What the 2026 Cost of a Data Breach report says about access

IBM and Ponemon put a number on the AI breach year. The one that matters is not the headline cost — it is that 92% of the organisations breached through AI lacked proper AI access controls.

Research review · Sep 2026

Reviewing: IBM and Ponemon Institute, Cost of a Data Breach Report 2026

The twenty-first Cost of a Data Breach report landed with a headline everyone quoted: the global average cost of a breach reached USD 4.99 million, up 12% on last year and the highest the study has recorded. In the United States the average hit USD 11.5 million, nearly double the global figure.

Those numbers will be on a hundred slides by Christmas. They are not the interesting part.

The finding nobody put in the headline

Buried in the AI section is a single sentence that reframes the whole report. Among the organisations that experienced an AI-related breach, 92% lacked proper AI access controls.

Not 92% had a weak model. Not 92% were running an unpatched gateway. Ninety-two per cent had no working answer to the question of what their AI systems were allowed to reach.

Set that beside the growth rate. AI-related breaches rose to 21% of the study from 13% the year before — a 61% increase in twelve months. The attack surface expanded fast, and the control that governs it was largely absent.

Where the money actually goes

The report is unusually clear about cost composition this year. Detection and escalation and lost business together made up 63% of the average breach cost — USD 3.18 million of the USD 4.99 million.

That is worth sitting with. The majority of what a breach costs is not the fix. It is the period before anyone understands what happened, and the damage done while that period runs.

A cross-system AI incident is the worst possible shape for that cost profile. One question touches six systems in under two seconds and assembles an answer that names none of its sources. Each of those six systems logged a permitted request. None of them logged the answer. Reconstructing what was exposed means reconstructing an assembly that happened outside every system that participated in it — which is exactly the work that runs the detection and escalation meter.

Shadow AI, doubled

Incidents involving shadow AI — people using AI tools the organisation never approved — more than doubled, to 43% from 20%. Those breaches cost more than the average, at USD 5.39 million, and in roughly one in five cases the organisation paid a regulatory fine.

The report also finds 68% of organisations lacked AI governance capable of managing AI or detecting shadow AI at all, up from 63%.

The two findings are the same finding. An organisation that cannot see which AI tools are running also cannot see what those tools can reach, because the second question is harder than the first and nobody has answered the first.

What kind of problem this is

The temptation is to read a report like this as an argument for more detection. The cost data even seems to support it: detection and escalation is the biggest line, so make detection faster.

We would read it the other way. Detection is expensive here because the exposure was assembled somewhere nothing was watching. You are not paying to find an intruder. You are paying to reconstruct which permitted answers, given to which people, added up to something they should not have had.

The controls that would have made that cheap are not detection controls. They are authorization controls: a record of what each call was allowed to return, computed against the person the agent was acting for, written down at the moment the decision was made.

That is what the 92% figure is pointing at, and it is the least-quoted number in the report.

The honest caveats

This is sponsored research, and it says so. Ponemon Institute conducts the study; IBM sponsors, analyses and publishes it. The sample is 602 organisations with 3,558 individual interviews — substantial, but self-reported, and organisations that agree to be interviewed about a breach are not a random sample of organisations that had one.

The AI-specific findings are also new enough that the year-on-year comparisons rest on one prior year of data. A 61% increase off a small base is a real signal about direction and a weak one about magnitude.

None of that touches the 92%. A control gap present in nine of every ten AI-related breaches is not a sampling artefact.

What we would do with it

If you are reading this report to decide where next year’s budget goes, the question it actually poses is narrow:

For the agents already running in your environment, can you say what each one could reach on behalf of the person it is acting for — across every system at once?

If the answer is no, you are in the 92%, and the rest of the report is a description of what that costs.

What could your agents reach for the person asking?

Contact sales

Fill out the form and we will be in touch.

Start with a scan

Ready to find out what your agents can reach before somebody else does?

Tell us a bit about your setup and we will be in touch.