The short answer
The average data breach now costs $4.99 million, a record, and breaches involving AI cost about $6 million. IBM's 2026 Cost of a Data Breach Report — conducted by the Ponemon Institute across 602 breached organisations between March 2025 and February 2026 — found the global average rose 12% year over year to a new high. One in four malicious breaches were AI-enabled, a 56% jump, driven by deepfake impersonation and AI-written phishing and malware.
The more useful signal for engineering leaders is where the new cost is coming from: attackers are using AI while defenders are still governing it on paper. If your teams build or buy AI-powered software, the report is less a headline than a to-do list — inventory where AI runs, put controls around it, and match attacker speed with automation in your own detection and response.
What did IBM actually find?
The 2026 edition of IBM's annual study reports a global average breach cost of $4.99 million, a 12% increase on the prior year and the highest figure the report has recorded. The rise was driven largely by higher detection and escalation costs and by lost business — the revenue and customers that leave after an incident. The research was conducted by the Ponemon Institute and sponsored and analysed by IBM, based on real breaches at 602 organisations worldwide between March 2025 and February 2026, so it reflects incidents, not projections.
The AI story sits inside that number. One in four malicious breaches were AI-enabled — a category that grew 56% year over year — and those breaches cost about $6 million on average, roughly $1 million more than the overall figure. The AI in question is mostly on the attacker's side: deepfake impersonation of executives and staff, AI-generated phishing, and malware that adapts. Separately, more than one in five organisations said they had suffered a breach that targeted their own AI models or applications, with compromised APIs, applications or plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%) as the leading causes.
Why are AI-enabled breaches costlier?
Cost in this report tracks closely with time to detect and contain, and AI compresses the attacker's side of that clock. A convincing deepfake voice call or an AI-written spear-phish gets a foothold faster and with fewer of the tell-tale mistakes that used to trip alarms. Adaptive malware changes shape to slip past static rules. When the intrusion is quieter and quicker, defenders find it later, dwell time grows, and the lost-business and response costs that dominate the total keep accruing.
There is a defensive counterpart, and it is the most actionable line in the report: organisations that used AI and automation extensively across their security operations saved an average of almost $2 million per breach compared with those that did not. That is not a case for buying an AI security product on faith — it is evidence that both sides of the fight are moving to machine speed, and the side still working purely at human speed pays for the difference. Yet about one in four organisations have not adopted these tools at all, which is a large share of the sample effectively conceding the tempo.
For teams that build software, the uncomfortable read is that a lot of this is your attack surface, not just the security team's. Compromised APIs, applications and plug-ins were a leading cause of AI-related breaches. Those are things engineers ship. Folding AI apps and their integrations into the same security review and testing discipline as the rest of the product is what keeps a new AI feature from quietly becoming a new way in.
What is shadow AI and why does it matter?
Shadow AI is the AI equivalent of shadow IT: tools adopted without security or IT oversight. It is an employee pasting customer data into a consumer chatbot, a team wiring an unsanctioned model into a workflow, or an AI feature that shipped without ever going through review. The report found shadow AI linked to breaches at roughly one in five organisations, adding as much as $670,000 to the average breach cost — and, more tellingly, that most organisations lacked the governance to manage AI or even detect its unsanctioned use, with only a minority requiring any approval before AI is deployed.
The reason shadow AI is expensive is simple: you cannot protect, monitor or patch a system you do not know exists. An ungoverned model connected to production data has no access controls, no logging and no owner, so a breach through it is both more likely and harder to trace. The fix is not a ban, which only pushes usage further into the shadows — it is a lightweight, enforceable path to sanctioned AI, plus the visibility to see what is actually running. Governance here is a security control, not a compliance formality.
