Site navigation

AI Is Driving Data Breaches, IBM Finds

Elizabeth Greenberg

,

ai data breaches
IBM found that AI is fast becoming a target and a tool for cybersecurity threats. 

AI adoption is greatly outpacing AI security and governance, according to IBM’s new Cost of a Data Breach Report.

While the overall number of organisations experiencing an AI-related breach is a small representation of the researched population, this is the first time security, governance, and access controls for AI have been studied in this report, which suggests AI is already an easy, high value target.

Over one in ten (13%) of organisations reported breaches of AI models or applications, while 8% of organisations reported not knowing if they had been compromised in this way.

Of those compromised, 97% report not having AI access controls in place.

As a result, 60% of the AI-related security incidents led to compromised data and 31% led to operational disruption.

This year’s results show that organisations are bypassing security and governance for AI in favour of do-it-now AI adoption. Ungoverned systems are more likely to be breached – and more costly when they are.

“The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it,” said Suja Viswesan, vice president, Security and Runtime Products, IBM.

“The report revealed a lack of basic access controls for AI systems, leaving highly sensitive data exposed, and models vulnerable to manipulation. As AI becomes more deeply embedded across business operations, AI security must be treated as foundational. The cost of inaction isn’t just financial, it’s the loss of trust, transparency and control.”

However, the report did reveal that organisations using AI and automation extensively throughout their security operations saved an average $1.9 million in breach costs and reduced the breach lifecycle by an average of 80 days.

The 2025 report, conducted by Ponemon Institute, sponsored and analysed by IBM, is based on data breaches experienced by 600 organisations globally from March 2024 through February 2025.

Breaches and the AI Era

AI governance policies are lacking, with 63% of breached organisations either not having and AI governance policy, or still in the development stage. Of the organisations that have AI governance policies in place, only 34% perform regular audits for unsanctioned AI.

One in five organisations reported a breach due to shadow AI, the report found, with only 37% having policies to manage AI or detect shadow AI.

Organisations that used high levels of shadow AI observed an average of $670,000 in higher breach costs than those with a low level or no shadow AI. Security incidents involving shadow AI led to more personally identifiable information (65%) and intellectual property (40%) being compromised compared to the global average (53% and 33% respectively).

AI is also making attacks smarter, with 16% of studied breaches involving attackers using AI tools, most often for phishing or deepfake impersonation attacks.


Recommended reading


Financial Costs of Breaches

The global average cost of a data breach fell to $4.44 million, the first decline in five years, IBM found.

The global average breach lifecycle, which is the mean time to identify and contain a breach, including restoring services, dropped to 241 days, a 17-day reduction from last year. Organisations which detected the breaches internally observed a $900,000 savings on breach costs compared to those disclosed by an attacker.

IBM found that healthcare breaches remain the costliest, averaging $7.42 million, even as the sector saw a $2.35m reduction in costs compared to last year. Breaches in this sector took the longest to identify and contain at 279 days , 5 weeks longer than the global average.

Last year, organisations pushed back against ransom demands, with more opting not to pay (63%) compared to the year prior (59%). As more organisations refuse to pay ransoms, the average cost of an extortion or ransomware incident remains high, particularly when disclosed by an attacker ($5.08m).

There was a significant reduction the number of organisations that said they plan to invest in security following a breach, 49% in 2025 compared to 63% in 2024. Less than half of those that plan to invest in security post-breach will focus on AI-driven security solutions or services.

Operational Disruption

Nearly all organisations studies suffered operational disruption following a data breach, the 2025 IBM report found. This level of disruption is taking a toll on recovery timelines. Among organisations that reported recovery, most took more than 100 days on average to do so.

However, compared to consequences of a breach continued to extend beyond containment. While down compared to the year prior, nearly half of all organisations reported that they planned to raise the price of goods or services because of the breach and nearly one-third reported price increases of 15% or more.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data