TL;DR: IBM’s 2026 Cost of a Data Breach Report found the global average breach cost reached $4.99 million, with AI-enabled malicious breaches averaging $6 million and shadow AI incidents rising to 43%, according to IBM and Ponemon Institute research. The real problem is not point-tool failure, but incomplete coverage across AI workloads, data states, and identity control boundaries.
At a glance
What this is: IBM’s 2026 breach report says the costliest failures now happen in the gaps between data, AI, and identity controls, not in direct attacks on a single security tool.
Why it matters: For IAM and security teams, the report reinforces that data protection, workload oversight, and agent identity governance must be treated as one control plane if blind spots are to be reduced.
By the numbers:
- IBM and Ponemon Institute found the global average cost of a data breach reached $4.99 million in 2026, up 12% from the prior year.
- One in four malicious breaches were AI-enabled, a 56% increase over last year, according to IBM.
- IBM reported that 43% of security incidents now involve shadow AI, more than doubling year over year.
- IBM found only 37% of breached organisations encrypt sensitive data both at rest and in transit.
👉 Read MIND's analysis of IBM’s 2026 Cost of a Data Breach Report
Context
Data security breaks down most often where coverage stops short of how information is actually used. In this report, IBM and Ponemon Institute describe breaches that moved through AI workloads, unsanctioned chatbots, and inconsistent encryption coverage rather than through a single obvious control failure. For IAM practitioners, the identity angle matters because AI tools and agent identities increasingly act on behalf of people and processes.
The report’s deeper implication is governance, not tooling alone. When data states, AI usage, and access decisions are owned by separate teams, attackers and careless users can move through the seams. That creates a control gap where data security posture management, DLP, and identity governance each see only part of the risk.
This is a familiar pattern in mature environments: the organisation has controls, but not end-to-end coverage. That makes the starting position typical rather than exceptional, which is exactly why the findings matter.
Key questions
Q: How should security teams govern sensitive data used by AI systems?
A: Security teams should treat AI as a data consumer that needs policy boundaries, not just authentication. Classify sensitive data, define which datasets may enter AI workflows, and monitor outputs, logs, and downstream reuse. If governance stops at login, the organisation can approve access while still losing control of the data itself.
Q: Why does shadow AI create such a high breach risk?
A: Shadow AI creates high breach risk because it can access sensitive data outside normal oversight, then process or reproduce that data in places security teams do not control. Once the tool can read privileged information, the organisation may lose visibility into retention, logging, and downstream exposure.
Q: What do organisations get wrong about encrypting data for AI use?
A: Many organisations assume encryption at rest is enough, but AI-related exposure often happens while data is moving or being transformed. If only one state is protected, the handoff becomes the weak point. Teams should validate encryption coverage across both states and confirm that AI ingestion paths inherit the same policy intent.
Q: How do security leaders know if their data controls cover the real risk surface?
A: They should measure whether sanctioned and unsanctioned AI channels, identity permissions, and encryption controls are governed as one system. If discovery stops at files or endpoints, the organisation is probably missing the places where users and agents actually interact with sensitive data. Complete coverage is visible when no high-risk path is unmanaged.
Technical breakdown
Why AI workloads create data security blind spots
AI workloads change where sensitive data lives and how it moves. A model, chatbot, plug-in, or agent may ingest information outside traditional file, endpoint, or email boundaries, which means legacy data controls can miss the transaction entirely. The report’s point is not that tools fail, but that the control model was built for a narrower environment. Once unsanctioned AI use becomes common, visibility depends on understanding the workload, the identity using it, and the data flowing through it.
Practical implication: extend discovery and policy enforcement to AI workloads, not just storage locations and sanctioned channels.
How inconsistent encryption creates governance gaps
Encryption is only effective when it covers both data at rest and data in transit consistently. The report highlights a common split: one team or tool protects stored data, another covers traffic, and neither owns the handoff between the two states. That leaves a gap where sensitive content can be exposed during movement, conversion, or transfer into AI services. In practice, the weak point is often not the algorithm, but the absence of unified policy across data states.
Practical implication: map encryption coverage across both states of data and close handoff gaps between teams and tools.
Why agent and application identity now sits inside data security
The report’s identity signal is straightforward: AI tools and agents can access sensitive data with permissions that were originally granted to humans or legacy applications. That creates an identity-to-data dependency that classic DLP or DSPM programmes do not fully model. If an AI agent can read, transform, or exfiltrate data, then access governance becomes part of data security, not a separate discipline. This is where IAM and NHI governance intersect directly with the report’s findings.
Practical implication: inventory AI and non-human identities with access to sensitive data and review their permissions as part of data governance.
Threat narrative
Attacker objective: The attacker seeks to reach sensitive information through overlooked AI and data pathways that bypass normal monitoring and governance.
- Entry occurs through compromised APIs, applications, plug-ins, or shadow AI channels that are not fully inventoried.
- Escalation happens when unsanctioned or over-permissioned AI workloads can reach sensitive data beyond the scope of normal controls.
- Impact follows when data is exposed, moved, or used in ways the organisation did not govern, increasing breach cost and response complexity.
