IBM Reports Urgent Need for AI Security Measures Amid Rising Breaches
1. Overview of Findings from the 2025 Cost of a Data Breach Report
On July 30, 2025, International Business Machines Corp (IBM) unveiled its latest findings in the annual Cost of a Data Breach Report, emphasizing a concerning trend: as organizations rapidly adopt artificial intelligence (AI) technologies, they are neglecting essential security and governance measures. The report highlights that 13% of organizations surveyed reported breaches related to AI models or applications, with a staggering 97% of these organizations lacking proper access controls.
AI Breaches on the Rise
The report, conducted by the Ponemon Institute and based on data from 600 organizations globally between March 2024 and February 2025, marks a pivotal moment in the intersection of AI technology and cybersecurity. Notably, 8% of respondents were unsure if they had experienced an AI-related breach, underscoring the potential for unrecognized vulnerabilities.
Among the organizations that reported being compromised, a significant 60% faced data compromises, while 31% experienced operational disruptions as a direct result of these incidents. IBM's Vice President of Security and Runtime Products, Suja Viswesan, commented, “The data shows that a gap between AI adoption and oversight already exists, and threat actors are starting to exploit it.”
2. Key Findings on AI Governance and Security
Lack of AI Governance Policies
One of the stark revelations from the report is that 63% of breached organizations either do not have an AI governance policy in place or are still in the process of developing one. Among those with established policies, only 34% conduct regular audits to identify unauthorized AI use. This lack of governance creates a fertile ground for breaches, particularly concerning shadow AI—unauthorized and unregulated AI applications.
The Cost of Shadow AI
The report indicates that 20% of organizations reported breaches attributed to shadow AI, with those heavily utilizing shadow AI experiencing breach costs averaging $670,000 higher than organizations that do not. Security incidents involving shadow AI led to a higher incidence of compromised sensitive data, with 65% of breaches affecting personally identifiable information and 40% impacting intellectual property.
The Role of AI in Cyberattacks
The findings also reveal that 16% of breaches involved attackers leveraging AI tools, primarily for phishing and deepfake impersonation attacks, signaling an evolution in the tactics of cybercriminals.
3. Financial Implications of Breaches
Breach Costs Decline Yet Remain High
Despite the alarming rise in AI-related breaches, the overall global average cost of a data breach has fallen to $4.44 million, marking the first decline in five years. However, the average cost of a breach in the U.S. reached a record $10.22 million. The report highlights a significant 241-day average breach lifecycle, reflecting a 17-day improvement from the previous year, with organizations that detected breaches internally saving around $900,000 in breach costs.
Sector-Specific Insights
Healthcare organizations continue to bear the brunt of breach costs, averaging $7.42 million per incident, despite a noted reduction of $2.35 million compared to the previous year. The healthcare sector also exhibits the longest recovery times, averaging 279 days to identify and contain breaches.
Ransom Payment Trends
The report documents a notable shift in organizations' responses to ransom demands, with 63% opting not to pay compared to 59% in the previous year. Consequently, the average cost of ransomware incidents remains critically high, particularly when disclosed by an attacker, averaging $5.08 million.
4. Operational Disruption and Long-Term Effects
The report underscores the extensive operational disruption that follows a data breach, with nearly all organizations reporting significant recovery timelines. Many organizations indicated plans to raise prices for goods or services as a consequence of breach-related costs, with nearly one-third forecasting increases of 15% or more.
5. Conclusion: The Imperative for AI Security
As AI technology continues to proliferate in business operations, the IBM report underscores the pressing need for robust security measures and governance frameworks. The findings reveal that organizations are not only at risk of financial losses but also face potential long-term damage to trust, transparency, and control. Companies must prioritize AI security as foundational to their operations to mitigate risks and safeguard valuable assets.
IBM’s release serves as a clarion call for organizations across all sectors to reassess their AI security posture and implement comprehensive governance policies to protect against the evolving threat landscape.