IBM and the Ponemon Institute published the 2025 Cost of a Data Breach Report in July 2025, documenting the first decline in global breach costs in five years even as AI-related exposures emerged as a major new cost driver. The global average breach cost fell 9% to $4.44 million, down from $4.88 million the year prior, with the report attributing the drop to faster identification and containment, a mean time of 241 days that is the lowest in nine years. The U.S. average, by contrast, climbed to a record $10.22 million, and healthcare remained the costliest industry at $7.42 million for the fifteenth consecutive year. Intellectual-property records were the most expensive data type at $178 per record. The headline AI finding was a pronounced governance gap: 97% of organizations that suffered an AI-related security incident lacked proper AI access controls, and 63% of the 600 organizations Ponemon surveyed had no AI governance policies at all. Heavy use of shadow AI added roughly $670,000 to the average breach cost, while extensive use of AI and automation in defense saved about $1.9 million per incident. Thirteen percent of organizations reported attacks that directly impacted their AI models or applications, a baseline the report frames as likely to grow sharply over the following twelve months.
Blog
Insights on AI security and development
Learn how to protect your code, understand AI risks, and build secure workflows with expert insights.

