Policy without control

The AI governance gap in IBM’s 2026 Cost of a Data Breach report.

Two-thirds of the organisations in IBM’s 2026 breach study had no AI governance policy in place. Of that 68 per cent, 35 per cent reported no policy at all and 33 per cent said one remained in development.

The finding comes from the 2026 Cost of a Data Breach Report, released on July 29 by IBM. Ponemon Institute conducted the research; IBM sponsored, analysed and published it, and IBM sells the identity, encryption and security automation products the findings favour. That alignment does not make the data wrong, but it belongs in view while reading it. The study examined 602 organisations across 16 countries and regions and 17 industries, drawing on 3,558 interviews about breaches that occurred between March 2025 and February 2026.

The headline number was the global average cost of a breach: 4.99 million US dollars, up 12 per cent and the highest the report has recorded in 21 editions. That reversed last year’s nine per cent decline, when security teams appeared to be gaining. Average costs in the United States reached a record 11.5 million US dollars against 10.22 million a year earlier, an increase of about 13 per cent, and roughly 2.3 times the global average. The report states this two ways: its key findings page gives 13 per cent and over twice the global average, while its detailed text on the same data gives 11 per cent and nearly double. The chart values support the first reading.

The number that should hold the attention of anyone responsible for records, compliance or discovery sits deeper in the report, and it is worth taking apart. Sixty-eight per cent of breached organisations lacked AI governance to manage AI or detect its unsanctioned use, against 63 per cent the year before. That figure is a composite. Thirty-five percent had no policies at all, down from 41 per cent, and 33 per cent had policies still in development, up from 22 per cent. The share with policies actually in place fell to 32 per cent from 37 per cent.

Read the composition rather than the headline and the picture sharpens. The 2026 sample holds fewer organisations reporting no policy at all, and fewer reporting a finished one. The distribution shifted toward a middle state where a policy exists on a slide deck and not in a control. Each annual study draws a different sample matched on characteristics rather than tracking the same companies, so this describes the population studied and not a journey any particular organisation took.

Five of six comparable governance controls declined

Of the six AI governance control types the study measured in both years, five lost adoption, as of the February 2026 close of the study window.

Strict approval processes for AI deployments, the most common control, dropped to 38 per cent from 45 per cent. Use of AI governance technology fell to 33 per cent from 39 per cent, and governance frameworks to 33 per cent from 39 per cent. Employee training on AI risks slipped to 30 per cent from 36 per cent. Regular audits for unsanctioned AI declined to 29 per cent from 34 per cent. Adversarial testing, or red teaming, was the only comparable control to gain ground, reaching 25 per cent from 22 per cent. Coordination between governance and security teams, along with two residual response options, appeared for the first time this year and carry no prior-year comparison. The 32 per cent holding a finished policy, cited above, comes from a separate question and is not a seventh control in this set.

Researchers studied coordination between governance and security teams for the first time, and 19 per cent of organisations reported coordinating those efforts. Because the question permitted multiple responses, non-selection does not establish that the remaining organisations deliberately separated the functions; it establishes only that they did not report coordination.

The exposure widened while the controls thinned. Security incidents involving an AI model or application reached 21 per cent of breached organisations, up from 13 per cent, a 61 per cent increase. Among organisations that suffered an AI-related breach, 92 per cent lacked proper AI access controls, which the report says include role-based access and multifactor authentication. Across all breached organisations, only 40 per cent applied access controls to AI models and data at all.

Identity and access management was the second-largest cost reducer among the 20 factors the report publishes of the 30 it analysed, associated with a 225,622 US dollars reduction against the average breach. Ranked across those 20 by size of effect in either direction, it sits third, behind supply chain breaches at 227,250 US dollars. The report measures each factor in isolation and does not establish causation, so read either figure as an association rather than a return. IBM draws the contrast itself: it names identity and access management among the most effective cost reducers, then reports that only 40 percent of organisations applied access controls to AI models and data.

Shadow AI became the expensive unknown

Security incidents involving shadow AI, meaning staff running AI tools the organisation never approved, reached 43 per cent this year against 20 per cent last year. Breaches involving shadow AI averaged 5.39 million US dollars, against 4.63 million a year earlier.

The downstream damage tracked with what an ungoverned data path produces. Forty-nine per cent of shadow AI incidents caused data loss or compromise, 42 per cent disrupted operations and 35 percent produced reputational damage. In about one in five, the organisation paid a regulatory fine.

