AI Governance Gaps Drive Record Breach Costs

The IBM 2026 Cost of a Data Breach Report Proves AI Governance Failure, Not AI Itself, Is Driving Costs

Every year, someone writes the same headline off this report: the average cost went up, here’s the number, here’s a quote about how cybersecurity matters more than ever. That headline is already stale by the time it’s published, and this year it misses the actual story entirely.

IBM and the Ponemon Institute released the 2026 Cost of a Data Breach Report this month, the 21st edition of a study that has tracked breach economics since 2005. The global average cost of a breach climbed to USD 4.99 million, a 12% jump over last year and a new record. That number will lead most of the coverage. It shouldn’t. The number that matters is buried on page 40: 92% of organizations that experienced an AI-related security incident lacked proper AI access controls when it happened.

Read that again. Not “some” organizations. Not “many.” Ninety-two percent. These are companies that already had an AI model or application compromised, and nearly all of them still hadn’t put basic role-based access or multifactor authentication around it. This isn’t a story about artificial intelligence being dangerous. It’s a story about governance that never showed up to the deployment meeting.

Most of the commentary on this report treats AI risk as a future problem, something to get ahead of before it becomes urgent. The data says otherwise. AI-driven attacks are up 56% year over year. Security incidents involving an organization’s own AI models grew from 13% of breaches to 21% — a 61% increase in a single research cycle. Shadow AI incidents more than doubled, from 20% to 43%. This isn’t a forecast. It’s happening at scale, right now, inside the 602 organizations Ponemon studied across 17 industries and 16 countries between March 2025 and February 2026.

Key Takeaways

  1. Global breach costs hit a record USD 4.99 million. That’s a 12% increase over last year, reversing a rare dip in 2025 and continuing an upward trend that has held since the pandemic.
  2. AI adoption without governance, not AI itself, is the primary cost driver. Among organizations that suffered an AI-related breach, 92% lacked proper AI access controls, and those incidents averaged USD 5.33 million versus USD 4.70 million for breaches that didn’t involve AI.
  3. Shadow AI incidents more than doubled to 43% of breached organizations, up from 20% last year, driving average costs from USD 4.63 million to USD 5.39 million and triggering regulatory fines in roughly one in five cases.
  4. AI governance is losing ground, not gaining it. Only 32% of breached organizations have AI policies in place today, down from 37% last year, and just 19% coordinate between AI governance and security teams.
  5. Security AI and automation remain the most effective cost reducer available, saving extensive adopters USD 1.93 million per breach and cutting containment time by 65 days — but only 36% of organizations use these tools extensively.

The Number Everyone Will Skip Past

Ninety-two percent lacking proper AI access controls is not a rounding error. It’s a structural failure that shows up across every AI-related incident type the report tracked. Model inversion attacks, where an attacker extracts sensitive data by probing a model’s outputs, averaged USD 6.07 million per breach — 18% above the global average. Prompt injection incidents came in close behind at USD 5.89 million. Cloud misconfigurations affecting AI workloads cost USD 5.25 million. None of these are exotic attacks on the model’s reasoning. They’re the predictable result of connecting a powerful system to sensitive data without access controls or identity and access management built around it. A confirmed data breach tied to model inversion or prompt injection carries the same notification obligations under HIPAA, GDPR, or comparable frameworks as any other breach — with the added complexity that reconstructing exactly what an AI system exposed is often harder than tracing a conventional intrusion.

The report’s own language backs this up: “The root causes of these incidents were often structural: compromise of connected APIs, applications and cloud misconfigurations, indicating governance failures — not model risk.” That’s IBM and Ponemon saying, in their own words, that the model is rarely the weak point. The wiring around it is.

This matters because the industry conversation about AI security still spends an enormous amount of energy on model behavior — hallucination, bias, jailbreaking — while the breach data says the exposure is showing up in DLP gaps, misconfigured cloud environments, and APIs nobody locked down. AI data governance isn’t a nice-to-have layered on top of an AI deployment. It’s the deployment. A formal risk assessment that specifically inventories which APIs, cloud configurations, and AI workloads currently lack access controls — rather than assessing AI risk at the model-behavior level — is the evidence base that converts this year’s 92% figure from an abstract statistic into a prioritized remediation list.

