Editor’s Note: Artificial intelligence governance lost ground at breached organizations this year even as AI exposure grew, and the 2026 Cost of a Data Breach Report from IBM and Ponemon Institute put numbers on the gap. Sixty-eight percent of breached organizations had no AI governance policy in place, five of the six governance controls measured in both years lost adoption, and only 19 percent reported governance and security teams working together. Separately, security incidents involving shadow AI climbed to 43 percent of the sample from 20 percent and averaged $5.39 million.

That combination should register with cybersecurity, data privacy, regulatory compliance and eDiscovery professionals for a shared reason: an organization that cannot inventory its AI systems cannot secure them, cannot document conformity for them, and cannot reliably preserve what they generate. Prompts, model outputs and agent logs can constitute business records or discoverable ESI depending on content, retention duty and control. Shadow AI puts them where no data map reaches.

Watch three things next: whether the share of organizations with policies actually in place recovers from 32 percent, whether the 247-day breach lifecycle keeps climbing, and whether governance and security functions start reporting into the same review. The EU deferral of high-risk obligations to December 2027 buys calendar time, not evidentiary readiness, and most Article 50 transparency requirements begin applying this month, with a limited transition through Dec. 2, 2026, for certain systems already on the market.


Content Assessment: Two-thirds of breached organizations had no AI governance policy in place

Information - 94%
Insight - 93%
Relevance - 93%
Objectivity - 94%
Authority - 95%

94%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Policy without control: the AI governance gap in IBM's 2026 Cost of a Data Breach Report."


Industry News – Cybersecurity Beat

Policy without control: the AI governance gap in IBM’s 2026 Cost of a Data Breach Report

ComplexDiscovery Staff

Two-thirds of the organizations in IBM’s 2026 breach study had no AI governance policy in place. Of that 68 percent, 35 percent reported no policy at all and 33 percent said one remained in development.

The finding comes from the 2026 Cost of a Data Breach Report, released July 29 by IBM. Ponemon Institute conducted the research; IBM sponsored, analyzed and published it, and IBM sells the identity, encryption and security automation products the findings favor. That alignment does not make the data wrong, but it belongs in view while reading it. The study examined 602 organizations across 16 countries and regions and 17 industries, drawing on 3,558 interviews about breaches that occurred between March 2025 and February 2026.

The headline number was the global average cost of a breach: $4.99 million, up 12 percent and the highest the report has recorded in 21 editions. That reversed last year’s 9 percent decline, when security teams appeared to be gaining. Average costs in the United States reached a record $11.5 million against $10.22 million a year earlier, an increase of about 13 percent, and roughly 2.3 times the global average. The report states this two ways: its key findings page gives 13 percent and over twice the global average, while its detailed text on the same data gives 11 percent and nearly double. The chart values support the first reading.

The number that should hold the attention of anyone responsible for records, compliance or discovery sits deeper in the report, and it is worth taking apart. Sixty-eight percent of breached organizations lacked AI governance to manage AI or detect its unsanctioned use, against 63 percent the year before. That figure is a composite. Thirty-five percent had no policies at all, down from 41 percent, and 33 percent had policies still in development, up from 22 percent. The share with policies actually in place fell to 32 percent from 37 percent.

Read the composition rather than the headline and the picture sharpens. The 2026 sample holds fewer organizations reporting no policy at all, and fewer reporting a finished one. The distribution shifted toward a middle state where a policy exists on a slide deck and not in a control. Each annual study draws a different sample matched on characteristics rather than tracking the same companies, so this describes the population studied and not a journey any particular organization took.



Five of six comparable governance controls declined

Of the six AI governance control types the study measured in both years, five lost adoption, as of the February 2026 close of the study window.

Strict approval processes for AI deployments, the most common control, dropped to 38 percent from 45 percent. Use of AI governance technology fell to 33 percent from 39 percent, and governance frameworks to 33 percent from 39 percent. Employee training on AI risks slipped to 30 percent from 36 percent. Regular audits for unsanctioned AI declined to 29 percent from 34 percent. Adversarial testing, or red teaming, was the only comparable control to gain ground, reaching 25 percent from 22 percent. Coordination between governance and security teams, along with two residual response options, appeared for the first time this year and carry no prior-year comparison. The 32 percent holding a finished policy, cited above, comes from a separate question and is not a seventh control in this set.

Researchers studied one coordination question for the first time, and the answer was 19 percent. That is the share reporting that governance teams and security teams worked together on AI oversight, which leaves a substantial majority without reported coordination. The question permitted multiple responses, so non-selection does not establish that the remaining organizations deliberately separated the functions; it establishes only that they did not report coordination. What the figure does establish is that coordination was the least-reported substantive governance practice on the list, below every control that preceded it, and uncoordinated oversight is where policy conflicts and slow incident response tend to originate.

