Ninety-Two Per Cent Of AI Breaches Had One Thing In Common
- Johan Steyn

- 17 hours ago
- 3 min read
Among organisations suffering an AI-related breach, almost all of them had failed to put proper access controls on the system.

Sign up for my Substack daily AI newsletter here.
See my AI Training course portfolio for corporate Business Leaders here.
Follow me on LinkedIn: https://www.linkedin.com/in/johanosteyn/
Most cyber statistics describe an adversary. This one describes a decision, or more precisely the absence of one. It should be read carefully by every executive who has signed off an artificial intelligence deployment in the past two years, because it concerns something that was never done rather than something that was done to them.
CONTEXT AND BACKGROUND
IBM’s Cost of a Data Breach Report 2026, conducted with the Ponemon Institute using data from around 600 organisations breached between March 2025 and February 2026, found that more than one in four organisations experiencing a malicious attack reported it as AI-driven, a rise of 56 per cent on the previous year, while the average global breach cost climbed 12 per cent to nearly five million dollars. The most consequential finding sits further down the report. Among organisations that suffered an AI-related breach, 92 per cent lacked proper AI access controls. Those breaches, driven largely by deepfake impersonation and AI-enabled malware, cost an average of six million dollars, and IBM’s own summary of the shift is that attacks are becoming faster and cheaper to launch while breaches keep becoming more expensive to find and fix.
INSIGHT AND ANALYSIS
That figure does not describe a sophistication problem. Ninety-two per cent is not the signature of an advanced adversary defeating a well-designed control. It is the signature of a control that was never implemented at all. Organisations deployed these systems at pace, connected them to customer records, financial systems, document repositories and internal communications, and never established who authorised that access, what precisely each system could reach, or under what conditions the permission would lapse. In any other context the omission would be caught immediately. A server installed with unrestricted access to production data and no authorisation record would be a finding in the first audit and a resignation matter in the second. The difference is that AI arrived through the innovation agenda rather than the technology risk process, and enthusiasm is a poor substitute for authorisation discipline. Speed of adoption has outrun control of access, and the breach data now shows what that gap costs.
IMPLICATIONS
South African organisations are not observing this from a distance. The Information Regulator recorded 2,374 security compromise notifications in the 2024/25 financial year at an average of 198 a month, rising to an average of 284 a month from April 2025, an increase of 40 per cent. The financial exposure is not confined to the R10 million administrative ceiling, since section 99 of POPIA creates a civil remedy allowing affected data subjects to claim compensation, and the Cybercrimes Act obliges designated financial and communications institutions to report offences to the police within 72 hours. Insider risk compounds the picture, with malicious insider events rising internationally from three in the whole of 2025 to 21 in the opening six months of 2026. An AI system holding unbounded access cannot distinguish between a legitimate internal request and a compromised one, which means over-permissioned tools amplify the insider problem rather than sitting alongside it.
CLOSING TAKEAWAY
The remedy IBM proposes is not exotic. Identity systems should grant AI agents just-in-time access, time-bound approvals and continuous risk-based runtime controls drawn from devices, users and workloads. None of that is novel thinking. It is ordinary access governance applied to a new category of system. What a board should require is simpler still, namely a register naming every AI system operating in the organisation, the data and systems each one can reach, the person who authorised that access, and the date the authorisation expires. Where that document does not exist, the organisation cannot describe its own exposure, and an exposure that cannot be described cannot be governed. Ninety-two per cent of organisations established this after the breach rather than before it.
Johan Steyn is a prominent AI thought leader, speaker, and author with a deep understanding of artificial intelligence’s impact on business and society. He is passionate about ethical AI development and its role in shaping a better future. Find out more about Johan’s work at https://www.aiforbusiness.net



Comments