IBM Found 97% of AI Breach Victims Had No Access Controls. Another 8% Don’t Know If They’ve Been Hacked At All.
IBM and the independent Ponemon Institute studied 600 breached organizations worldwide for the 20th annual Cost of a Data Breach Report, covering incidents between March 2024 and February 2025 and released July 30, 2025. Thirteen percent had suffered a security incident tied to an AI model or application; of those, 97% had no AI access controls in place, and 63% had no AI governance policy at all.
Seven months later, IBM’s own X-Force researchers checked back. The gap hadn’t closed — it had been exploited. More than 300,000 AI chatbot credentials were found for sale on dark web markets, harvested by commodity infostealer malware.
- 97%of AI-breach victimshad no proper AI access controls in place — IBM / Ponemon Institute, 2025
- $670Kadded per breachby unsanctioned “shadow AI” tools — IBM Cost of a Data Breach Report 2025
- 300,000+AI chatbot credentialsstolen by infostealer malware and offered for sale in 2025 — IBM X-Force Threat Intelligence Index 2026
IBM has published its Cost of a Data Breach Report annually for two decades, drawing on research conducted independently by the Ponemon Institute. The 2025 edition — the 20th — interviewed executives and security staff at 600 organizations around the world that had experienced a confirmed data breach between March 2024 and February 2025. For the first time, the survey broke out breaches of AI models and AI applications as their own category, rather than folding them into general software incidents.
The result: 13% of the 600 organizations reported a security incident that compromised an AI model or AI application. A further 8% said they did not know whether their AI systems had been compromised — a category IBM had never needed to include in previous editions. Among the organizations that confirmed an AI-related breach, 97% said they had no AI access controls in place at the time. Sixty percent of those incidents resulted in compromised data; 31% caused operational disruption.
The access-control failure sits inside a broader pattern. Of the 600 organizations studied, 63% either had no AI governance policy or were still developing one. Among the minority that did have a policy, only 34% conducted regular audits to catch unsanctioned AI use. Less than half — 45% — had any formal approval process before a new AI tool went into production, and 61% said they lacked AI governance technology of any kind to enforce whatever policy existed on paper.
IBM Security’s Vice President of Security and Runtime Products, Suja Viswesan, put the finding plainly in the report’s release. The gap was not a minor lag — it was already being exploited, and the consequences went beyond a balance sheet.
“The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it. The report revealed a lack of basic access controls for AI systems, leaving highly sensitive data exposed, and models vulnerable to manipulation. As AI becomes more deeply embedded across business operations, AI security must be treated as foundational. The cost of inaction isn't just financial — it's the loss of trust, transparency and control.”
Suja Viswesan, VP Security and Runtime Products, IBM · July 30, 2025
The most common entry point wasn’t a sophisticated exploit against a frontier model. It was IBM’s own AI supply chain: compromised applications, unsecured APIs, and malicious plug-ins connecting employees to AI services with little oversight of what those connections touched. Layered on top of that is what IBM calls “shadow AI” — employees downloading or using consumer-grade AI tools, like a personal ChatGPT account or an unapproved coding assistant, without security or IT sign-off.
One in five organizations — 20% — reported a breach directly attributable to shadow AI, and only 37% had any policy to detect or manage it. Breaches involving high levels of shadow AI averaged $4.63 million, a $670,000 premium over organizations with little or none. Those incidents also took longer to contain (247 days versus a 241-day global average), compromised customer personal data at a higher rate (65% versus 53%), and involved intellectual-property theft in 40% of cases.
AI cuts both ways. About 16% of all breaches in the study — roughly one in six — involved attackers actively using AI tools to carry out the intrusion, most commonly for AI-generated phishing (37% of that subset) and deepfake impersonation (35%). The efficiency gain for attackers is stark: IBM’s researchers found that generative AI has cut the time needed to craft a convincing phishing lure from roughly 16 hours down to about 5 minutes.
