AI Models

IBM Report: 92% of AI Security Incidents Trace Back to Missing Access Controls

IBM's Cost of a Data Breach Report 2026 reveals that 92% of AI-related security incidents stem from missing access controls, not the AI models themselves. Breaches involving AI cost an average of $5.33 million, rising to $6.04 million when attackers use AI. The report highlights basic oversights like misconfigured APIs and cloud services as primary entry points.

Neura News

Neura News

Neura Market Editorial

August 3, 20263 min read
IBM Report: 92% of AI Security Incidents Trace Back to Missing Access Controls

A new report from IBM finds that most companies hit by AI-related security incidents were missing a basic defense. The Cost of a Data Breach Report 2026, published Aug. 3, 2026, shows that 92% of companies experiencing AI-related security incidents lacked basic access controls for their AI systems.

The research, conducted by the Ponemon Institute across 602 companies, points to a pattern that has little to do with the sophistication of the AI itself. In about 1 in 5 affected companies, the entry point was a compromised API, connected application, or misconfigured cloud service. The problem rarely starts with the model itself.

Access Controls Are the Missing Link

IBM traces the gaps back to basic oversights that don't require sophisticated attackers to exploit. Access controls, the fundamental security measure that governs who can reach a system, were simply not in place for many AI deployments.

The report notes that whether a company ran an open-source or proprietary model made almost no difference. Security outcomes did not hinge on the choice of model type. Instead, the surrounding infrastructure, such as APIs and cloud configurations, proved to be the weak points.

The Cost of AI Incidents

The financial impact of these breaches is significant. Incidents involving AI cost an average of $5.33 million. That compares to $4.70 million for incidents without an AI component.

The gap widens when attackers themselves use AI. When attackers used AI, costs jumped to $6.04 million. Without AI use by attackers, costs were $5.03 million.

The #1 Newsletter in AI

Stay ahead of the AI curve

The most important updates, news, and content — delivered weekly.

No spam. Unsubscribe anytime.

Global Breach Costs Rise

The broader picture shows a steady climb in breach expenses. The global average across all data breaches rose 12% to $4.99 million. That figure covers every type of incident in the study, not just those tied to AI.

The report, an annual industry benchmark, underscores a growing concern in enterprise environments. AI security incidents are no longer a niche problem. They are becoming a routine part of the threat landscape.

Simple Fixes, Big Consequences

The findings suggest that many organizations are skipping the basics. IBM traces the gaps back to basic oversights that don't require sophisticated attackers to exploit. A misconfigured cloud service or an exposed API can be enough to open the door.

The report does not blame the models themselves. It points instead to the systems around them. Companies that fail to lock down access controls are leaving their AI investments exposed.

For organizations running AI, the lesson is straightforward. The model is only part of the equation. The infrastructure that supports it needs the same rigor as any other critical system.

Related on Neura Market

More from Neura News

AI Models

42 Mathematicians Urge Royal Society to Warn Government and Media About AI Existential Risk

Forty-two mathematical fellows, including Fields Medal winners Martin Hairer, Peter Scholze, and Wendelin Werner, have signed an open letter urging the Royal Society to warn the UK government and media about existential risks from advanced AI. The letter follows recent breakthroughs in which leading models solved open research problems, including a Millennium Problem. None of the signatories are affiliated with AI companies. The group warns that AI labs' estimates of existential risk above ten percent must not be dismissed as hype, and that by the time the situation becomes obvious to the public, it may be too late to act.

Sep 18·2 min read
Developer

Steve Yegge Shuts Down Gas Town After Failing to Build Anything Else With It

Steve Yegge shut down Gas Town, his ultra-vibed coding agent orchestrator, after admitting he never built anything else with it despite heavy subscription spend. Databricks reported a 60% coding spend increase after rolling out GPT-6 Astra to 3,500 engineers, OpenAI published a misalignment disclosure framework with six case reports, and Xiaomi ran MiMo-V2.6 RL training in public with live telemetry.

Sep 18·21 min read