Policy without control
The AI governance gap in IBM’s 2026 Cost of a Data Breach report. Two-thirds of the organisations in IBM’s 2026 breach study had no AI governance policy in place. Of that 68 per cent, 35 per cent reported no policy at all and 33 per cent said one remained in development. The finding comes from […] Policy without control was originally published on Emerging Europe .
A significant void exists in AI governance policies among organizations, according to IBM's 2026 Cost of a Data Breach report released on July 29. Two-thirds of the 602 organizations surveyed had no AI governance policy in place, with 35 percent having no policy at all and 33 percent still developing one. The findings, conducted by IBM in collaboration with the Ponemon Institute, cover 17 industries across 16 countries and regions, analyzing 3,558 interviews on breaches that occurred between March 2025 and February 2026.
The global average cost of a breach reached $4.99 million, a 12 percent increase from the previous year, marking the highest cost recorded in the report's 21 editions. This trend reversed last year's nine percent decline, when security teams appeared to be gaining ground. The study reveals that 68 percent of breached organizations lacked AI governance to manage AI or detect its unsanctioned use, up from 63 percent the previous year.
Of those with policies, only 32 percent had actually implemented them, a drop from 37 percent the prior year. The remaining 32 percent had policies still in development. The composition of AI governance policies has shifted from a completed one to a halfway state, where a policy exists only on a slide deck and not in practice. Of the six AI governance control types studied, five saw a decline in adoption.
Strict approval processes for AI deployments dropped to 38 percent from 45 percent, while AI governance technology usage fell to 33 percent from 39 percent, and governance frameworks to 33 percent from 39 percent. Employee training on AI risks decreased to 30 percent from 36 percent, and regular audits for unsanctioned AI declined to 29 percent from 34 percent.
Adversarial testing, or red teaming, was the only comparable control to gain ground, reaching 25 percent from 22 percent. Only 19 percent of organizations reported coordinating AI governance and security teams, a new question in this year's study. Security incidents involving AI models or applications increased to 21 percent of breached organizations, up from 13 percent, a 61 percent increase.
Among those affected, 92 percent lacked proper AI access controls, such as role-based access and multifactor authentication. Only 40 percent of all breached organizations applied access controls to AI models and data at all, ranking third in cost reduction behind supply chain breaches. Shadow AI, involving employees running unauthorized AI tools, reached 43 percent of breached organizations, up from 20 percent the previous year.
The average breach cost for shadow AI incidents was $5.39 million, compared to $4.63 million in the prior year. The report highlights that while identity and access management is the second-largest cost reducer, only 40 percent of organizations applied access controls to AI models and data, highlighting the gap between policy and implementation.
The data emphasizes the importance of robust AI governance policies and controls to mitigate the risks and costs associated with AI-related breaches.
Written by urgent.news from Emerging Europe's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.