AI Security Neglect: Enterprises Face Rising Costs and Risks as Adoption Outpaces Safeguards

Reviewed byNidhi Govil

3 Sources

Share

IBM's Cost of a Data Breach Report 2025 reveals alarming gaps in AI security and governance, with 97% of breached organizations lacking proper AI access controls. Shadow AI and supply chain vulnerabilities emerge as key threats, while AI-related breaches add significant costs to organizations.

AI Security Neglect: A Growing Concern

IBM's Cost of a Data Breach Report 2025 has revealed a concerning trend in the enterprise world: organizations are rapidly adopting AI technologies while neglecting crucial security and governance measures

1

. This rush to implement AI without proper safeguards has caught the attention of attackers, who are already exploiting these vulnerabilities.

Source: The Register

Source: The Register

Key Findings

The report, based on data from 600 organizations globally between March 2024 and February 2025, highlights several alarming statistics:

  1. 13% of organizations reported security incidents involving AI models or applications

    1

    .
  2. A staggering 97% of breached organizations lacked proper AI access controls

    1

    2

    .
  3. 60% of AI-related security incidents resulted in compromised data, while 31% caused operational disruptions

    2

    .
  4. Shadow AI, the unauthorized use of AI tools by employees, added an average of $670,000 to breach costs

    2

    .

The Shadow AI Threat

Shadow AI has emerged as a significant security risk. Organizations reported that security incidents involving shadow AI led to higher rates of compromised personally identifiable information (PII) and intellectual property compared to the global average

2

3

. The lack of oversight and governance for these unofficial AI tools creates an increased risk of exploitation by attackers.

Supply Chain Vulnerabilities

Supply chain compromise was identified as the most common cause of AI-related breaches, accounting for 30% of incidents

1

2

. This category includes compromised apps, APIs, and plug-ins, with the majority of intrusions originating from third-party vendors providing software as a service (SaaS).

Governance Gap

Source: VentureBeat

Source: VentureBeat

The report reveals a significant lack of governance in mitigating AI risks:

  1. 87% of organizations have no governance in place to mitigate AI risks

    1

    .
  2. 63% of breached organizations either don't have an AI governance policy or are still developing one

    2

    3

    .
  3. Two-thirds of breached organizations don't perform regular audits to evaluate risk

    1

    .
  4. Over three-quarters of organizations don't conduct adversarial testing on their AI models

    1

    .

The Cost of Inaction

While the global average cost of a data breach saw a slight decline to $4.5 million, AI-related breaches and shadow AI use significantly increased costs

3

. In the United States, the average data breach cost reached a record high of $10.2 million

3

.

AI as a Double-Edged Sword

Interestingly, the report also highlights the potential benefits of AI in cybersecurity. Organizations using AI and automation extensively shortened their breach response times by 80 days and lowered average breach costs by $1.5 million

2

. However, attackers are also leveraging AI, with 16% of breaches involving AI-powered attacks, primarily for phishing and deepfake impersonation

3

.

Industry Impact

The healthcare sector remains the most vulnerable, with an average breach cost of $7.4 million and the longest time to identify and contain breaches at 279 days

3

. This underscores the critical need for improved security measures in sensitive industries.

Source: Silicon Republic

Source: Silicon Republic

The Path Forward

As AI becomes more deeply embedded in business operations, experts emphasize the need for a fundamental shift in approach. Suja Viswesan, VP of Security and Runtime Products at IBM, warns that "the cost of inaction isn't just financial, it's the loss of trust, transparency and control"

1

. Organizations must prioritize AI security and governance to protect sensitive data and maintain stakeholder confidence in an increasingly AI-driven business landscape.

TheOutpost.ai

Your Daily Dose of Curated AI News

Don’t drown in AI news. We cut through the noise - filtering, ranking and summarizing the most important AI news, breakthroughs and research daily. Spend less time searching for the latest in AI and get straight to action.

© 2025 Triveous Technologies Private Limited
Instagram logo
LinkedIn logo