92% of AI breaches traced to weak access controls, IBM finds

A staggering 92% of companies hit by AI security incidents had neglected basic access controls, IBM reports. The issue wasn’t the AI model itself—it was the lack of proper safeguards around who could interact with or modify these systems.
The human factor behind AI breaches
IBM’s findings point to a critical oversight: organizations are rushing to deploy AI tools without treating them like the high-stakes systems they are. Weak access controls—such as shared credentials, unmonitored admin rights, or no multi-factor authentication—created easy entry points for attackers. The result? Sensitive data leaks, model poisoning, or unauthorized use of AI services costing millions.
Why governance lags behind adoption
The gap between AI adoption and security maturity isn’t new, but IBM’s data quantifies the risk. Companies often prioritize speed and innovation over foundational security measures. Yet, as AI systems grow more integrated into workflows, the attack surface expands. The report suggests many breaches could have been prevented with stricter identity management and least-privilege principles.
What’s next for enterprises
IBM urges organizations to treat AI systems with the same rigor as core IT infrastructure. Regular audits, role-based access, and real-time monitoring are no longer optional. For companies still treating AI as a "black box," the message is clear: security must be built in from day one.
Why it matters
This isn’t just about compliance—it’s about resilience. AI breaches can disrupt operations, erode customer trust, and expose intellectual property. The lesson is simple: basic access controls are the first line of defense. For enterprises betting on AI, neglecting them is a gamble they can’t afford.
Source: The Decoder. AI-assisted editorial synthesis — TechnoExpress.

