Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Trending Research

IBM Report: AI-Enabled Breaches Now Cost $6M on Average

IBM's 2026 Cost of a Data Breach report finds 1 in 4 malicious breaches are now AI-enabled, costing $1M more than average. Shadow AI is a growing culprit.

Enterprise DNA | | via IBM Security
IBM Report: AI-Enabled Breaches Now Cost $6M on Average

IBM Security released its 2026 Cost of a Data Breach report on July 29, and the headline number demands attention from any business deploying AI: one in four malicious breaches are now AI-enabled, and they cost significantly more than average to contain.

The report surveyed over 600 organizations across 17 industries and 16 countries. Researchers found the global average breach cost hit $4.99 million this year, a 12 percent increase from 2025 and the highest figure the report has ever recorded. In the United States, that average climbed to $11.5 million, up 14 percent year over year.

But the more telling number is the AI-enabled subset. Breaches driven by AI tools, primarily deepfake impersonation and AI-generated malware, cost an average of $6 million each. That is roughly $1 million above the global average, and the category grew by 56 percent compared to last year.

What Is Actually Happening

Deepfake impersonation accounted for the largest share of AI-driven attacks, representing close to half of them. Attackers are using voice and video deepfakes to impersonate executives, IT staff, and vendors to bypass human verification checks. AI-enabled malware adapts to evade detection in ways that traditional signature-based tools cannot keep up with.

This is not theoretical risk. These are real attacks hitting real companies at scale, and the tools to execute them are now widely available and cheap to deploy.

The shadow AI finding compounds the problem. Shadow AI (ungoverned AI tools adopted by employees without IT approval or security review) affected 43 percent of breached organizations in 2026, up from 20 percent just a year earlier. That is more than a doubling in one year. When employees connect unvetted AI tools to business systems, they create data exposure paths that security teams do not know exist and therefore cannot monitor or close.

The Defense Gap Is Costly

Companies that reported using AI and automation in their security operations cut breach costs by an average of nearly $2 million compared to those that did not. AI as a defense tool works. The problem is that too few organizations are deploying it consistently.

Only 37 percent of breached organizations encrypt sensitive data both at rest and in transit. Just 34 percent have real visibility into their cryptographic assets. These are foundational controls, and most breached companies are not meeting them.

The picture that emerges is an asymmetry: attackers are leveraging AI aggressively while most enterprise defenses have not kept pace. The gap is widening, and the cost of that gap is measurable in millions of dollars per incident.

What This Means for Business

The IBM report is a useful reality check for any business leader who thinks AI risk is a problem for “later.” A few practical takeaways:

Shadow AI is your immediate governance priority. If you have teams adopting AI tools without an approval process, you are almost certainly in that 43 percent. The risk is not hypothetical. It is statistically your most likely breach vector right now. You need a policy that governs what AI tools connect to business data, not a ban on AI but a structured approval process.

AI in your security operations pays for itself. The $2 million average saving from AI-assisted security ops is compelling math. If you have not started there, it is the highest-ROI place to deploy AI in your business this year.

Deepfake verification is now a process problem, not a technology problem. When attackers can convincingly impersonate your CEO on a video call, your verification protocols need to go beyond whether it looks right. Multi-channel verification (a second contact method that the attacker cannot also intercept) is becoming a baseline expectation, not an advanced security measure.

The cost of ungoverned AI adoption is concrete and quantifiable. When a CFO asks why you need AI governance policies or an AI advisor, the IBM report gives you the number: ungoverned AI exposure is contributing to breaches that cost $1 million more than average. Governance is not bureaucracy. It is risk management with a measurable return.

For Enterprise DNA clients, this is exactly the territory that Omni Advisory addresses: helping business leaders build a real AI governance structure before an incident makes it urgent. The businesses that get ahead of this will spend far less on breach response than those who treat it as a checkbox exercise. The IBM report is available in full at the link below. The country-by-country data and industry breakdowns tell a more nuanced story than the headline numbers alone, and it is worth reading in full if your business handles sensitive customer or financial data.