The practical response starts with discovery, not policy. An acceptable-use memo does not find the analyst pasting customer records into a consumer chatbot. Network egress monitoring, browser telemetry, single sign-on logs and expense-report review for unbudgeted AI subscriptions do. Only 29 per cent reported running regular audits for unsanctioned AI, leaving most organisations without that particular monitoring mechanism. Other enforcement paths were measured separately and some of those organisations will hold them, but an unaudited environment is one where the size of the problem stays unknown. The factor the report labels “lack of visibility into the number and location of applications (shadow IT)” was associated with costs 201,165 US dollars above the global average.

Attackers skipped the approval process

One in four organisations that experienced a malicious attack reported it was AI-driven, a 56 per cent increase over last year, and another 11 per cent could not determine whether AI was involved. Malicious AI-driven attacks averaged 6.04 million US dollars against 5.03 million for malicious attacks without AI, a gap of about 1.01 million US dollars. Deepfake and impersonation attacks accounted for 45 per cent of that volume, AI-enabled malware 19 per cent, and AI-generated phishing or other communication 17 per cent.

Sixty-two per cent of AI-driven attacks targeted critical infrastructure sectors, with financial services and energy organisations showing the highest concentration. Financial services breaches averaged 6.29 million US dollars.

Defenders lost ground on the clock. Mean time to identify and contain a breach rose to 247 days from 241, a 2.5 per cent increase that reversed a five-year decline. Breaches running past 200 days averaged 5.65 million US dollars; those resolved faster averaged 4.32 million.

Suja Viswesan, vice president of IBM Security Software, said in the company’s announcement that attackers are using AI to operate faster and more cheaply while the cost of successful intrusions keeps climbing, and that the delay between finding a weakness and closing it converts directly into higher losses.

IBM anchored its forward-looking warning to outside work. A survey by a University of California, Berkeley team including Yujin Potter and Dawn Song asked AI and security researchers to score the offense-defence balance on a scale of zero to 100 and reported that experts expect it to favour attackers by 31.7 per cent within two years, narrowing to 12.8 per cent at five years and 0.46 per cent at 10. The sample was small: 129 experts opened the survey and 34 completed it. Treat it as expert sentiment, not measurement.

Where AI incidents actually got expensive

The report priced AI incident types, and the ranking is instructive for anyone building a control programme.

Model inversion, where an attacker reconstructs protected training data by probing a deployed model, was costliest at 6.07 million US dollars. IBM describes that as 18 per cent above the global average, though its own published figures imply about 22 per cent, and no figure in the report produces the 5.14 million US dollars baseline that 18 per cent would require. Prompt injection followed at 5.89 million US dollars. Cloud security misconfigurations affecting AI workloads reached 5.25 million US dollars, malicious models 4.94 million US dollars, model evasion 4.72 million US dollars and compromise of connected applications, APIs and plug-ins 4.37 million US dollars.

Note what the ranking spans. Model inversion and prompt injection, the two costliest, attack how a model reasons and what it retains. But malicious models, model evasion and data poisoning are model-level attacks too, and all three sit below cloud misconfigurations on the cost scale. The list does not sort cleanly into model problems and infrastructure problems. IBM’s executive summary described the root causes as often structural rather than model risk, and its frequency data supports that: cloud misconfigurations and compromise of connected apps, APIs or plug-ins were the two most-reported incident types at 27 per cent each. Cost and frequency are different measures, so this ranking neither confirms nor contradicts the point.

Among factors associated with higher costs, supply chain breaches led at 227,250 US dollars, followed by security system complexity at 208,265 US dollars, shadow IT at 201,165 US dollars and noncompliance with regulations at 201,112 US dollars. Among those associated with lower costs, a DevSecOps approach led at 253,805 US dollars, ahead of identity and access management, key lifecycle management tools at 214,923 US dollars and encryption at 213,478 US dollars. None of these figures is additive, and none is a measured effect.

Encryption deserves its own line. Fifty-three percent of breached organizations had not encrypted sensitive data at rest and in motion when the breach occurred. Another 10 percent did not know.

