AI security risk is often discussed as if the model is the main problem. IBM's Cost of a Data Breach Report 2026 points to a more basic weakness: many affected companies did not have adequate access controls around their AI systems.
What IBM Found
The report, based on research by the Ponemon Institute across 602 companies, found that among firms hit by an AI-related incident, 92 percent had inadequate access controls in place.
That finding matters because access controls are a foundational part of security. They determine who can reach a system, what they can do inside it, and how tightly connected tools are protected. In the incidents IBM studied, the weakness was not presented as a rare edge case. It appeared in nearly every AI security incident covered by the report.
The result is a practical warning for companies adding AI systems to their operations. If access to those systems is poorly managed, the organization may be exposed even before any deeper question about model type or model design becomes relevant.
The Entry Point Was Often Outside The Model
IBM's findings also suggest that the model itself was not usually where the problem began. In about one in five affected companies, the entry point was a compromised API, a connected application, or a misconfigured cloud service.
That shifts the focus from AI as a standalone risk to AI as part of a wider technical environment. A company may deploy a model, connect it to applications, expose it through APIs, or run it through cloud services. Each connection can become part of the attack surface if it is not properly controlled.
The report also found that whether a company used an open-source or proprietary model made almost no difference. Based on the source article, the larger issue was not the licensing or origin of the model. It was the surrounding security posture, especially access control.
AI Incidents Cost More
The financial gap in IBM's report is clear. Incidents involving AI cost an average of $5.33 million, compared to $4.70 million for incidents without an AI component.
The global average across all data breaches rose 12 percent to $4.99 million. That broader increase gives the AI numbers added context: breach costs were already moving higher, and incidents involving AI sat above the non-AI figure reported by IBM.
The report also separated incidents where attackers themselves used AI. In those cases, costs jumped to $6.04 million. Without AI, they came in at $5.03 million.
Those figures do not mean every AI system will produce a more expensive breach. They do show that, in the report IBM released, AI was associated with higher average costs when it appeared in the incident, and also when attackers used it.
Why Basic Controls Matter
IBM traces the gaps back to basic oversights that do not require sophisticated attackers to exploit. That is one of the most important points in the source material. The issue is not framed as an exotic failure that only the most advanced adversaries could find.
For businesses, the lesson is direct: AI adoption should not outrun basic security work. Access controls, API security, connected application oversight, and cloud configuration all sit close to the center of the risk described in the report.
The findings also make it harder to treat AI security as a narrow model-selection problem. If open-source and proprietary models made almost no difference in the incidents described, then organizations need to look at the systems around the model. The controls that govern access may be more important than the label attached to the model itself.
In plain terms, IBM's report presents AI breach risk as an operational security problem. The companies affected were not mainly described as choosing the wrong kind of model. They were described as lacking the basic controls needed to keep AI systems and their connected services properly protected.