You Trust Your Organization is Secure. But Can You Verify It?

Read Now

Shadow AI Has Become the New Shadow IT — With Higher Stakes

A decade ago, security teams fought a losing battle against shadow IT: employees signing up for cloud tools without approval, storing company data in personal Dropbox accounts, running unsanctioned SaaS. Most organizations eventually built visibility programs and CASBs to bring it under control. Shadow AI is repeating that exact pattern, except the tools involved can ingest, summarize, and regenerate sensitive content in ways a personal file-sharing account never could.

The report found that security incidents involving an organization’s shadow AI — unapproved AI tools workers adopt on their own — more than doubled this year, from 20% to 43% of breached organizations. These incidents carried a higher average cost than last year (USD 5.39 million versus USD 4.63 million) and produced consequences that go beyond a simple data leak: 49% resulted in data loss or compromise, 42% caused operational disruption, and 21% led to a regulatory fine.

Here’s the part that should worry every compliance officer reading this: shadow AI incidents are now generating fines in roughly one out of every five cases. That’s a new data point this year, and it means shadow AI has crossed from an internal control problem into a regulatory exposure. An employee pasting a customer record into an unapproved chatbot to draft a faster response isn’t a policy violation anymore. It’s a potential GDPR or state-privacy-law event with a dollar figure attached, and if that customer record includes PII or PHI, the notification obligations compound the fine exposure the report documents.

The comparison to shadow IT only holds up to a point, though, and the point where it breaks down matters. Shadow IT typically meant data sitting somewhere it shouldn’t. Shadow AI means data actively being processed, transformed, and in some cases used to train or fine-tune a model outside anyone’s visibility. You can’t always claw that back with a deletion request. This is precisely the gap that zero trust generative AI approaches and AI risk governance frameworks are built to close: applying policy enforcement at the point where content moves between a user and an AI system, rather than trying to police behavior after the fact. Data classification applied before content ever reaches an AI tool is the prerequisite that makes this enforcement possible — a policy engine cannot block a customer record from an unapproved chatbot if it has no way to recognize that record as sensitive in the first place.

Governance Is Losing Ground, Not Catching Up

If AI governance were improving even slowly, the last two findings would read as a temporary lag. They don’t, because the report shows governance moving backward. Only 32% of breached organizations have AI policies in place this year, down from 37% last year. Organizations with no policies at all also dropped, from 41% to 35%, but the share “in development” jumped from 22% to 33%. Translation: fewer companies have finished the job, and more are perpetually starting it.

The coordination gap is worse. Only 19% of organizations reported that their AI governance and security teams actually coordinate with each other — a question the report asked for the first time this year. IBM’s researchers put it plainly: “That lack of collaboration could lead to blind spots, policy conflicts and slower response times to security incidents.” Governance and security operating in separate lanes is exactly how a 92% access-control failure rate happens without anyone owning the fix. The CISO Dashboard gives both teams a single, shared, real-time view of AI-mediated data access — closing the coordination gap by ensuring governance and security are looking at the same evidence rather than working from separate, disconnected reporting.

None of this is happening because organizations don’t see the risk. It’s happening because AI deployment moved at product-team speed while governance moved at committee speed, and the gap between those two speeds is where the breach costs are accumulating. The frontier AI models referenced throughout this year’s report — capable of finding vulnerabilities across major operating systems and browsers faster than human researchers — have only widened that gap. Within two years, researchers at UC Berkeley project AI will favor attackers over defenders by 31.7%. Governance built for last year’s threat model is already behind.

The Defensive Case for AI Is Still Real — It’s Just Underused

None of this is an argument against using AI in the enterprise, and it would be dishonest to frame it that way. The same report shows AI and automation delivering the single largest cost reduction available to security teams. Organizations that used security AI and automation extensively cut their average breach cost to USD 4.00 million, compared to USD 5.93 million for organizations with no use at all — a savings of USD 1.93 million per breach. Extensive adopters also identified and contained breaches in 215 days, 65 days faster than organizations using none of these tools.

