Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
whitepaper

The AI Security Report.

For three years AI security was argued in scenarios. What if a model leaks its training data, what if an agent is talked into moving money, what if the corpus is poisoned. The 2026 study of 602 organisations that were actually breached replaces the scenarios with invoices, pricing each AI incident type, the hour it runs, and the defence. Read the ranking and it does not describe a model behaving badly. It describes ordinary access control failure in a new place.

In depth

The Argument Has Moved From Whether To How Much.

01

The costliest AI attacks are the least discussed.

Model inversion leads at $6.07M and barely reaches a board agenda, while prompt injection at $5.89M takes most of the conference programme and most of the tooling spend, on a gap of under 4 per cent. Inversion goes unmentioned because it does not look like an attack while it runs: no malicious instruction, no anomalous payload, just a caller with legitimate access making many legitimate queries against a model grounded on data they were never entitled to see. It lands in the cost data rather than the alert queue.

In shortIt lands in the cost data rather than the alert queue
02

This is an identity problem wearing a model-shaped mask.

Of organisations with an AI-related breach, 92% had no proper AI access controls, only 40% control access to their models and data at all, and fewer than half secure non-human identities, the category every agent, service account, connector and API key belongs to. That explains the cost ranking better than any property of the models does, since inversion needs unmetered query access and injection needs an agent on a credential broad enough to be worth persuading. Remove the access and both still happen, at a far lower price, since reachable blast radius is what the invoice is calculated from.

In shortRemove the access and both still happen, at a far lo…
03

Containment time is the one line a board can buy down.

Most figures here describe a condition; this one describes a rate, at roughly $1,100 per hour, so a breach running an extra day costs about $26K and an extra fortnight about $370K. Runbooks that name an AI system, credentials revocable per tool rather than per platform, logs that exist before the investigation starts, and one person with authority to stop a system all shorten the clock. Each has a price, and each sits against $1,100 an hour.

In shortEach has a price, and each sits against $1,100 an hour
04

Shadow AI is the supply line, not a separate risk.

In 2025 one in five breaches traced back to unsanctioned AI use at a premium of roughly $670K, and 63% of breached organisations had no AI governance policy at all. The 2026 access data gives the mechanism: a system nobody registered cannot be inside the 40% whose access is controlled, and its credential is a non-human identity in the half that goes unsecured. Blocking tools does not remove it, and a registration path quicker than the workaround does.

In shorta registration path quicker than the workaround does
The detail

Where The Budget Goes, And Where The 2026 Cost Actually Sits.

Set the usual allocation of AI security money against what the breach figures reward. The difference is not maturity or headcount. It is whether the spend watches the model or bounds what can reach it and how long an incident is allowed to run.

Zone · 01

The defender discount

$1.93M is the average saving per breach where AI and automation are used in defence, the largest single reduction in the study and the one most directly bought with a decision. The distribution is where the argument sits. Half of breached organisations apply AI to threat hunting. Only 18% apply it to vulnerability management.

Zone · 02

The attacker premium

Roughly $1M is added to the average breach when the attacker uses AI, on a global average that reached $4.99M and rose 12% year on year. That premium arrives whether or not you deploy AI yourself, which makes it the one line here that no internal decision can switch off. It is the offence side compounding.

Zone · 03

Five questions per system

Model safety is a supplier property and a research field, mostly outside the control of the organisation buying the model. Everything the 2026 data prices sits inside that control. Which systems exist, who and what can reach each one, what data sits behind it, who can switch it off today, and how long the last incident took to contain.

By the numbers

The figures that make it a board-level conversation.

$6.07M
model inversion, the costliest AI incident type in the 2026 breach study
$5.89M
prompt injection, second on the list and 18% above the global average breach
$1,100
added for every hour a breach runs before it is contained, the only line with a unit price
Inside the report

What you'll take away.

01

Step 1 - Ask for the AI inventory and treat its absence as the first finding

Every hosted model, agent, embedded vendor feature and API integration, with its owner, its data and its credential. Pull from network logs and the expense ledger, since the systems that matter most are undeclared.

02

Step 2 - Put access control on models and data, and join the 40%

Authenticated, attributed and rate-limited calls, with retrieval inheriting source permissions. This is the control 92% of AI-breach victims lacked, and it bears on both of the costliest incident types.

03

Step 3 - Bring non-human identities inside identity governance

Agents, service accounts and connectors get an owner, a scope, an expiry and a revocation path, on the same lifecycle a member of staff gets. Fewer than half of breached organisations do this.

04

Step 4 - Rehearse containment on one AI system and record the clock

Simulate a compromised agent credential on the highest-value system. Measure the hours to detect, revoke, contain and confirm, then multiply by $1,100 and take that number to the funding conversation.

Questions

Frequently asked.

Why is model inversion costlier than prompt injection?

Inversion reconstructs sensitive training or reference data from a model that answered too many queries for too many callers, so it prices as a data exposure event rather than a systems incident. It also runs invisibly, with no malicious instruction and no anomalous payload, which means it is usually found late.

Does better input filtering reduce these costs?

Marginally, and not where the money is. The cost data rewards bounding what an attacker reaches and shortening how long they have, which means access control on models and data, scoped credentials per tool, and a rehearsed containment path. Filtering lowers the hit rate on one incident type and changes nothing about the blast radius.

We have not deployed AI. Are these numbers relevant to us?

Yes, on two counts. The roughly $1M AI-driven attack premium lands on the defender regardless of what the defender deployed. And one in five breaches in the 2025 data traced back to unsanctioned AI use, so the question is not whether you deployed it but whether you know where it already is.

What is the clearest misallocation in the 2026 data?

Half of breached organisations use AI for threat hunting and only 18% use it for vulnerability management, a near fivefold gap between finding the attacker already inside and closing the hole they came through. Hunting produces visible output weekly and patching produces an absence, which explains the split without justifying it.

How do we turn this into a funding case?

Use the only line with a unit price. At roughly $1,100 per hour, an extra day of incident costs about $26K and an extra fortnight about $370K, so every control that shortens the clock can be priced against the hours it removes. That turns a security ask into arithmetic rather than assurance.

Where do your other AI security resources fit around this one?

This report gives a board the price. Benchmarking AI Security scores the systems you already run against twenty controls, and AI Security: What Buyers Should Ask puts the same ground to a supplier before you sign. Read this for the argument, the other two for the work it funds.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send The AI Security Report straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Price one incident properly and the rest of the argument ends there.

Two weeks, free, nothing to sign. Working code in your repo, a visible backlog, and an architecture note on access control, non-human identity and containment for one live AI system. SECTION 7 - FAQ - 5 to 8 questions

Book an AI security review