IBM Finds AI-Enabled Breaches Cost $6 Million on Average IBM's 2026 Cost of a Data Breach Report, released July 29, found that one in four malicious breaches were AI-enabled, costing an average of $6 million, roughly $1 million more than the global average of $4.99 million. The report also found that organizations using AI and automation in security operations reduced breach costs by nearly $2 million on average, but one in four organizations had not adopted these tools. IBM Report Finds AI Raises Breach Costs IBM released its 2026 Cost of a Data Breach Report on July 29, finding that one in four malicious breaches were AI-enabled and cost an average of $6 million. IBM reported that the global average breach cost reached $4.99 million, up 12% year over year, while organizations using AI and automation in security operations reduced breach costs by nearly $2 million on average. IBM released its 2026 Cost of a Data Breach Report on July 29, reporting that one in four malicious breaches were AI-enabled, a 56% increase from the prior year. According to IBM, AI-enabled breaches cost organizations an average of $6 million , roughly $1 million more than the report's $4.99 million global average cost for all breaches. The report places the global average at $4.99 million, up 12% from IBM's 2025 figure. Cybersecurity Dive reported that attacks involving model inversion and prompt injection also cost roughly $6 million on average, extending the issue beyond AI-assisted phishing or malware to attacks against AI systems themselves. AI-enabled attacks add cost and exposure IBM identified deepfake impersonation and AI-enabled malware as major contributors to AI-enabled breaches. HIPAA Journal reported that deepfake and impersonation activity represented 45% of AI-driven attacks in the study, followed by AI-generated malware at 19% and AI-generated phishing or other communications at 17%. IBM also reported that more than 20% of organizations experienced a breach targeting AI models or applications. Cybersecurity Dive cited a related finding that 92% of organizations reporting attacks on AI models had not properly controlled access to those tools. That result is notable because model access can expose not only application interfaces, but also connected data sources, agent permissions, and operational workflows. The report also found that breach containment is taking longer. HIPAA Journal reported that the average time to identify and contain a breach rose 2.5% year over year to 247 days, while removable-media and supply-chain incidents took 258 days on average. The same source attributed rising costs across sectors largely to detection, escalation, and lost-business expenses. Security operations adoption remains uneven IBM reported that organizations using AI and automation in security operations reduced breach costs by almost $2 million on average, but one in four organizations had not adopted these tools in their security operations. More than half of respondents reported using agents for threat detection and containment, according to IBM, while only 18% used agents for vulnerability management. Cybersecurity Dive similarly reported that about half of breached organizations used AI agents to hunt threats, but fewer than one in five used agents to scan for and manage network vulnerabilities. IBM Security Software VP Suja Viswesan said the priority is to reduce the gap between discovery and remediation by building remediation into development workflows, securing identity at runtime, and fixing risks more quickly. IBM and the Ponemon Institute also found that 85% of organizations intended to increase security spending after learning about advanced frontier-AI cyber capabilities, compared with 64% that reported plans to increase spending after experiencing a breach. For security and ML teams, the findings reinforce a broader operational pattern: deploying detection agents without comparable controls for exposure discovery, identity, and remediation can leave an uneven defense posture. Model and agent deployments introduce additional interfaces to govern, including prompt inputs, tool permissions, retrieval systems, service identities, and audit trails. Key Points - 1IBM found AI-enabled malicious breaches averaged $6 million, placing them roughly $1 million above the global breach-cost average. - 2More than half of respondents used agents for detection, but only 18% applied them to vulnerability management, according to IBM. - 3Comparable AI security deployments require governance across model access, tool permissions, retrieval systems, identities, and remediation workflows. Scoring Rationale The report provides measurements on AI-enabled attacks, model security controls, and security-agent adoption for security leaders evaluating AI risk and automation investments. Sources Public references used for this report. Practice interview problems based on real data 1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with. Try 250 free problems /problems