NHI Mgmt Group analysis
Incomplete coverage is now the primary data security failure mode. The report’s core lesson is not that organisations lack controls, but that controls stop at the edge of the problem. AI workloads, shadow AI, and mixed data states create seams where no single team owns the full pathway. Practitioners should treat the seam itself as the risk boundary.
Identity and data governance are converging in ways most programmes have not modelled. If AI agents, plug-ins, and application identities can touch sensitive data, then access review alone is no longer enough. The governance question becomes who or what can act on data across its lifecycle, which is where NHI and IAM controls must be aligned with data protection policies.
Shadow AI creates a detection problem before it becomes a breach problem. Once employees can move data into unsanctioned tools, the traditional assumption that sanctioned channels define the risk surface breaks down. That creates a verification trust gap, where policy exists but enforcement does not follow the data. Teams should expect AI usage discovery to become a baseline data security requirement.
Data security posture management is no longer sufficient without access governance. The report shows why posture tools must be paired with identity controls that understand AI access paths. This is the point where access policy, workload identity, and data classification must operate together. The practical conclusion is that control ownership must shift from tool silos to shared governance.
What this signals
Seam security will become a governance metric, not just an architecture concern. As AI usage spreads, programmes that cannot show coverage across data states, AI channels, and identity permissions will keep absorbing breach cost in the gaps. The operational signal is simple: if no one owns the handoff, then no one owns the risk. That is where data security, IAM, and NHI governance have to converge.
Verification trust gap: organisations increasingly trust that approved controls cover the full data path, but AI adoption is widening the distance between approval and actual use. Readers should expect more pressure to prove where data can travel, who or what can touch it, and whether the policy follows the data into unmanaged environments. For identity teams, that means access governance must reach beyond applications and into AI workloads.
For mature programmes, the next step is control integration, not control accumulation. Adding another data tool without identity context will not close the seam problem the report describes. The stronger response is to connect inventory, classification, access review, and runtime prevention so the organisation can see the same risk from multiple angles. That is the difference between partial coverage and operational resilience.
For practitioners
- Inventory AI workloads and shadow AI channels Map every approved and unapproved AI service that can receive or process sensitive data, including browser-based tools, plug-ins, and embedded copilots. Tie each service to an owning team and a data classification scope.
- Unify encryption coverage across data states Validate that sensitive data is protected both at rest and in transit, and test the handoff points between storage, transport, and AI ingestion paths.
- Align IAM and NHI reviews with data access Review human, application, and agent identities that can reach sensitive datasets, then remove permissions that are not required for the current task or workflow.
- Extend DLP and DSPM to AI usage paths Ensure data controls see sanctioned and unsanctioned AI channels, including endpoint, browser, SaaS, and agent-driven access patterns.
- Create a seam-focused governance register Document where one control hands off to another, such as DLP to encryption to IAM, so ownership gaps can be tracked and tested explicitly.
Key takeaways
- The report shows that breach cost is now being driven by coverage gaps across AI, data, and identity controls rather than by a single failed defence.
- AI-enabled malicious breaches and shadow AI incidents are rising fast, which makes unmanaged access paths a material security and governance problem.
- The practical response is to unify discovery, encryption, access governance, and runtime prevention across both human and non-human identities.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack surface, NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-4 | Access control and least privilege are central to the report’s identity and AI governance gap. |
| NIST SP 800-53 Rev 5 | AC-6 | Least privilege is directly implicated when AI tools and agents can reach sensitive data. |
| ISO/IEC 27001:2022 | A.5.15 | Access control policies must extend to AI workloads and data-handling pathways. |
| MITRE ATT&CK | TA0006 , Credential Access; TA0009 , Collection | The article describes attacks that move through access and data collection stages. |
Map AI-related exposure to credential access and collection tactics when evaluating monitoring coverage.
Key terms
- Shadow AI: AI agents, copilots, or connected tools operating without full visibility or governance from security teams. Shadow AI becomes an identity problem when those systems authenticate with unmanaged tokens, service accounts, or OAuth apps that can reach production resources.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Data Security Posture Management: Data Security Posture Management, or DSPM, is the continuous discovery and monitoring of where sensitive data lives, how it is exposed, and where policy gaps exist. Its value rises when it feeds remediation rather than generating findings alone, especially in environments where AI expands the number of data paths.
- Activation Trust Gap: The activation trust gap is the difference between trusting data because it is protected and governing it because it is being reused. It appears when organisations move data from backup or archival systems into AI pipelines without reapplying access, sensitivity, and consumer controls.
What's in the full article
MIND's full analysis covers the operational detail this post intentionally leaves for the source:
- IBM and Ponemon Institute's breach breakdown by attack path, sector, and control failure
- The report’s quantitative detail on AI-enabled incidents, shadow AI, and encryption coverage
- Context on how the study defines breach cost and the organisations included in the sample
- The analyst commentary that sits behind the headline figures and their year-over-year movement
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and identity lifecycle management. It helps practitioners connect access governance to the broader security programme their teams already run.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org