# IBM finds 92% of companies hit by AI security breaches lacked basic access controls

> Source: <https://the-decoder.com/ibm-finds-92-of-companies-hit-by-ai-security-breaches-lacked-basic-access-controls/>
> Published: 2026-08-03 15:47:08+00:00

# IBM finds 92% of companies hit by AI security breaches lacked basic access controls

**In nearly every AI security incident, the affected company lacked access controls for its AI systems.** That's the finding of IBM's [Cost of a Data Breach Report 2026](https://www.ibm.com/reports/data-breach), based on research by the Ponemon Institute across 602 companies. Among firms that experienced an AI-related incident, 92 percent had inadequate access controls in place.

The problem rarely starts with the model itself: In about one in five affected companies, the entry point was a compromised API, a [connected application](https://the-decoder.com/one-tampered-chatgpt-link-could-spawn-a-rogue-ai-agent-that-took-orders-from-an-attacker-every-five-minutes/), or a misconfigured cloud service. Whether a company runs an open-source or proprietary model made almost no difference.

IBM traces the gaps back to basic oversights that don't require [sophisticated attackers](https://the-decoder.com/hackers-hijacked-high-profile-instagram-accounts-by-simply-asking-metas-ai-chatbot-to-change-the-email/) to exploit. Incidents involving AI cost an average of $5.33 million, compared to $4.70 million for those without an AI component. The global average across all data breaches rose 12 percent to $4.99 million. When attackers themselves used AI, costs jumped to $6.04 million. Without AI, they came in at $5.03 million.

```
AI News Without the Hype – Curated by Humans

					Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.				

					Subscribe now
```

[IBM](https://www.ibm.com/reports/data-breach)
