Most AI-Related Breaches Skip the Model, IBM’s 2026 Report Finds

A cloud security engineer works at a workstation with two monitors in a bright, modern office setting.

When attackers breached an AI system this year, they usually reached it through an exposed API or a misconfigured cloud bucket sitting right next to the model, not by defeating the model itself. IBM’s 2026 Cost of a Data Breach report, conducted by the Ponemon Institute across 600 organizations worldwide, leads its coverage with AI-enabled attacks. Its own data on AI-related breaches tells a plainer story: the break-in almost always lands in the plumbing around the model.

  • The report counts one in four malicious breaches as AI-enabled, led by deepfake impersonation and AI-enabled malware, yet the AI breaches it examines rarely involve beating the model.
  • Compromised APIs and cloud misconfigurations each accounted for 27% of the breaches that reached an AI system, the two most common ways in.
  • Only 40% of the organizations breached through their AI had access controls on those models and data.
  • AI and automation in security operations cut breach costs by nearly $2 million, yet one in four security teams still run without them.

Where AI-Related Breaches Actually Land

The break-in usually starts at the edge of the AI system. One in five organizations reported a breach that reached an AI model or application, and hardly any of it involved outsmarting the model. The most common ways in were compromised application programming interfaces (APIs), applications, or plug-ins, and cloud misconfigurations affecting AI workloads, each at 27%. Only 40% of those victims had access controls on their models and data, the plainest gap the report puts in front of security teams.

The overall bill is what makes those open doors expensive. The average breach reached $6 million, up 35% from $4.44 million a year earlier, and the United States set a record at $11.5 million, nearly double the global average. Healthcare stayed the costliest industry at $6.64 million, even after dropping from $7.42 million, because patient records still pay off for identity theft and insurance fraud.

The 247-Day Detection Gap Behind the AI Headlines

The report opens on AI-enabled attacks, and then its own sources spend the rest of it tracing the AI-related breaches back to ordinary failures around the model. Ariel Parnes, co-founder of cloud security firm Mitiga, says attackers are compromising the APIs, plug-ins, and cloud settings around models rather than breaking them. “These attacks land in the telemetry of the cloud and identity environments, not in the model itself, so the defense is behavioral detection across everything the AI touches,” Parnes says. Even the fixes aim slightly wide. Three in four enterprises say frontier AI threats are pushing them to rethink how they deploy agents across security operations, yet only 18% point those agents at vulnerability management.

The cost driver underneath is old and dull: how long it takes to notice. The mean time to identify and contain a breach rose to 247 days this year, the first increase after a five-year decline, and every extra week of dwell time adds to the invoice. “When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” says Suja Viswesan, VP of IBM Security Software. AJ Thompson, who sits on IBM’s Worldwide Security Advisory Council, is blunter: the bigger cost driver is still how fast you spot a breach, rather than how sophisticated the attack is.

Two forces stretch the same gap. AI lets attackers move faster and cheaper, while defenders still take 247 days to catch them, and that distance between attacker speed and defender awareness is where the $6 million goes. A thin security bench pulls it wider: IBM pegs the skills shortage as a leading cost amplifier, adding about $180,000 to the average breach. Shadow AI, the unsanctioned employee use of AI tools, pulls it wider again, with related incidents more than doubling to 43% in a year, up from 20%.

How to Lock the API Before the 247-Day Clock Starts

For chief information security officers (CISOs), the order is unglamorous on purpose: shut the doors attackers actually use, then shorten the time it takes to notice them, then drag shadow AI into daylight.

Put access controls on the models and their APIs first – Only 40% of breached organizations had them, even though compromised interfaces and cloud misconfigurations, each at 27%, were the top ways in. Kayne McGladrey, a CISSP-certified security advisor and IEEE senior member, says to “treat your models and their APIs like crown jewels.”

Buy down the 247-day detection window with automation – IBM credits AI and automation inside AI-driven security operations with cutting nearly $2 million from the average breach, yet one in four teams still run without them. Point that tooling at the cloud and identity telemetry around every model, the ground Parnes says these attacks actually cross.

Bring shadow AI under governance before it rivals supply-chain risk – Unsanctioned AI use doubled to 43% as a breach-cost factor, and unapproved employee tools, in the words of Huntress security operations manager Dray Agha, “introduce unmanaged vulnerabilities into corporate environments.” More than half of breached organizations now plan to invest in AI security and governance tools, an 88% jump from last year.

The one in five companies that watched an attacker reach an AI model through an exposed API can get the bill back down the same way it went up. They lock the interface, close the 247-day gap the report keeps circling, and stop treating AI-related breaches as a model problem when the model was never the way in.

Join our LinkedIn group Information Security Community!

Holger Schulze
Holger Schulze is the founder and publisher of Cybersecurity Insiders, an independent cybersecurity research and media company. He writes about how AI is reshaping cybersecurity, where attackers are moving faster than defenses, and what security leaders can do about it. His work draws on original research and real-world incidents, translating both into practical guidance for security teams. Holger moderates the Information Security Community on LinkedIn, one of the largest professional networks in cybersecurity. Connect at linkedin.com/in/holger-schulze

No posts to display