Artificial intelligence is playing an increasingly significant role in cybercrime, with IBM’s 2026 Cost of a Data Breach Report finding that one in four malicious data breaches now involve AI. The report shows AI-enabled attacks increased 56% compared with the previous year, reflecting the growing use of AI for phishing, malware creation and digital impersonation by cybercriminals.
The study, conducted by the Ponemon Institute, analyzed 602 organizations that experienced data breaches between March 2025 and February 2026. Researchers also surveyed 3,558 security professionals and C-suite executives to assess how organizations are responding to the evolving cyber threat landscape.
According to the report, AI-enabled breaches now cost organizations an average of $6 million, approximately $1 million more than the global average data breach cost of $4.99 million. Overall breach costs also increased 12% year over year. While IBM markets enterprise cybersecurity products, its annual breach report is widely referenced across the security industry.
The findings were released before the widely discussed Hugging Face security incident. On July 21, OpenAI disclosed that one of its frontier AI models successfully completed a simulated attack chain against Hugging Face’s environment during internal testing, demonstrating how advanced AI systems can combine multiple vulnerabilities to gain broader access to computer systems.
Suja Viswesan, Vice President of Security Software Products at IBM, said, “One of the most striking findings is that 85% of enterprises expect to increase security investment after learning about the capabilities frontier AI models could put into the wrong hands. Fear often drives action, and in this case, organizations are taking these emerging risks seriously.”
Viswesan added, “For years, the security industry has argued that waiting for a major incident before investing is the wrong approach. Our findings suggest a shift in mindset: enterprises are increasingly acting on anticipated risk, recognising that as AI capabilities advance, security needs to evolve ahead of the threat curve rather than react after the fact.”
While AI is enabling more sophisticated cyberattacks, the technology is also proving valuable for defenders. IBM found that organizations using AI and automation within their security operations reduced the average cost of a data breach by nearly $2 million. However, the report found a major gap in vulnerability management. More than half of surveyed organizations use AI agents for threat detection and incident containment, but only 18% deploy them to identify and manage software vulnerabilities, leaving known weaknesses exposed.
Separate research released on July 28 by application security company Veracode highlighted another growing concern: AI-generated software code. The company’s annual GenAI Code Security Report evaluated more than 100 AI models and found that large language models from both U.S. and Chinese developers generated vulnerable code 44% of the time.
Veracode reported that GPT-5.5 achieved the highest security pass rate at 68%, followed by GPT-5.3-Codex and Claude Opus 4.8, both at 62%. The company noted these evaluations were performed using raw models rather than production systems enhanced with additional safeguards or human oversight.
Chris Wysopal, Veracode’s cofounder and chief security evangelist, said the findings “reveal that despite major gains in AI speed, capability and reasoning, LLMs are not getting safer.” He added, “What this research makes clear is that as AI-fueled code velocity increases, AI-generated code needs to be traced like any unreviewed code. Development teams must take steps to address the security gap in AI-generated code by scanning and fixing issues to ensure that AI-generated code is never shipped blind.”
The research suggests organizations will increasingly need to strengthen both cybersecurity defenses against AI-powered attacks and software development processes that identify and eliminate vulnerabilities introduced by AI-generated code.
Leave a comment