Dive Brief:
- Half of organizations that experienced a data breach in 2025 are using AI agents to hunt for threats, but fewer than one in five of those organizations are using agents for the task for which they’re most suited: scanning for and managing vulnerabilities on a network.
- That data point comes from IBM’s 2026 Cost of a Data Breach Report, which also found that 85% of breached organizations plan to spend more money on “security tools and governance.”
- The report, published on Wednesday, also covers businesses’ use of AI agents in security operations centers, organizations’ post-quantum cryptographic migrations and ways to reduce breach costs.
Dive Insight:
Data breaches now cost businesses an average of $5 million, according to the new report, a 12% increase over the figure from IBM’s 2025 research. Some attacks on AI tools cost businesses much more — inversion and prompt-injection attacks cost organizations an average of roughly $6 million.
“Unlike traditional exploits that compromise systems, these behavioral attacks undermine how AI models reason and respond,” IBM researchers wrote, “expanding remediation beyond technical recovery into trust and governance.”
The vast majority (92%) of organizations that suffered attacks on their AI models failed to properly control access to those tools, even as businesses describe identity management as one of their best defenses against costly breaches. Only four in 10 organizations said they limited access to their AI systems.
Identity controls “have failed to keep pace” with AI’s sprawl across corporate networks, IBM researchers said. “The outcome is predictable: expanded attack paths, higher financial impact and incidents driven by basic enforcement gaps that don’t even require attacker sophistication.”
Organizations in the U.S. faced higher breach costs than their international counterparts, according to the report, with the healthcare sector experiencing the costliest attacks.
Even as AI increasingly attracts corporate executives’ attention, basic cybersecurity principles still define the attack landscape. On-premises systems experienced more breaches than private cloud, public cloud, or hybrid environments, and most victims failed to encrypt their data, making it more attractive to thieves.
Governance is the missing piece when it comes to AI, according to the report, whose findings echoed a long line of research showing that companies are adopting AI before they know how to manage it. The share of security incidents involving shadow AI more than doubled year over year, to 43%, with the average cost of those breaches also increasing. More than two-thirds of organizations said they didn’t have governance processes in place to limit shadow AI, a slight uptick from the 2025 figure.
IBM’s report is based on a study of 602 organizations that experienced data breaches between March 2025 and February 2026, with respondents representing 17 industries in 16 countries.