What it means for US & EU teams
For US teams, the practical priority is visibility and controls around AI. Inventory where AI is used across your products and internal workflows — including the tools nobody sanctioned — and put access controls, logging and rate limits around AI applications and the APIs and plug-ins they depend on. Because lost business is a leading cost driver, faster detection pays for itself: extending AI and automation into your own monitoring is one of the few moves the data shows actually lowers the bill.
EU teams carry an added regulatory dimension on the same facts. Under the GDPR's security-of-processing duties, an ungoverned model touching personal data is hard to defend, and the EU AI Act adds obligations around documentation, risk management and oversight for higher-risk uses. In regulated sectors such as FinTech and HealthTech, a shadow-AI tool that leaks data is not only a breach cost but a compliance exposure, and the access-control and logging gaps the report highlights are exactly what auditors probe. Governing AI use and documenting it is part of the paper trail, not an optional extra.
The durable takeaway is the same on both sides of the Atlantic: AI has become part of your attack surface and your defence at the same time, and the record cost reflects the gap between how fast attackers adopted it and how slowly most organisations governed it. The teams that come out ahead treat AI features as assets to inventory, secure and review — not experiments that quietly reach production.
What to do this quarter
Treat this as a scoped programme, not an open-ended one. Here is a finishable version.
- Inventory your AI. List every place AI runs across products and workflows, including unsanctioned tools; you cannot secure what you cannot see.
- Lock down the integrations. Put access controls, authentication, logging and rate limits around AI apps and the APIs, plug-ins and cloud workloads they call — the leading causes of AI-related breaches.
- Write a short AI governance policy. Require a lightweight review before AI ships and a sanctioned path to approved tools, so shadow AI has somewhere legitimate to go.
- Automate detection and response. Extend AI and automation into monitoring so defenders match attacker speed — the move the report ties to almost $2M in savings.
- Rehearse the AI-era incident. Update playbooks for deepfake impersonation and AI-driven phishing, including out-of-band verification for high-risk requests.
- Map it to compliance. For EU or regulated data, document controls against GDPR and EU AI Act obligations while you build them, not after an incident.
Handled deliberately, AI is a capability you ship and a defence you run. Left ungoverned, it is the record line item in next year's version of this report. The difference is visibility and discipline, not luck.
Frequently asked questions
How much does a data breach cost in 2026?
IBM's 2026 report puts the global average at $4.99 million, up 12% year over year and a new record. The study, run by the Ponemon Institute and sponsored by IBM, covers 602 organisations breached between March 2025 and February 2026. Breaches involving AI ran higher, at about $6 million — roughly $1 million above the global figure.
Why are AI-enabled breaches more expensive?
AI-enabled attacks — deepfake impersonation, AI-written phishing and adaptive malware — are faster and more convincing, so they are detected and contained later, which drives up dwell time and lost-business costs. IBM found one in four malicious breaches were AI-enabled, up 56% year over year.
What is shadow AI?
Shadow AI is the use of AI tools without IT or security oversight — pasting data into consumer chatbots, wiring in an unsanctioned model, or shipping an AI feature that skipped review. The report linked it to breaches at roughly one in five organisations and found it added as much as $670,000 to the average cost. You cannot secure a system you do not know exists.
Does AI in security operations reduce breach costs?
Yes. Organisations that used AI and automation extensively in security operations saved almost $2 million per breach on average, according to IBM's 2026 report — while about one in four organisations still have not adopted these tools. Both attackers and defenders are moving to machine speed.
What should software teams do first?
Start with visibility: inventory where AI is used, including unsanctioned tools. Put access controls and logging around AI apps and the APIs and plug-ins they call, since compromised APIs and cloud misconfigurations led the causes of AI-related breaches. Add a short governance policy that requires review before AI ships, and automate your own detection and response.
Sources
IBM Newsroom — 2026 Cost of a Data Breach study (primary source, 29 July 2026)
Help Net Security — Data breach cost 2026 averaged $4.99 million, AI attacks ran higher
Network World — IBM: AI-driven attacks increased 56%, breach costs up 12%