Nine out of 10 companies that got breached through their AI systems never set up the access controls that would have made the attack hard. That’s not a subtle finding. It’s a plumbing problem.
IBM’s Cost of a Data Breach Report 2026, built on Ponemon Institute research covering 602 companies, puts the number at 92 percent. Among firms that suffered an AI-related incident, that share had inadequate access controls in place.
The model isn’t where the trouble starts
Attackers mostly didn’t go after the model. In about one in five affected companies, the way in was a compromised API, a connected application or a misconfigured cloud service.
The kind of thing a security team writes down in a ticket and then doesn’t get to for a quarter.
And the open-source versus proprietary argument that eats up so much air in AI procurement meetings? Whether a company ran an open model or a closed one made almost no difference to whether it got hit.
What the failures cost
Incidents involving AI cost an average of $5.33 million. Those without an AI component came in at $4.70 million. The global average across all data breaches rose 12 percent to $4.99 million.
The gap widens when the attackers bring their own AI. Breaches where attackers used AI cost $6.04 million on average, against $5.03 million where they didn’t.
Roughly a million dollars, then, separating an attacker with tooling from one without.
No sophisticated adversary required
IBM traces the gaps back to basic oversights that don’t require sophisticated attackers to exploit. That framing matters more than the dollar figures, because it changes who the report is aimed at.
If the entry points are exposed APIs, over-connected apps and cloud services nobody locked down, then the fix isn’t a new AI security product. It’s the access control work that was already on the backlog before anyone deployed a model.
Read the 92 percent as a checklist rather than a headline. Go find every service account, API key and integration that touches your AI stack, and see how many of them you can name. If the list runs longer than you expected, you’re already in the same category as the 602 companies Ponemon surveyed.