The company said AI-enabled incidents rose 56% from last year and cost an average of $6 million, above the global breach average of $4.99 million.
AI-enabled breaches accounted for one in four malicious incidents in IBM's 2026 Cost of a Data Breach Report, a 56% increase from last year, with average costs reaching $6 million versus the global breach average of $4.99 million. IBM said the attacks were driven mainly by deepfake impersonation and AI-enabled malware, making intrusions faster and cheaper to launch even as remediation remains costly. More than 20% of organizations also reported a breach targeting AI models or applications, most often tied to compromised APIs (application programming interfaces), applications or plug-ins, and cloud misconfigurations affecting AI workloads. The report said organizations using AI and automation in security operations reduced breach costs by nearly $2 million on average, though one in four had not adopted those tools. Separate follow-on research by Ponemon Institute found 85% planned to increase security spending after learning about advanced frontier AI cyber capabilities, above the 64% that said in the initial research they would raise spending after a breach. Critical infrastructure saw 62% of reported AI-driven attacks, with financial services and energy showing the highest concentration.