accounting for the majority of this attack type. At the same time, the study shows that the use of AI and automation in security operations reduces the cost of an incident by nearly $2 million on average – yet a quarter of organizations have not yet implemented such tools. A follow-up survey found that more than half of companies use agents for threat detection and containment, but only 18 percent use agents in vulnerability management. Three out of four surveyed companies say that frontier AI threats are forcing them to rethink the use of agents within their security organization.
Particularly relevant for CISOs: one in five organizations reported an incident that specifically targeted AI models or AI applications. The most common causes were vulnerabilities in surrounding systems – compromised APIs, applications, or plug-ins (27 percent) as well as cloud misconfigurations affecting AI workloads (27 percent). The vast majority of affected organizations lacked adequate access controls; overall, only 40 percent deploy access controls on their AI models and data at all. Suja Viswesan, VP of IBM Security Software, summarizes the dynamic as follows: AI is making attacks faster and cheaper, while security incidents are simultaneously becoming more expensive – a gap that translates directly into breach costs when detection and remediation are delayed.
Kayne McGladrey, Senior Member of the IEEE and former CISO at Hyperproof, describes securing AI models and their APIs as the most obvious gap that needs to be closed: models and APIs should be treated like crown jewels, with identity and access controls analogous to those used for databases. Udaya Bhaskar Vemuri, Senior Application Security Analyst and DevSecOps expert, adds that organizations should regularly review integrations and plug-ins, monitor for unusual activity, protect sensitive data, and assign a clearly designated person responsible for security and oversight to every AI system.
Alongside deepfakes and AI malware, AI-powered phishing and direct attacks on AI models, such as prompt injection, are becoming costly blind spots for enterprises. Dray Agha, Senior Manager of Security Operations at Huntress, also points to an internal risk: unsanctioned use of AI applications by employees leads to unmanaged vulnerabilities within corporate environments. He advises CISOs to adopt proactive governance – security must be embedded in development workflows, attack surfaces must be aggressively managed, and strict access controls must be applied to AI workloads. Peter Garraghan, CSO and founder of AI security testing provider Mindgard, warns against blindly relying on the effectiveness of AI guardrails: research has shown that existing safeguards have various blind spots and that a defense-in-depth approach is required. Organizations must continuously test AI models and applications against realistic adversarial attacks to identify weaknesses in their safeguards before and while they are in production use.
Source: www.csoonline.com · Published August 7, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.