AI ramps up data breach costs – with one in ten businesses now hit by AI data breaches

One in ten businesses have experienced a data breach related to use of artificial intelligence (AI), according to new research.

IBM and Ponemon Institute’s Cost of a Data Breach report found AI is increasingly becoming a security risk: 13% of businesses surveyed said they had fallen victim to AI-related incidents. What’s more, 97% of affected companies did not have proper controls for their AI models or apps. According to the research, compromised apps, APIs or plugins were typically to blame for AI-related security incidents.

Nearly two thirds of businesses who fell victim to an AI-related breach suffered “broad data compromise” while around one third experienced “operational disruption”, the report noted.

Supply chain compromise was the most common cause, accounting for 30% of AI-data breaches, followed by model inversion at 24% and model evasion at 21%.

For CIOs, the risks associated with AI are likely increased by employees’ use of non-authorised tools – so-called ‘shadow AI‘. The report noted that breaches involving shadow AI resulted in more company data and intellectual property being compromised and added around $670,000 to the cost of a breach, compared to incidents that did not involve shadow AI.

The average cost of a breach in the US has now hit $10.22 million – up almost 10% year on year, the report said, due to increasing fines linked to breaches, as well as rising detection and escalation costs. In the UK, the average cost of a breach is now $4.41 million, compared to $4.53 million last year. Globally, businesses that experience a data breach face a bill of $4.4 million per incident.

AI data breaches: good news… and phishing attacks

The report did highlight some good news for enterprises that find themselves on the wrong end of a data breach, however. Worldwide, the average cost of an incident has fallen by 9% compared to last year.

The report attributed the fall to businesses finding and containing breaches faster than in previous years, thanks to the rise of AI and automation in security departments. Now, the report found, breaches are identified and contained within 241 days, compared to 258 days last year and a record 287 days in 2021.

Predictably, it’s not just security professionals that are ramping up their use of AI – criminals are too. The report found 16% of all breaches saw attackers taking advantage of AI, most commonly  to create phishing attacks and deepfakes, or impersonate people to gain access to systems.

Phishing remains the most common way of attackers gaining unauthorised access to systems, with around 16% of all data breaches now involving phishing attacks, followed closely by supply chain compromise, which accounted for 15% of breaches.

Jo Best
Jo Best

Jo has been writing about technology for over 20 years, and has always been fascinated by emerging technologies and innovation. These days, she's particularly interested in the intersection of technology, science, and human health.