Highlighted
5
Min Read
May 19, 2026

AI Series - Part 2: The devil's dilemma: why AI increases data breach risk and mitigates damage

 Jurgen Otten
Jurgen Otten
GRC Consultant
AI Series - Part 2: The devil's dilemma: why AI increases data breach risk and mitigates damage

AI is rapidly becoming a critical component of business operations. At the same time, recent data breach analyses show that security and governance are struggling to keep pace with this development.

In a triptych based on the IBM/Ponemon Cost of a Data Breach Report 2025 Jurgen Otten discusses:


– the risks of rapid AI adoption and shadow AI;

– the dual nature of AI as both a threat and a defense mechanism; and

– why investing in IAM, SOC, and GRC demonstrably pays off.

The insights from the 2025 edition describe trends that are continuing to develop and will most likely be quantitatively confirmed in the 2026 edition.

The 2026 edition of the IBM/Ponemon Cost of a Data Breach Report is expected sometime this summer.

The dual nature of AI as both a threat and a defense mechanism

Within cybersecurity, AI plays an uncomfortable dual role. On the one hand, uncontrolled AI adoption increases the risk of data breaches, especially when AI applications are used without formal approval frameworks. On the other hand, recent research shows that the thoughtful deployment of AI and automation is one of the most effective ways to limit the impact of data breaches. The tension between these two realities has now become a strategic dilemma for many organizations.

The IBM/Ponemon Cost of a Data Breach Report 2025 illustrates this dilemma. The average global cost of a data breach is USD 4.44 million. However, the average cost of a data breach for organizations that do not use security AI and automation amounts to USD 5.52 million. These costs largely consist of four components: detection & escalation, post-breach response, notification, and lost business. Especially the latter category — revenue loss, reputational damage, and customer churn — represents structural and difficult-to-predict damage.

In contrast to this cost picture, there is a striking finding: the cost of a data breach for organizations that extensively apply security AI and automation averages USD 3.62 million, a cost saving of USD 1.9 million per data breach compared to organizations that do not use security AI and automation.

This saving doesn't stem from one specific control measure, but from a combined effect across the entire security lifecycle: faster detection, shorter containment, and less escalation. The report shows that these organizations get their incidents under control an average of 80 days faster than organizations without such functionality.

An important detail is where this cost saving is realized. The report shows that the detection & escalation component, in particular, has significantly decreased in recent years. This trend is directly related to the deployment of AI-driven detection, correlation, and response. As this technology matures and becomes more widely available, it is expected that this cost item will further decrease. In other words: the technology is becoming cheaper, while the financial impact of rapid detection is increasing.

It's also interesting to see where organizations invest *after* a data breach. The report shows that additional budgets are primarily allocated to security AI and automation within threat detection & response, incident response planning & testing, data security, IAM, and managed security services. That list is telling. These are not ad hoc measures, but building blocks of a more integrated security and governance approach.

Beneath the surface, a second effect is at play here. Organizations that have established clear policy frameworks beforehand — such as clear responsibilities, decision-making around technology use, and embedded assessment and approval mechanisms — prove to be able to act faster when things go wrong. Not because they are more bureaucratic, but because responsibilities and courses of action are defined in advance. This directly translates into shorter detection times and lower escalation costs.

The main conclusion, therefore, is not that "AI solves the problem," but that the right time has come to invest strategically. Security AI and automation are demonstrably effective. The total costs of data breaches are high and remain so, but organizations that invest now demonstrably reduce both their risk and their financial exposure. In a landscape where AI will inevitably play a central role, not investing is likely the most expensive option.

Navaio would be happy to discuss with you where your organization stands, what risks are real, and where targeted efforts can yield the most value.

Part 1: The calm before the storm: AI adoption, shadow AI, and the underestimated data breach risk. [link]

Part 3: From risk to return: gaining control over AI and shadow AI with demonstrable ROI.[link]

Stel ons jouw vraag!
Thank you! You have been subscribed.
Oops! Something went wrong while submitting the form.
Download E-Book Unravelling UGC: A Comprehensive Exploration