The rapid adoption of AI has far surpassed the implementation of security around its surroundings and its governance.
That’s one of the important points IBM’s The costs of the 2025 Data Breach Report revealed surprising trends for organizations and businesses beginning to embrace AI.
This is the first time that an annual report has been considering AI security, governance and access control, and the initial findings suggest that they have done Grimmreading and quickly become targets of “easy and high value.”
The study was conducted by the Ponymon Institute in Michigan and is based on data breaches experienced by 600 organizations worldwide between March 2024 and February 2025.
A significant 13% of those surveyed reported violations of AI models and applications, and an additional 8% found that if an additional 8% compromised, an additional 8% did not notice.
Of those compromised, 97% at large admitted that they had no AI access controls in place.
Additionally, 60% of AI-related security incidents have compromised data, leading to operational disruptions in 31%.
What’s even more surprising was the fact that over 63% of breached organizations either do not have or are still deploying governance policies. Only 34% of those who implemented the policy performed regular audits of unauthorized AI.
The report also represents the phenomenon of “Shadow AI”: unauthorized use of AI tools or applications by employees without IT approval or oversight.
Shadow AI turns out to be responsible for one of the five violations. It also generally increased the cost of data breaches by $670,000 compared to organizations that were not an issue.
The use of Shadow AI has led to an increase in compromised individually identifiable information (65%) and intellectual property (40%), above the global average of 53% and 33%, respectively.
Another amazing development is the level of violations that used AI tools (16%), generally due to phishing and deep falking spoofing.
Suja Viswesan, vice president of IBM, said there are clear lessons to learn from the report.
“This data shows that there is already a gap between AI adoption and surveillance and threat actors are beginning to misuse it,” she said.
“This report reveals the lack of basic access controls for AI systems, revealing highly sensitive data and models are vulnerable to operations. As AI is embedded deep within the entire business operation, AI security must be treated as a foundation. The cost of omission is not a loss of trust, transparency, and control.”
But that wasn’t all bad news. The report identified globally that the costs of all violations fell to an average of $4.44 million, the first decline in five years, despite an average US cost reaching a record $10.22 million.
Additionally, the global average violation lifecycle (time it took to identify and resolve violations) has decreased from 2024 to 241 days, 17 days.