The problem is adoption, not effectiveness. Only 36% of organizations use security AI and automation extensively, up modestly from 32% last year. Their usage skews heavily toward detection and response; deployment in prevention lags well behind. Among the half of breached organizations running AI agents in their security operations center, 56% use them for threat hunting and 54% for automated response, but only 18% apply agents to vulnerability scanning and management — precisely the area where frontier AI models are creating the most exposure. Organizations are pointing their best tools at cleanup, not at the front door. Feeding threat hunting and automated response signals into a unified SIEM platform gives security operations centers the correlation layer needed to extend AI-driven detection into the vulnerability scanning gap the report identifies as underused.

Every governance and access-control finding in this report points to the same practical fix: apply zero trust architecture principles to AI the same way they’ve been applied to networks and identities for the last decade. Continuous verification. Least-privilege access. Policy enforcement at the point of data exchange, not after the fact. Attribute-based access control (ABAC) — evaluating content sensitivity, user or agent role, and request context simultaneously at every access event — is the technical mechanism that makes continuous verification operational rather than aspirational. Kiteworks built its Compliant AI capability and Secure MCP Server around exactly this principle: govern what data an AI system — or an AI agent — can access, use, and exchange, with the same rigor applied to human users, rather than bolting controls on after a model is already in production.

Where the Rest of the Money Moves

A few other findings from this year’s report deserve attention because they show where costs concentrate outside the AI narrative. Healthcare remains the most expensive industry for the 13th consecutive year, averaging USD 6.64 million per breach, even as that figure declined from last year’s USD 7.42 million. Financial services jumped the other direction, up to USD 6.29 million from USD 5.56 million, and financial services and energy together accounted for 62% of all AI-driven breaches studied — a concentration the report calls a systemic risk, since a disruption in either sector cascades into consumer finances, economic systems, and power grids.

Phishing remained the costliest initial attack vector for the fourth consecutive year, averaging USD 5.29 million, with voice and SMS phishing specifically used in 17% of attacks. Ransomware climbed to 39% of breached organizations, up from 34% last year and a 62.5% rise since 2023, and attackers are increasingly weaponizing brand reputation alongside data encryption: 41% of ransomware attacks now include threats of public shaming and media leaks, more common than the traditional tactic of encrypting operational systems.

On the cost-reduction side, a DevSecOps approach was the single largest factor lowering breach costs, cutting the average by USD 253,805. IAM implementation was close behind at USD 225,622, and encryption also ranked among the top reducers at USD 213,478. On the other side of the ledger, supply chain breaches involving a compromised business partner added USD 227,250 on average, the single most expensive cost amplifier the report identified — a reminder that supply chain risk management and third-party risk management remain unglamorous, unavoidable line items in any security budget.

Encryption itself is still not universal, which is worth sitting with given how central it is to every compliance framework in this space. Among breached organizations, 53% hadn’t encrypted sensitive data at rest and in motion at the time of the breach, and another 10% weren’t sure whether it had been encrypted at all. Only 37% could say with confidence that it had. That’s not an AI problem or a frontier-model problem. That’s a basics problem, and it’s one every organization can fix without waiting for a governance committee to finish its charter. Any exposed data in this category likely includes intellectual property and customer records whose loss compounds well beyond the immediate breach cost figures the report captures.

Delay Is the Most Expensive Line Item in the Report

One more pattern threads through every finding above: time is money, almost literally. Breaches that took longer than 200 days to identify and contain averaged USD 5.65 million this year, up 12% from USD 5.01 million last year. Breaches resolved in under 200 days averaged USD 4.32 million — still up 11% year over year, but well below the slower group. The gap between fast and slow response widened rather than narrowed, which tracks with everything the AI-driven attack data shows: attackers are compressing their own timelines while a meaningful share of defenders are not.

Recovery tells a more encouraging story, at least on the surface. Forty-two percent of breached organizations reported fully recovering this year, up from 35% last year and a fourfold improvement over 2024’s 12%. But “recovery” in this research means restored operations, met compliance obligations, and rebuilt customer trust — and 58% of organizations still hadn’t reached that point when researchers collected the data. Nearly one in five organizations needed more than 150 days just to fully recover, on top of the time already spent identifying and containing the breach itself. Add those numbers together and the real cost of a slow-moving incident isn’t captured in the headline average at all. It’s in the months of disrupted operations, delayed contracts, and customer churn that a single dollar figure can’t fully represent.

