3 Sources
[1]
Enterprises neglect AI security - and attackers have noticed
IBM report shows a rush to embrace technology without safeguarding it, and as for governance... Organizations rushing to implement AI are neglecting security and governance, IBM claims, with attackers already taking advantage of lax protocols to target models and applications. The findings come
[2]
Shadow AI adds $670K to breach costs while 97% of enterprises skip basic access controls, IBM reports
Want smarter insights in your inbox? Sign up for our weekly newsletters to get only what matters to enterprise AI, data, and security leaders. Subscribe Now Shadow AI is the $670,000 problem most organizations don't even know they have. IBM's 2025 Cost of a Data Breach Report, released today in
[3]
AI cyberattacks outpace security as sector still the wild west
IBM's latest Cost of a Data Breach report finds that AI is already an easy and high value target. A new IBM report finds that artificial intelligence adoption is "greatly" outpacing AI security and governance. The company has been issuing its annual Cost of a Data Breach report for two decades
Share
Copy Link
IBM's Cost of a Data Breach Report 2025 reveals alarming gaps in AI security and governance, with 97% of breached organizations lacking proper AI access controls. Shadow AI and supply chain vulnerabilities emerge as key threats, while AI-related breaches add significant costs to organizations.
IBM's Cost of a Data Breach Report 2025 has revealed a concerning trend in the enterprise world: organizations are rapidly adopting AI technologies while neglecting crucial security and governance measures
1
. This rush to implement AI without proper safeguards has caught the attention of attackers, who are already exploiting these vulnerabilities.
Source: The Register
The report, based on data from 600 organizations globally between March 2024 and February 2025, highlights several alarming statistics:
1
.1
2
.2
.2
.Shadow AI has emerged as a significant security risk. Organizations reported that security incidents involving shadow AI led to higher rates of compromised personally identifiable information (PII) and intellectual property compared to the global average
2
3
. The lack of oversight and governance for these unofficial AI tools creates an increased risk of exploitation by attackers.Supply chain compromise was identified as the most common cause of AI-related breaches, accounting for 30% of incidents
1
2
. This category includes compromised apps, APIs, and plug-ins, with the majority of intrusions originating from third-party vendors providing software as a service (SaaS).
Source: VentureBeat
The report reveals a significant lack of governance in mitigating AI risks:
1
.2
3
.1
.1
.While the global average cost of a data breach saw a slight decline to $4.5 million, AI-related breaches and shadow AI use significantly increased costs
3
. In the United States, the average data breach cost reached a record high of $10.2 million3
.Related Stories
Interestingly, the report also highlights the potential benefits of AI in cybersecurity. Organizations using AI and automation extensively shortened their breach response times by 80 days and lowered average breach costs by $1.5 million
2
. However, attackers are also leveraging AI, with 16% of breaches involving AI-powered attacks, primarily for phishing and deepfake impersonation3
.The healthcare sector remains the most vulnerable, with an average breach cost of $7.4 million and the longest time to identify and contain breaches at 279 days
3
. This underscores the critical need for improved security measures in sensitive industries.
Source: Silicon Republic
As AI becomes more deeply embedded in business operations, experts emphasize the need for a fundamental shift in approach. Suja Viswesan, VP of Security and Runtime Products at IBM, warns that "the cost of inaction isn't just financial, it's the loss of trust, transparency and control"
1
. Organizations must prioritize AI security and governance to protect sensitive data and maintain stakeholder confidence in an increasingly AI-driven business landscape.Summarized by
Navi
[1]
[2]
[3]
14 Aug 2026•Technology

08 Sept 2026•Technology

19 May 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