The exposure widened while the controls thinned. Security incidents involving an AI model or application reached 21 percent of breached organizations, up from 13 percent, a 61 percent increase. Among organizations that suffered an AI-related breach, 92 percent lacked proper AI access controls, meaning role-based access and multifactor authentication on the models themselves. Across all breached organizations, only 40 percent applied access controls to AI models and data at all.

Identity and access management was the second-largest cost reducer among the 30 factors the study measured, associated with a $225,622 reduction against the average breach. Ranked across all 30 by size of effect in either direction it sits third, behind supply chain breaches at $227,250. The report measures each factor in isolation and does not establish causation, so read either figure as an association rather than a return. IBM draws the contrast itself: it names identity and access management among the most effective cost reducers, then reports that only 40 percent of organizations applied access controls to AI models and data.

Shadow AI became the expensive unknown

Security incidents involving shadow AI, meaning staff running AI tools the organization never approved, reached 43 percent this year against 20 percent last year. Breaches involving shadow AI averaged $5.39 million, against $4.63 million a year earlier.

The downstream damage tracked with what an ungoverned data path produces. Forty-nine percent of shadow AI incidents caused data loss or compromise, 42 percent disrupted operations and 35 percent produced reputational damage. In about one in five, the organization paid a regulatory fine.

The practical response starts with discovery, not policy. An acceptable-use memo does not find the analyst pasting customer records into a consumer chatbot. Network egress monitoring, browser telemetry, single sign-on logs and expense-report review for unbudgeted AI subscriptions do. Only 29 percent reported running regular audits for unsanctioned AI, leaving most organizations without that particular monitoring mechanism. Other enforcement paths were measured separately and some of those organizations will hold them, but an unaudited environment is one where the size of the problem stays unknown. The factor the report labels “lack of visibility into the number and location of applications (shadow IT)” was associated with costs $201,165 above the global average.

Attackers skipped the approval process

One in four organizations that experienced a malicious attack reported it was AI-driven, a 56 percent increase over last year, and another 11 percent could not determine whether AI was involved. Malicious AI-driven attacks averaged $6.04 million against $5.03 million for malicious attacks without AI, a gap of about $1.01 million. Deepfake and impersonation attacks accounted for 45 percent of that volume, AI-enabled malware 19 percent and AI-generated phishing 17 percent.

Sixty-two percent of AI-driven attacks targeted critical infrastructure sectors, with financial services and energy organizations showing the highest concentration. Financial services breaches averaged $6.29 million.

Defenders lost ground on the clock. Mean time to identify and contain a breach rose to 247 days from 241, a 2.5 percent increase that reversed a five-year decline. Breaches running past 200 days averaged $5.65 million; those resolved faster averaged $4.32 million.

Suja Viswesan, vice president of IBM Security Software, said in the company’s announcement that attackers are using AI to operate faster and more cheaply while the cost of successful intrusions keeps climbing, and that the delay between finding a weakness and closing it converts directly into higher losses.

IBM anchored its forward-looking warning to outside work. A survey by a University of California, Berkeley team including Yujin Potter and Dawn Song asked AI and security researchers to score the offense-defense balance on a scale of zero to 100 and reported that experts expect it to favor attackers by 31.7 percent within two years, narrowing to 12.8 percent at five years and 0.46 percent at 10. The sample was small: 129 experts opened the survey and 34 completed it. Treat it as expert sentiment, not measurement.

Where AI incidents actually got expensive

The report priced AI incident types, and the ranking is instructive for anyone building a control program.

Model inversion, where an attacker reconstructs protected training data by probing a deployed model, was costliest at $6.07 million. IBM describes that as 18 percent above the global average, though its own published figures imply about 22 percent, and no figure in the report produces the $5.14 million baseline that 18 percent would require. Prompt injection followed at $5.89 million. Cloud security misconfigurations affecting AI workloads reached $5.25 million, malicious models $4.94 million, model evasion $4.72 million and compromise of connected applications, APIs and plug-ins $4.37 million.

Note what the ranking spans. Model inversion and prompt injection, the two costliest, attack how a model reasons and what it retains. But malicious models, model evasion and data poisoning are model-level attacks too, and all three sit below cloud misconfigurations on the cost scale. The list does not sort cleanly into model problems and infrastructure problems. IBM’s executive summary described the root causes of AI-related incidents as structural rather than model risk, a useful corrective for organizations treating vendor selection as a security decision, though the incident-cost ranking complicates that framing rather than confirming it.

Among factors associated with higher costs, supply chain breaches led at $227,250, followed by security system complexity at $208,265, shadow IT at $201,165 and noncompliance with regulations at $201,112. Among those associated with lower costs, a DevSecOps approach led at $253,805, ahead of identity and access management, key lifecycle management tools at $214,923 and encryption at $213,478. None of these figures is additive, and none is a measured effect.