The organizations identifying breaches fastest weren’t relying on outside help to do it. Internal IT and security teams identified 38% of breaches this year — more than any other source — and did so in 209 days on average, 15% faster than the global average. That’s the strongest argument in the entire report for investing in internal detection capability rather than treating incident response as something to outsource entirely.

What Changes Now

IBM’s own recommendations track closely with what the data has been showing for two consecutive years: shift identity security to continuous, runtime verification rather than a one-time approval; extend that verification to non-human identities, since only 46% of organizations currently secure the machine identities their AI workflows depend on; and treat AI sovereignty — control over where AI systems run, how data is processed, and who has access — as a security requirement, not a philosophical preference.

Eighty-five percent of organizations now say they plan to increase security spending specifically because of new frontier AI model threats, up sharply from 64% before they understood the scale of what those models can do. That’s the right instinct arriving late. The organizations that come out ahead in next year’s report won’t be the ones that spent the most. They’ll be the ones that closed the gap between deploying AI and governing it, before the incident forced the conversation. If your organization is still treating data governance and AI deployment as separate workstreams, this report is the argument for merging them, and Kiteworks secure data exchange is built specifically to enforce that governance at the point where humans and AI agents actually touch sensitive content. The Kiteworks data control pane unifies that enforcement across email, file sharing, managed file transfer, and AI system connections, so the same access control and audit standard applies everywhere sensitive content moves.

To learn more about governing what AI systems and agents can access, use, and exchange, schedule a custom demo today.

Frequently Asked Questions

According to the IBM Cost of a Data Breach Report 2026, the global average cost of a data breach is USD 4.99 million, a 12% increase over the prior year and a new record high. The United States recorded the highest regional average at USD 11.5 million, nearly double the global figure. The report attributes the increase largely to higher detection, escalation, and lost-business costs, which together made up 63% of total breach costs this year. Organizations looking to reduce exposure to these cost categories should evaluate their incident response plan and detection tooling as a starting point.

Security incidents involving an organization’s own AI models or applications grew from 13% of breaches last year to 21% this year, a 61% increase, according to the same IBM report. The growth reflects both wider AI adoption across the enterprise and a governance response that hasn’t kept pace: 92% of organizations with an AI-related breach lacked proper AI access controls at the time of the incident. Closing that gap starts with applying the same IAM discipline to AI systems that organizations already apply to human users and networks. Organizations subject to regulatory compliance obligations should treat this 92% figure as a sector-wide benchmark: regulators increasingly evaluate AI data access governance under the same access control standards that already apply to human user access.

Shadow AI refers to employees using AI tools that haven’t been vetted or approved by their organization’s IT or security teams, similar to shadow IT a decade earlier. The IBM report found shadow AI security incidents more than doubled this year, from 20% to 43% of breached organizations, with average costs rising to USD 5.39 million and regulatory fines occurring in roughly one in five incidents. Because shadow AI tools can actively process and retain sensitive data rather than simply store it, organizations need data classification and policy enforcement at the point content reaches an AI system, not after the fact. Data minimization applied at that same enforcement point — ensuring only the minimum content necessary for a given AI task ever reaches the model — further limits exposure when a shadow AI tool does slip through undetected.

Yes, and the effect is substantial. Organizations that used security AI and automation extensively reported an average breach cost of USD 4.00 million, compared to USD 5.93 million for organizations with no use of these tools — a savings of USD 1.93 million. Extensive users also identified and contained breaches 65 days faster on average. The catch is adoption: only 36% of organizations currently qualify as extensive users, and most concentrate that use in detection and response rather than prevention, which is where tools like SOAR and automated vulnerability management could close the remaining gap.

Start with visibility and access control rather than policy documents. The report shows that structural failures — unsecured APIs, misconfigured cloud environments connected to AI workloads, and missing access controls — caused far more AI-related breaches than any weakness in the underlying models. Organizations should also establish coordination between AI governance and security teams, since only 19% currently do, and extend identity and lifecycle management to non-human identities, which only 46% of organizations currently secure. A risk assessment that maps every AI workload’s current access controls against this year’s 92% failure benchmark gives security and governance teams the prioritized, evidence-based starting point that the report’s findings collectively point toward.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks