AI Breaches Often Land in Plumbing Around Model
The IBM 2026 Cost of a Data Breach report reveals that most AI-related breaches do not target the model itself, but rather exploit vulnerabilities in APIs, cloud misconfigurations, and other surrounding systems.
According to the report, one in four malicious breaches is AI-enabled, with deepfake impersonation and AI-enabled malware leading the way. However, only 40% of organizations that were breached through their AI had access controls on those models and data.
The most common ways attackers breached AI systems were through compromised APIs or cloud misconfigurations, each accounting for 27% of breaches. The average breach cost $6 million, up 35% from the previous year's average of $4.44 million.