IBM's 2025 Cost of a Data Breach Report, drawing on Ponemon Institute research across 600 organizations, quantified for the first time the financial drag created by ungoverned enterprise AI adoption. The report found that 97% of breached organizations that suffered an AI-related security incident lacked proper AI access controls, and 63% had no AI governance policies in place to manage AI use or prevent employees from using shadow AI tools. High levels of shadow AI, where workers download or use unapproved internet-based AI tools, added an extra USD 670,000 to the global average breach cost, with AI-related breaches producing broad data compromise and operational disruption that interrupted sales orders, customer service and supply chains. Even with these new risks, the global average breach cost fell 9% to USD 4.44 million from USD 4.88 million the prior year, the first decline in five years, driven by AI-powered defenses that cut mean detection and containment time to 241 days, the lowest in nine years. The report also noted that 13% of surveyed organizations had experienced an attack that impacted their AI models or applications, and urged tighter identity and access management, cloud security review, AI governance, and continuous staff training.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