The 2025 report’s access-control warning did not stay theoretical for long. IBM X-Force — the company’s threat-intelligence arm — published its 2026 Threat Intelligence Index on February 25, 2026, and found that infostealer malware had exposed more than 300,000 AI chatbot credentials over the course of 2025, harvested by commodity malware families like Raccoon and Vidar and advertised on dark web markets. A stolen chatbot credential is not a minor nuisance: X-Force noted that a compromised set of login details can let an attacker manipulate an AI system’s outputs, exfiltrate data through it, or inject malicious prompts into whatever workflow the account is connected to.
“Attackers aren't reinventing playbooks, they're speeding them up with AI.”
Mark Hughes, Global Managing Partner for Cybersecurity Services, IBM · X-Force Threat Intelligence Index 2026
IBM: 13% of Organizations Reported Breaches of AI Models, 97% of Which Reported Lacking Proper AI Access Controls.
The AI findings sat inside a data-breach market that is, on the whole, improving. The global average cost of a breach fell to $4.44 million in 2025, down 9% from $4.88 million the year before — the first decline in five years, driven by faster detection and containment (a 241-day average lifecycle, the lowest in nine years). Organizations that deployed AI-powered security tools extensively saved roughly $1.9 million per breach and contained incidents 80 days faster than organizations with no AI security tools at all.
But the improvement was not evenly distributed. The United States average breach cost rose to $10.22 million, an all-time national high, driven by regulatory penalties and slower detection relative to the global pace. Healthcare remained the single costliest industry for the 14th consecutive year, at $7.42 million per breach and a 279-day average containment time — the longest of any sector IBM tracks. In the United Kingdom, organizations using AI and automation extensively across security operations saw costs fall to £3.11 million, against £3.78 million for those that did not — while only 31% of UK organizations reported having an AI governance policy in place, below the already-low global rate.
Government and industry responses to the gap IBM documented have accumulated steadily through 2026. On February 17, 2026, NIST’s Center for AI Standards and Innovation launched the AI Agent Standards Initiative, organizing work across industry-led standards, open-source protocol development, and identity research specifically for autonomous AI agents. On May 1, 2026, CISA, the NSA, and cyber agencies from Australia, Canada, New Zealand, and the United Kingdom jointly published “Careful Adoption of Agentic AI Services” — the first coordinated Five Eyes guidance addressing autonomous AI agents as a distinct security category, identifying privilege escalation and weak identity controls as leading risks.
Market analysts describe the same imbalance from a spending angle. Gartner forecasts worldwide AI spending will reach $2.52 trillion in 2026, while a separate Gartner analysis found enterprises are spending roughly 17 times more on AI tools than on securing those tools — with spending on dedicated AI governance platforms projected at only $492 million in 2026. A Gartner poll of 147 CIOs found that while 24% had already deployed AI agents and another 50% were experimenting with them, only about 6% reported having an advanced AI security strategy in place.
Every figure in IBM’s report describes the same underlying imbalance from a different angle: enterprises are moving AI into production faster than they are building the identity, access, and audit infrastructure to govern it. Gartner puts a number on the imbalance directly — enterprises spend about 17 times more on AI tools than on AI security, and its CIO poll found roughly three-quarters of organizations have already deployed or are experimenting with AI agents against just 6% with an advanced AI security strategy in place. IBM’s 600 breached organizations are what that gap looks like once it has already been exploited.
AI oversight is lacking, and attackers are exploiting weak access controls, according to IBM's Cost of a Data Breach Report 2025. On the flip side, security teams that use AI and automation extensively are reducing the cost and duration of breaches.
IBM research shows proper AI access controls are leading to costly data leaks.
IBM did not need to speculate about AI security risk in its 2025 report — it measured it, across 600 real breaches. Ninety-seven percent of the companies breached through an AI system had no access controls in place. Sixty-three percent had no governance policy at all. Seven months later, IBM’s own threat researchers found 300,000-plus stolen AI chatbot credentials for sale, confirming the gap the company had already documented. The technology moved into production. The locks did not move with it.



