IBM: AI-Driven Breaches Push Average Cost to Record $5 Million
IBM and the Ponemon Institute published the 2026 Cost of a Data Breach Report on July 29, 2026. The headline number is $4.99 million, the global average cost of a breach, a 12% increase over last year and a record high. AI is not the whole of that increase, which IBM attributes largely to detection, escalation and lost business costs, but it is the part moving fastest. AI-driven attacks rose 56% year over year, led by deepfake impersonation and AI-enabled malware, and the breaches that were AI-enabled cost about $6 million, roughly a million above the global average. The report adds that 92% of organizations that suffered an AI-related breach did not have proper AI-access controls in place.
The 92% is what turns this into a documentation problem. Where a state has enacted the NAIC Insurance Data Security Model Law, a licensee owes a written information security program built on a risk assessment, and a domiciled insurer in the states that took up the annual certification signs for that program every February 15. Access controls on an AI system belong in that file. A breach is when someone outside the security team reads it, and among the organizations that have already been through one, IBM found it mostly was not there.
The report also contains a counterweight. IBM’s X-Force write-up puts the saving from extensive use of AI and automation in security at $1.93 million per breach against organizations using none. The gap between attackers using AI and defenders not using it is widening, and the cost curve is following. Breached organizations are reacting to that: 85% said they plan to increase spending on security tools and governance, which means the market for AI security vendors is about to get crowded. The procurement question is whether a vendor can document its own AI well enough to survive the exam the carrier is preparing for.
Pull the AI inventory and check what each entry actually records. An entry that names a system says nothing about who could reach it, what they could do with it, and whether any of that was logged. Those three fields are what turn a list into evidence, and the inventory build behind Exhibit A’s counts sets out what each entry has to carry.