Brussels moved the deadline, not the obligation

European timing shifted this summer in a way that is easy to misread as relief.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, took effect July 27, 2026, and moved the application date for high-risk AI obligations under Annex III of the AI Act to Dec. 2, 2027, and for Annex I systems to August 2, 2028. Article 50(1), which requires providers of AI systems intended to interact directly with natural persons to inform them they are dealing with an AI system, still applies from August 2, 2026. Providers of systems generating synthetic audio, image, video or text that were on the market before that date have until December 2, 2026, to meet the machine-readable marking requirement in Article 50(2).

Deferring application dates is not withdrawing obligations, and it does nothing about the evidentiary problem underneath. An organization that cannot inventory its AI systems in 2026 will not be able to document conformity for them in 2027, and the inventory is the slow part. Noncompliance with regulations was associated with costs 201,112 US dollars above the global average in this year’s data, a figure drawn entirely from obligations already in effect.

Preservation gaps hide inside governance gaps

Customer personally identifiable information appeared in 52 per cent of breaches, the most targeted category, at 192 US dollars per record. Intellectual property was costliest at 196 US dollars per record. Ransomware attackers, present in 39 per cent of breaches, have broadened what they weaponise: 41 per cent threatened to publicise the breach or hand data to reporters, and 19 per cent went after internal communications including email and Slack messages.

For discovery practitioners, a governance gap is a preservation gap. Prompts, model outputs, retrieval logs and agent action histories can constitute business records or discoverable electronically stored information, depending on their content, the retention obligations that attach to them, their relevance to a matter, and whether they sit within the organisation’s possession, custody or control. Shadow AI makes every one of those determinations harder, because the systems generating the material may sit outside approved data maps, outside negotiated terms of service and outside the jurisdictions the organisation selected. A legal hold cannot reach a system nobody knows exists, and a data map that omits the tools employees actually use is not a data map. The 19 per cent coordination figure is where this becomes concrete: where governance and security do not meet, neither is well positioned to tell legal what exists.

Information governance inherits the same problem one layer down. Retention schedules written for document management systems often say nothing about the source chunks, metadata, cached prompts and derived embeddings that vector stores retain, and disposition evidence may be incomplete when those materials outlive the record they came from. Only 46 per cent reported securing non-human identities, the credentials assigned to machines and agents, in AI workflows, leaving most of the study population without reported controls over those credentials and raising the risk of persistent or under-reviewed access to the data those workflows touch.

Read the methodology before quoting the number

Ponemon Institute, founded in 2002 and chaired by Larry Ponemon, describes its work as independent research. The methodology section is candid about limits worth restating before any of these figures reach a board deck.

The sample is non-statistical, so margins of error and confidence intervals do not apply. The sampling frame was judgmental and, by the researchers’ own assessment, biased toward organisations with more mature privacy and information security programmes. Costs are extrapolated rather than drawn from financial records. Nonresponse bias was not tested. Every governance figure is self-reported by people describing their own organisation’s failures.

Those limitations could mean the 68 per cent figure understates the governance problem, particularly because a sampling frame favouring mature programmes should over-represent organisations that already hold policies. That is the more probable direction, but it is not the only one: self-reporting in a confidential benchmark does not distort in a single direction, nonresponse was never tested, and neither the direction nor the size of any resulting bias can be determined from this design. Read 68 per cent as a descriptive result for a non-statistical sample, not as a population estimate and not as a floor.

Organisations using security AI and automation extensively, 36 per cent of the sample, averaged four million US dollars per breach against 5.93 million for those using none, and resolved incidents in 215 days against 280. That is a correlation, and the study’s design cannot raise it past one: it does not control for security programme maturity, and mature programs may both adopt these tools and contain breaches faster for reasons the research never measured. The spending figures need their denominators stated. In follow-up research conducted in May, 456 of the original 602 organisations responded, and 78 percent of those said they were aware of new frontier AI model threats. Among that aware subset, about 356 organisations, 85 per cent planned to increase security spending. The 64 per cent figure comes from the original research stage across the full sample. The report charts the two as before and after frontier model threat awareness, which invites reading them as a matched pair; they rest on different respondent bases and support only a directional reading. Spending is the easy commitment. Governance is the one that requires telling a business unit no.

Which raises the question worth carrying into the next budget cycle: if your organisation approved an AI deployment this quarter, can you name who reviewed it, what data it touches, where its outputs are stored, and who would preserve them under a litigation hold?

Read the complete article at Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report.


Photo: Dreamstime.