The twenty-first Cost of a Data Breach report landed with a headline everyone quoted: the global average cost of a breach reached USD 4.99 million, up 12% on last year and the highest the study has recorded. In the United States the average hit USD 11.5 million, nearly double the global figure.
Those numbers will be on a hundred slides by Christmas. They are not the interesting part.
The finding nobody put in the headline
Buried in the AI section is a single sentence that reframes the whole report. Among the organisations that experienced an AI-related breach, 92% lacked proper AI access controls.
Not 92% had a weak model. Not 92% were running an unpatched gateway. Ninety-two per cent had no working answer to the question of what their AI systems were allowed to reach.
Set that beside the growth rate. AI-related breaches rose to 21% of the study from 13% the year before — a 61% increase in twelve months. The attack surface expanded fast, and the control that governs it was largely absent.
Where the money actually goes
The report is unusually clear about cost composition this year. Detection and escalation and lost business together made up 63% of the average breach cost — USD 3.18 million of the USD 4.99 million.
That is worth sitting with. The majority of what a breach costs is not the fix. It is the period before anyone understands what happened, and the damage done while that period runs.
A cross-system AI incident is the worst possible shape for that cost profile. One question touches six systems in under two seconds and assembles an answer that names none of its sources. Each of those six systems logged a permitted request. None of them logged the answer. Reconstructing what was exposed means reconstructing an assembly that happened outside every system that participated in it — which is exactly the work that runs the detection and escalation meter.
Shadow AI, doubled
Incidents involving shadow AI — people using AI tools the organisation never approved — more than doubled, to 43% from 20%. Those breaches cost more than the average, at USD 5.39 million, and in roughly one in five cases the organisation paid a regulatory fine.
The report also finds 68% of organisations lacked AI governance capable of managing AI or detecting shadow AI at all, up from 63%.
The two findings are the same finding. An organisation that cannot see which AI tools are running also cannot see what those tools can reach, because the second question is harder than the first and nobody has answered the first.
What kind of problem this is
The temptation is to read a report like this as an argument for more detection. The cost data even seems to support it: detection and escalation is the biggest line, so make detection faster.
We would read it the other way. Detection is expensive here because the exposure was assembled somewhere nothing was watching. You are not paying to find an intruder. You are paying to reconstruct which permitted answers, given to which people, added up to something they should not have had.
The controls that would have made that cheap are not detection controls. They are authorization controls: a record of what each call was allowed to return, computed against the person the agent was acting for, written down at the moment the decision was made.
That is what the 92% figure is pointing at, and it is the least-quoted number in the report.
The honest caveats
This is sponsored research, and it says so. Ponemon Institute conducts the study; IBM sponsors, analyses and publishes it. The sample is 602 organisations with 3,558 individual interviews — substantial, but self-reported, and organisations that agree to be interviewed about a breach are not a random sample of organisations that had one.
The AI-specific findings are also new enough that the year-on-year comparisons rest on one prior year of data. A 61% increase off a small base is a real signal about direction and a weak one about magnitude.
None of that touches the 92%. A control gap present in nine of every ten AI-related breaches is not a sampling artefact.
What we would do with it
If you are reading this report to decide where next year’s budget goes, the question it actually poses is narrow:
For the agents already running in your environment, can you say what each one could reach on behalf of the person it is acting for — across every system at once?
If the answer is no, you are in the 92%, and the rest of the report is a description of what that costs.