Blog

The AI Tipping Point Is an Identity Tipping Point

Abstract dark blue background with curved glowing lines and dotted patterns, forming smooth waves and a large central oval space, evoking a futuristic, dynamic design that subtly hints at the hidden complexity behind understanding the cost of a data breach.

Every year the IBM/Ponemon Institute’s Cost of a Data Breach Report comes out, and the industry does the same thing with it: grab the headline figure, bolt it onto a product pitch, and move on. The newly released 2026 edition, subtitled “The AI tipping point”, deserves a deeper look. The report studied 602 breached organizations across 17 industries and buried in its 30 cost factors and breach timelines is a story that I suspect many might miss. 

Three findings stood out to me. Taken together, they say something uncomfortable about where our defenses stand. 

Finding 1: Breaches got more expensive, and we got slower 

The global average cost of a breach hit $4.99 million, a 12% jump over last year and a new record. In the United States, the average breach reached $11.5 million. That is more than double the global figure! Put differently, an average breach now costs about $1,100 per hour, and the majority of that cost comes from detection, escalation, and lost business in the form of disrupted operations, crisis management, and customer churn. 

Here is the part that should bother us more than the price tag. The mean time to identify and contain a breach rose to a whopping 247 days. This reverses a five-year declining trend. After years of steady improvement with better tooling, better automation and better playbooks, the defense clock is now running backward. And time is the cost multiplier: breaches that ran longer than 200 days averaged $5.65 million, against $4.32 million for shorter ones. 

We were winning the response-time battle. This year we started losing it again. The question is why. 

Finding 2: Attackers moved to machine speed — through the same old doors 

The report’s answer is unambiguous: AI-driven attacks increased 56% over last year. More than one in four organizations that suffered a malicious breach reported it was AI-driven, and those attacks carried a premium: roughly $1 million above the average malicious breach cost. Deepfake impersonation alone accounted for 45% of AI-driven attack volume, something I discussed in one of the Radio Logic Podcasts.

But look at where these attacks enter. For the fourth consecutive year, phishing topped the initial attack vectors, and it led to the costliest breaches at $5.29 million. Social engineering, help desk impersonation, and MFA fatigue, came in at $5.23 million. Abusing valid accounts: $5.07 million. Unfortunately, none of this surprised me.  

AI did not invent new doors; it industrialized walking through the identity ones. A deepfake is credential theft with better production values.

MFA fatigue is an attack on human trust in an identity workflow. Valid account abuse is not an exploit at all; it is your own access model, used against you at a speed your review cycles were never designed for. 

The report makes the same point about breaches involving AI systems themselves: among organizations that suffered an AI-related breach, 92% lacked proper AI access controls, and the root causes were overwhelmingly structural: compromised APIs, connected applications, and cloud misconfigurations. Governance failures, not model failures. And that 92% is not a story about unlucky companies. Only 40% of organizations report using access controls on AI models and data, which means most of the market is sitting on the same gap and has not been tested on it yet. 

Finding 3: The controls that worked are the unglamorous ones 

For all the attention frontier AI threats are getting, the report’s cost-factor analysis reads like a case for identity fundamentals. Identity and access management was the second-largest cost reducer of all 30 factors studied, cutting $225,622 from the average breach. On the other side of the ledger: excessive privileges and poor role management added $177,313, and mismanaged secrets and keys added $198,933. 

Meanwhile, the identity population that is growing fastest is the one we govern worst. Fewer than half of organizations (46%) secure non-human identities in their AI workflows. Security incidents involving shadow AI more than doubled to 43%, at an average cost of $5.39 million. And while security AI and automation delivered real returns, only about a third of organizations use these tools across the full lifecycle. 

Automation amplifies whatever you feed it. Feed it fragmented, stale identity data and you get faster confusion, not faster containment. 

One story, not three 

Read together, these findings describe a single dynamic. Attackers now operate at machine speed against the identity layer. That includes the human credentials, service accounts and API keys, and increasingly the AI agents we are wiring into our own workflows. Defenders, meanwhile, are answering machine-speed questions with identity data scattered across directories, cloud platforms, IGA systems and HR sources — which is a large part of why “who has access to what, and should they?” still takes 247 days to answer under breach conditions. 

You cannot observe what you have not unified. You cannot act on what you cannot observe. That sequence — unify the identity data into one authoritative view, observe posture and drift across it, then act with confidence — is the discipline the report’s numbers keep pointing back to, whether the subject is IAM’s cost impact, unsecured NHIs, or the 92% of AI-breached organizations missing basic access controls. 

It is also, candidly, the problem we spend our days on at Radiant Logic. RadiantOne exists because this fragmentation is not solvable one silo at a time. The value of identity data, like the risk in it, only becomes visible when it is brought together. But you do not need our platform to act on this report. Start by asking whether you could produce a complete, current inventory of every identity in your environment  – human, non-human, and agentic – and every entitlement attached to it, in hours rather than quarters. If the answer is no, then that gap is what an AI-equipped adversary is counting on. 

IBM calls 2026 the AI tipping point. Read closely, it is an identity tipping point. The organizations that come out ahead will not be the ones with the most AI in their security stack; they will be the ones whose identity data is unified enough that speed – human or machine – works for them instead of against them. If the question of inventory is an uncomfortable unknown, it is the conversation we are having with identity teams right now, and we are happy to have it with yours.  

Source: IBM & Ponemon Institute, Cost of a Data Breach Report 2026.