According to IBM's "2026 Cost of a Data Breach Report," the majority of current AI security incidents do not originate from the models themselves, but rather from deficiencies in access control and fundamental security management within enterprises. The report, based on a survey of 602 global companies by the Ponemon Institute, found that 92% of companies experiencing AI-related security incidents lacked comprehensive AI system access control measures, becoming a major cause of data breaches.
The report indicates that about one-fifth of AI security incidents stem from peripheral infrastructure, including API breaches, vulnerabilities in connected applications, or misconfigured cloud services. However, whether enterprises use open-source models or proprietary models has little impact on the likelihood of such incidents. IBM believes these risks are largely due to basic security oversights, which can be exploited with relatively simple attack methods.
In terms of costs, data breaches involving AI averaged $5.33 million, higher than $4.7 million for breaches not involving AI. The average cost of data breaches globally increased by 12% year-over-year in 2026, reaching $4.99 million. Notably, when attackers use AI to conduct attacks, the average loss rises to $6.04 million, compared to $5.03 million for attacks that do not use AI.
IBM believes that as AI systems accelerate their integration into core business operations, strengthening fundamental security capabilities such as identity authentication, access control, and cloud environment configuration will become key measures to reduce AI security risks and data breach costs.




