IBM: 92% of AI Incidents Traced to Missing Access Controls
IBM studied 602 companies: 92% of those hit by AI incidents had no basic access controls in place. Average damages came to $5.33M — versus $4.70M for conventional attacks.
IBM analyzed 602 companies following AI-related incidents in 2026 and found that 92% of affected organizations had failed to configure basic access controls for their AI systems. The primary attack vectors were compromised APIs and cloud services — not flaws in the models themselves. Average losses from an AI breach reached $5.33M, compared to $4.70M for conventional attacks.
The problem isn't the novelty of the threat — it's that AI systems aren't being held to the same security standards that have long applied to any other enterprise software. When attackers themselves use AI, losses climb to $6.04M, and that gap is only going to widen.
Source: the-decoder.com
Free course
Stop reading about AI — start building with it
The free Claude Code course: your first site, tool or game — no coding. No upsells, no cross-sells — nothing to buy here.
Start free →▌ Related guides

Author
Evgenii Arsentev
PhD · Chief Executive Officer, digital health
Articles · Latest articles