AI security incidents are spreading across company systems and attack chains
IBM’s company study maps access controls and incident costs, while Interpol’s Africa assessment shows how AI is spreading through different stages of the attack chain.
Artificial Intelligence··Evening
Entry points and incident costs inside companies
IBM’s 2026 Cost of a Data Breach study, conducted by the Ponemon Institute, covers 602 companies. It says 92 percent of companies that experienced an AI-related security incident lacked adequate access controls for their AI systems. In roughly one fifth of affected organisations, the attacker entered through a compromised API, a connected application, or a misconfigured cloud service. IBM says the use of open-source rather than proprietary models made little difference to the outcomes. The survey-based figures put the average cost of an incident with an AI component at $5.33 million, compared with $4.70 million when no such component was present. The worldwide average across all breaches rose 12 percent to $4.99 million. When attackers used AI, the average was $6.04 million, against $5.03 million when they did not. The company-side picture therefore centres on access, connected software, and cloud configuration rather than on the model category alone.[1]
Every stage of the attack across Africa
Interpol’s 2026 assessment brings together data from 36 countries for 2025–2026. The agency reports AI involvement in 55 percent of reported cybercrimes and says losses increased from 192 million dollars in 2024 to 484 million dollars in 2025. The assessment counts about 600,000 extortion cases involving fake imagery made with AI, synthetic identities capable of passing biometric checks, and attacks that automate several stages. Use is not confined to the first contact: reconnaissance, phishing, extortion, and evasion appear as connected parts of the same chain. Four coordinated operations during the reporting period produced more than 1,500 arrests. These figures depend on each country’s capacity to detect and report incidents, which limits direct comparison between countries. Even with that qualification, the assessment provides a broad regional view of AI being used not as one isolated attack tool but across linked criminal steps.[2]
Two views of the same operational shift
The two studies measure different units. IBM begins with the affected company and examines entry points, access controls, and monetary cost. Interpol starts with national reporting and assembles the stages at which AI is used, the regional loss total, and the results of coordinated operations. The 92 percent and 55 percent figures do not share a denominator: the first describes missing access controls among companies that suffered an AI-related incident, while the second describes AI involvement among cybercrimes reported across 36 countries. That distinction matters. Read together, they show two sides of an operational shift. For organisations, entry points include connected applications, APIs, and cloud settings. For attackers, the same technology links work from reconnaissance through evasion. One report shows where controls inside companies failed; the other shows how far the criminal chain has expanded. The security agenda also encompasses the access arrangements around models, connected software, reporting capacity, and cross-border enforcement operations, rather than model behaviour alone.[1], [2]