the feed MANY MINDED · THE BRIEF
SECURITY · friction · impact 2/5 · 2026-08-04 · IBM

The breach report says the model was rarely the problem

IBM and Ponemon put AI-involved breaches at $5.33m against $4.70m without; 92% of hit companies lacked adequate AI access controls.

IBM's Cost of a Data Breach Report 2026, conducted with the Ponemon Institute across 602 companies, was published on 3 August. Its headline finding for AI systems is about configuration rather than capability: 92 percent of companies that suffered an AI-related security incident had inadequate access controls on those systems.

The cost figures around it: breaches involving AI averaged $5.33 million, against $4.70 million for breaches that did not. Where attackers themselves used AI tools, the average rose to $6.04 million. The global average cost of a breach across all categories rose 12 percent to $4.99 million. Where entry points were examined — about a fifth of the affected companies — the common vectors were compromised APIs, connected applications and misconfigured cloud services. The report's own framing is that basic oversights rather than sophisticated attacks enabled most of these, and that this held whether the company used open-source or proprietary models.

That last point is the one worth keeping. The security debate around AI is usually conducted as an argument about which models are dangerous, and this dataset says the model was rarely the thing that failed. Boring controls were.

The caveats are ordinary but real. This is vendor-sponsored research, the AI and non-AI comparison comes from the same dataset without controlling for company size or sector, and the published account gives limited detail on sample demographics.

Source: The Decoder