Recent research by IBM reveals a troubling trend: over 22% of UK firms experienced an AI-related security breach within the last year. This data stems from IBM’s 2026 Cost of a Data Breach report, which highlights that AI-driven cyber attacks surged by 56% in the same period, raising urgent calls for companies to fortify their defenses against such threats.

IBMs findings illustrate a significant shift in the economics of cyber risk, with the financial repercussions of AI-related breaches now averaging around $6 million. As cybercriminals become increasingly sophisticated, they are not only targeting AI systems directly but also employing AI technologies to enhance the scale and impact of their attacks. Approximately 20% of organizations reported breaches where AI models or applications were the prime target.

Furthermore, the report identified that the vulnerabilities within surrounding systems are particularly prevalent, as evidenced by 27% of breaches linked to compromised APIs or plug-ins, in addition to cloud misconfigurations, which also accounted for 27%. This highlights a growing need for organizations to maintain awareness of potential weaknesses in their cybersecurity frameworks.

In a notable twist, IBM’s report also found that AI is being weaponized by threat actors to streamline malicious operations. The prevalence of deepfake impersonation attacks has risen sharply, being reported as the most common AI-enabled threat by 45% of survey participants. Other notable AI-enabled attacks, including malware and phishing attempts, have also increased in frequency and complexity.

Mark Hughes, the global managing partner for IBM’s Cybersecurity Services, emphasizes the dual threats presented by AI: it creates new vulnerabilities for enterprises while also being exploited by hackers. He stated, “AI has dramatically lowered the barrier for cybercriminals. Attackers can now execute attacks in minutes rather than days with advanced frontier models.