IBM finds 92% of companies hit by AI security breaches lacked basic access controls
92%. That's the share of companies breached through AI systems that lacked basic access controls — not model vulnerabilities.

Why it matters
AI security incidents are overwhelmingly operational failures, not frontier model problems. Practitioners deploying AI need to audit access controls before worrying about model robustness — a governance and policy story, not a capability one.
The key facts
8 to know92% of companies hit by AI security breaches had inadequate access controls
Model vulnerabilities were rarely the root cause
IBM security research finding
Access control gaps identified as primary attack surface
92% of companies that experienced AI security incidents had inadequate access controls
Model capability/safety was rarely the root cause of breaches
Access control failures, not frontier model issues, drive real-world AI security incidents
Source: IBM security research
Go to the source
The Decoderthe-decoder.com
Publisher excerpt: According to IBM, 92 percent of companies that experienced an AI security incident had inadequate access controls for their AI systems. The model itself was rarely the problem.
