Skip to content
Rush Commerce
AI & Automation3 min read

92% of AI breach victims had no AI access controls

IBM's 2026 Cost of a Data Breach report: AI-enabled breaches cost $6M, shadow AI drove 43% of incidents, and 92% of AI-breached orgs lacked basic access controls.

IBM's 2026 Cost of a Data Breach report landed last week, and one number does most of the work. Among organizations that suffered an AI-related security incident, 92% were missing basic AI access controls — no role-based access, no MFA, nothing gating the model or the app in front of it. Not a novel attack class. Not a prompt-injection zero-day. The same controls you already apply to your CRM, absent from the thing you pointed at your CRM.

What actually happened

Per IBM's release, the study covers 602 breached organizations interviewed by the Ponemon Institute, spanning incidents from March 2025 through February 2026. The headline figures:

  • One in four malicious breaches were AI-enabled, a 56% jump year over year, averaging $6 million each
  • The global average breach cost hit $4.99 million — a record, up more than 10%
  • AI involvement added roughly $1 million on top of an otherwise comparable attack
  • Over 20% of organizations reported breaches targeting AI models or applications directly, most often through compromised APIs, plug-ins, or cloud misconfiguration (27% each)

Then the governance numbers, via Help Net Security's breakdown. Shadow AI — employees using unapproved tools — figured in 43% of security incidents, more than double the prior year's share. Close to 70% of breached organizations had no governance policy for managing AI or spotting unsanctioned deployments. Fewer than one in five had their governance and security teams talking to each other.

The one bright spot: organizations using AI and automation in security operations cut breach costs by about $2 million.

Why AI access controls matter for your business

Read the 92% and the 43% together and the shape is obvious. The AI in your company that's most likely to leak something isn't the deployment your team designed — it's the one nobody filed a ticket for. Someone pasted a customer list into a free tool to clean it up. Someone wired a spreadsheet to an API key with far more scope than the job needed. Neither shows up in a security review because neither exists on paper.

We've written before about the enterprise AI governance gap and about agents inheriting permissions nobody revoked. IBM's data is the bill for it. And the fix genuinely is not a platform purchase:

  1. Inventory first. What AI touches your systems right now, and under whose credentials? Check your OAuth grants, your API key list, and your browser-extension inventory. You will find things.
  2. Scope every key to one job. An AI integration that reads orders should hold a token that reads orders. Not an admin key someone generated in 2024 because it was faster.
  3. Put the model behind the same auth as everything else. If your internal assistant has no SSO and no role checks, it's a public endpoint that happens to be hard to guess.
  4. Give people a sanctioned tool. Shadow AI at 43% is a demand signal, not a discipline problem. If the approved path is slower than the unapproved one, you already know which one gets used.

None of this is a project. It's an afternoon of auditing and a week of narrowing scopes. The $6 million figure is what the alternative averages.

Key takeaways

  • 92% of organizations with AI-related security incidents lacked role-based access, MFA, or equivalent controls on their AI models and apps
  • AI-enabled breaches hit one in four malicious incidents (up 56%) and averaged $6M, against a record $4.99M global average
  • Shadow AI featured in 43% of incidents — more than double last year — and ~70% of breached orgs had no AI governance policy at all
  • The remedy is scoped credentials, SSO on internal AI tools, an actual inventory, and a sanctioned option fast enough that people use it

Most AI security incidents are permissions problems wearing a new hat. We build AI automation with scoped credentials, audit trails, and access controls from day one — tell us what your AI can currently reach.

Sources: IBM Newsroom, Help Net Security.

  • #ai-security
  • #access-controls
  • #shadow-ai
  • #data-breach
  • #governance
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.