
The threat posed by attackers using AI to enhance their offensive activities, and the need for defenders to use AI to combat those activities, has been a major focus of our analysis in 2026.
New data from IBM quantifies the financial impact of AI-powered attacks, how AI can lessen that impact, and how AI-powered defenses can protect against the uninformed use of AI – or shadow AI – by a company’s own workers.
The 2026 Data Breach Report from IBM presents data from 600+ organizations across 17 industries and 16 geographic regions; it provides valuable insights into the rapidly shifting security challenges facing business leaders, and the increasingly powerful defenses at their disposal.
In this report, I’ll present what I find to be five of the most compelling findings through an AI lens, but I recommend reviewing the full report which is packed with fresh insight.
Breach Cost By Industry
Tech analysts widely cite a few industries as having the most valuable – and sensitive – data to maintain and protect. And the findings in this report on the cost of data breaches aligns closely with those long-held views.
Overall, the study found that the global average cost of a data breach – across industries — reached $5 million last year, an increase of 12% vs. 2025. The report notes that 63% of those costs – nearly two thirds – are from two functions: 1) detection and escalation and 2) lost business. As I reported earlier this week, detection and escalation are being addressed by the cybersecurity community broadly.
Even more insightful is the breakdown of breach cost by industry, where healthcare leads the way with an average cost of $6.6 million in 2026 which, interestingly, is down from over $7 million in 2025. “Attackers continue to value and target the industry’s patient PII, which can be used for identity theft, insurance fraud and other financial crimes,” the report says. Personally Identifiable Information (PII) includes data such as tax ID numbers, emails, and home addresses.
Healthcare is followed in breach costs by financial services, with a per-breach cost of $6.3 million in 2026, up 11% from $5.6 million in 2025. In all of the other top 10 industries by breach costs, the cost per incident increased in 2026.
The most stolen or compromised data type, at 52% of the total, was customer PII and the cost of those PII compromises averages $192 per record.
Average Data Breach Cost by Industry, in Millions

Also notable: costs escalate when attacks leverage AI; those powered by AI average $6 million per breach, vs. $5 million for those that aren’t AI driven. The most common type of AI attack (45%): deepfake or impersonation attacks.
Recovery Time Factors
Once a data breach occurs, it’s clear that companies continue to struggle to recover. Just 42% of companies report they have fully recovered from a breach and among those that have recovered, 71% need 100 days or more to do so. That’s a protracted recovery time, if recovery happens at all, highlighting again how damaging breaches can be.
Time For Organizations to Fully Recover from Data Breaches

Going on Offense
Given the severity and impact of data breaches, it may come as a surprise that organizations are not extensively using AI to protect their data – yet. A little over one third of respondents — 36% in 2026 – report extensive use of AI, up more than 10% from one year ago. But 25% still report no use of AI in security measures – lack of trust in AI is likely one important factor in this limited-use finding.
Percent of organizations in each category of Defensive AI use

There’s hard financial data in support of using AI defensively: a nearly $2 million cost per breach savings for those that use AI extensively. The average cost is $4 million for AI users and nearly $6 million for non-users.
Where AI Is Being Used
The aforementioned AI security leaders (in deployment terms) are focusing their efforts on AI agents that perform threat hunting (54%) and automated response/containment (54%), followed by alert triage (45%). All three functions are frequently cited by security and tech pros as major stress points with a strong propensity to overwhelm human security analysts, so this finding underscores how the human capacity problem can be addressed with AI.
Use of AI Agents by Security Function

AI In The Shadows
The final data point we’ll highlight revolves around shadow AI – the practice of employees using unauthorized, typically free, tools to do their work without an organization’s approval or knowledge. It could also include individually created AI agents that, without proper guardrails, could wreak havoc or open the door to data breaches.
This phenomenon, which mirrors shadow IT as well as past struggles with personal cell phones for corporate functions, has given rise to vendor initiatives aimed at providing inventories or ideally, complete visibility, into the AI tools in use within a company.
The data breach report hones in specifically on the impact of a shadow AI-driven security incident, showing data loss and operational disruption as the downsides impacting the most companies – and with more companies reporting those outcomes in 2026 vs. 2025.
Companies Reporting Each Shadow AI Security Incident Impact

AI is presenting new opportunities to combat bad actors and misguided employees, but it’s clear companies are in a race to keep up with the AI-driven activities of those groups. The data breach report overall could be considered mildly encouraging in that it shows AI being used defensively is putting up important wins. But not enough companies are availing themselves of the technology – or they aren’t yet confident enough in the technology to this point – to truly turn the tide.




