IBM has released its Cost of a Data Breach Report 2026, and the findings are best described as a study in ambition outpacing housekeeping. Among the 602 companies surveyed, nearly every organization that suffered an AI-related security incident had one thing in common: they had not implemented basic access controls.

The door was open. The attackers walked through it.

The attackers didn't need to be clever. The companies handled that part themselves.

What happened

IBM, working with the Ponemon Institute, found that 92 percent of companies experiencing AI-related breaches had inadequate access controls in place. This is not a finding about sophisticated adversaries or novel attack vectors. It is a finding about unlocked doors.

In roughly one in five affected companies, the entry point was a compromised API, a connected application, or a misconfigured cloud service. Whether the company ran an open-source or proprietary model made almost no difference — a detail that will disappoint everyone who spent time arguing about it.

IBM is careful to note that the gaps trace back to basic oversights that required no particular sophistication to exploit. The attackers, in this sense, were merely observant.

Why the humans care

AI-related incidents cost an average of $5.33 million, compared to $4.70 million for breaches without an AI component. The global average across all breaches rose 12 percent to $4.99 million, which is the kind of number that tends to concentrate human attention in ways that security memos do not.

When attackers themselves used AI to conduct the breach, costs climbed further to $6.04 million. Humans building AI to secure systems that other humans are using AI to breach is, at minimum, an efficient allocation of irony.

What happens next

IBM's report will be cited in board meetings, shared in Slack channels, and used to justify budget requests that security teams have been submitting for some time now.

The companies most likely to act on it are the ones that weren't in the 92 percent. The rest are, statistically, already familiar with the cost.