Encryption deserves its own line. Fifty-three percent of breached organizations had not encrypted sensitive data at rest and in motion when the breach occurred. Another 10 percent did not know.

Brussels moved the deadline, not the obligation

European timing shifted this summer in a way that is easy to misread as relief.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, took effect July 27, 2026, and moved the application date for high-risk AI obligations under Annex III of the AI Act to Dec. 2, 2027, and for Annex I systems to Aug. 2, 2028. Article 50(1), which requires providers of AI systems intended to interact directly with natural persons to inform them they are dealing with an AI system, still applies from Aug. 2, 2026. Providers of systems generating synthetic audio, image, video or text that were on the market before that date have until Dec. 2, 2026, to meet the machine-readable marking requirement in Article 50(2).

Deferring application dates is not withdrawing obligations, and it does nothing about the evidentiary problem underneath. An organization that cannot inventory its AI systems in 2026 will not be able to document conformity for them in 2027, and the inventory is the slow part. Noncompliance with regulations was associated with costs $201,112 above the global average in this year’s data, a figure drawn entirely from obligations already in effect.

Preservation gaps hide inside governance gaps

Customer personally identifiable information appeared in 52 percent of breaches, the most targeted category, at $192 per record. Intellectual property was costliest at $196 per record. Ransomware attackers, present in 39 percent of breaches, have broadened what they weaponize: 41 percent threatened to publicize the breach or hand data to reporters, and 19 percent went after internal communications including email and Slack messages.

For discovery practitioners, a governance gap is a preservation gap. Prompts, model outputs, retrieval logs and agent action histories can constitute business records or discoverable electronically stored information, depending on their content, the retention obligations that attach to them, their relevance to a matter, and whether they sit within the organization’s possession, custody or control. Shadow AI makes every one of those determinations harder, because the systems generating the material may sit outside approved data maps, outside negotiated terms of service and outside the jurisdictions the organization selected. A legal hold cannot reach a system nobody knows exists, and a data map that omits the tools employees actually use is not a data map. The 19 percent coordination figure is where this becomes concrete: where governance and security do not meet, neither is well positioned to tell legal what exists.

Information governance inherits the same problem one layer down. Retention schedules written for document management systems often say nothing about the source chunks, metadata, cached prompts and derived embeddings that vector stores retain, and disposition evidence may be incomplete when those materials outlive the record they came from. Only 46 percent reported securing non-human identities, the credentials assigned to machines and agents, in AI workflows, leaving most of the study population without reported controls over those credentials and raising the risk of persistent or under-reviewed access to the data those workflows touch.

Read the methodology before quoting the number

Ponemon Institute, founded in 2002 and chaired by Larry Ponemon, describes its work as independent research. The methodology section is candid about limits worth restating before any of these figures reach a board deck.

The sample is nonstatistical, so margins of error and confidence intervals do not apply. The sampling frame was judgmental and, by the researchers’ own assessment, biased toward organizations with more mature privacy and information security programs. Costs are extrapolated rather than drawn from financial records. Nonresponse bias was not tested. Every governance figure is self-reported by people describing their own organization’s failures.

Those limitations could mean the 68 percent figure understates the governance problem, particularly because a sampling frame favoring mature programs should over-represent organizations that already hold policies. That is the more probable direction, but it is not the only one: self-reporting in a confidential benchmark does not distort in a single direction, nonresponse was never tested, and neither the direction nor the size of any resulting bias can be determined from this design. Read 68 percent as a descriptive result for a nonstatistical sample, not as a population estimate and not as a floor.

Organizations using security AI and automation extensively, 36 percent of the sample, averaged $4 million per breach against $5.93 million for those using none, and resolved incidents in 215 days against 280. That is a correlation, and the study’s design cannot raise it past one: it does not control for security program maturity, and mature programs may both adopt these tools and contain breaches faster for reasons the research never measured. The spending figures need their denominators stated. In follow-up research conducted in May, 456 of the original 602 organizations responded, and 78 percent of those said they were aware of new frontier AI model threats. Among that aware subset, about 356 organizations, 85 percent planned to increase security spending. The 64 percent figure comes from the original research stage across the full sample. The report charts the two as before and after frontier model threat awareness, which invites reading them as a matched pair; they rest on different respondent bases and support only a directional reading. Spending is the easy commitment. Governance is the one that requires telling a business unit no.

Which raises the question worth carrying into the next budget cycle: if your organization approved an AI deployment this quarter, can you name who reviewed it, what data it touches, where its outputs are stored, and who would preserve them under a litigation hold?



News sources



Assisted by GAI and LLM technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more legible for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).