For three years AI security was argued in scenarios. What if a model leaks its training data, what if an agent is talked into moving money, what if the corpus is poisoned. The 2026 study of 602 organisations that were actually breached replaces the scenarios with invoices, pricing each AI incident type, the hour it runs, and the defence. Read the ranking and it does not describe a model behaving badly. It describes ordinary access control failure in a new place.
Set the usual allocation of AI security money against what the breach figures reward. The difference is not maturity or headcount. It is whether the spend watches the model or bounds what can reach it and how long an incident is allowed to run.
$1.93M is the average saving per breach where AI and automation are used in defence, the largest single reduction in the study and the one most directly bought with a decision. The distribution is where the argument sits. Half of breached organisations apply AI to threat hunting. Only 18% apply it to vulnerability management.
Roughly $1M is added to the average breach when the attacker uses AI, on a global average that reached $4.99M and rose 12% year on year. That premium arrives whether or not you deploy AI yourself, which makes it the one line here that no internal decision can switch off. It is the offence side compounding.
Model safety is a supplier property and a research field, mostly outside the control of the organisation buying the model. Everything the 2026 data prices sits inside that control. Which systems exist, who and what can reach each one, what data sits behind it, who can switch it off today, and how long the last incident took to contain.
Every hosted model, agent, embedded vendor feature and API integration, with its owner, its data and its credential. Pull from network logs and the expense ledger, since the systems that matter most are undeclared.
Authenticated, attributed and rate-limited calls, with retrieval inheriting source permissions. This is the control 92% of AI-breach victims lacked, and it bears on both of the costliest incident types.
Agents, service accounts and connectors get an owner, a scope, an expiry and a revocation path, on the same lifecycle a member of staff gets. Fewer than half of breached organisations do this.
Simulate a compromised agent credential on the highest-value system. Measure the hours to detect, revoke, contain and confirm, then multiply by $1,100 and take that number to the funding conversation.
Inversion reconstructs sensitive training or reference data from a model that answered too many queries for too many callers, so it prices as a data exposure event rather than a systems incident. It also runs invisibly, with no malicious instruction and no anomalous payload, which means it is usually found late.
Marginally, and not where the money is. The cost data rewards bounding what an attacker reaches and shortening how long they have, which means access control on models and data, scoped credentials per tool, and a rehearsed containment path. Filtering lowers the hit rate on one incident type and changes nothing about the blast radius.
Yes, on two counts. The roughly $1M AI-driven attack premium lands on the defender regardless of what the defender deployed. And one in five breaches in the 2025 data traced back to unsanctioned AI use, so the question is not whether you deployed it but whether you know where it already is.
Half of breached organisations use AI for threat hunting and only 18% use it for vulnerability management, a near fivefold gap between finding the attacker already inside and closing the hole they came through. Hunting produces visible output weekly and patching produces an absence, which explains the split without justifying it.
Use the only line with a unit price. At roughly $1,100 per hour, an extra day of incident costs about $26K and an extra fortnight about $370K, so every control that shortens the clock can be priced against the hours it removes. That turns a security ask into arithmetic rather than assurance.
This report gives a board the price. Benchmarking AI Security scores the systems you already run against twenty controls, and AI Security: What Buyers Should Ask puts the same ground to a supplier before you sign. Read this for the argument, the other two for the work it funds.
Drop your details and we'll send The AI Security Report straight to your inbox - no spam, unsubscribe anytime.
Two weeks, free, nothing to sign. Working code in your repo, a visible backlog, and an architecture note on access control, non-human identity and containment for one live AI system. SECTION 7 - FAQ - 5 to 8 questions
Book an AI security review