Security breaches involving shadow AI have surged to 43%, more than doubling from 20% in 2025, according to the IBM Cost of a Data Breach Report 2026. This jump contributes to a record average breach cost of $4.99 million worldwide, marking a 12% increase from last year. The United States faces the steepest financial impact, with an average cost of $11.5 million per breach, more than twice the global average.

Some of the priciest incidents stem from agent-native attacks like model inversion and prompt injection, which exploit autonomous AI permissions. Model inversion attacks average $6.07 million each, while prompt injection costs $5.89 million. Such figures highlight the vulnerabilities tied to insufficient governance over non-human identities an area where 92% of organizations hit by AI-related breaches lacked proper controls.

Escalating Attacks and Market Response

AI-driven breaches are no longer rare. One in four organizations reported such an incident, overwhelmingly targeting critical infrastructure. Financial services and energy sectors bore the brunt, with breaches costing approximately $6 million per event. Attack tactics have evolved dramatically, including automated reconnaissance, AI-generated phishing, deepfake impersonations, and adaptive malware, all enabling attackers to strike faster and more effectively.

Limor Kessem, IBM's Global Lead for X-Force Cyber Crisis Management, pointed out that AI accelerates the complexity and cost-effectiveness of sophisticated attacks. AI-powered incidents rose 56% year-over-year, with nearly half involving deepfake and impersonation methods.

Addressing this gap, Cyera's billion-dollar acquisition of Oasis Security spotlights the growing market for managing AI agents and automated software. Oasis specializes in agentic access management, directly tackling the non-human identity risks that IBM's data associates with higher financial damages.

Meanwhile, regulatory frameworks lag behind. The EU AI Act’s high-risk compliance rules have been postponed to December 2027, with only a third of member states preparing oversight authorities. Projects like the Nvidia Open Secure AI Alliance are assembling defensive tools, but organizations still struggle to keep up as vulnerabilities emerge faster than fixes can be applied.

This material is for informational purposes and does not constitute financial advice.