IBM's own cost table contains both halves of the argument.
In IBM's 2025 chart of factors that raise or lower average breach cost, adopting AI and governing AI appear as separate line items — pointing in opposite directions.
Cost amplifier
+US$193,511
“Adoption of AI tools”
Added to the average cost of a breach.
Source: IBM/Ponemon, Cost of a Data Breach Report 2025, cost-factor chart.
Second-largest mitigator
−US$223,503
“AI-driven and ML-driven insights”
Subtracted from the average cost of a breach.
Source: IBM/Ponemon, Cost of a Data Breach Report 2025, cost-factor chart.
Adopting AI raises breach cost. Governing it lowers breach cost.
The gap between those two numbers is the entire market this report addresses.
IBM's methodology caveat travels with these numbers
These figures come from a self-reported cross-sectional survey of 600 organizations breached between March 2024 and February 2025, analyzed with activity-based costing. They are correlational, not causal, and the sample is small relative to the number of factors reported. They are per-factor deviations from a baseline — they are not additive, and no organization can claim their sum. This is a caveat IBM states, and one the report repeats wherever these numbers appear.
Finding 02 — Complexity
The second-largest amplifier is the security stack itself.
Most controls in this market enforce at one layer, and each holds its own policy. A single policy change therefore means changing several systems — which then disagree with each other. The disagreement is not a configuration accident; it is the predictable result of storing the same intent in several places.
That is the structural argument for one policy plane consumed by every surface, and the report maps it to a named file path rather than to a diagram.
Source: IBM/Ponemon, Cost of a Data Breach Report 2025, cost-factor chart. Same methodology caveat as above — correlational, per-factor, not additive.
Finding 03 — The realized-loss picture
Almost all the money that has moved so far moved because a person was deceived.
The report catalogs 36 AI security incidents from 2023 to 2026, each verified against primary sources. The pattern is not the one most vendors describe.
US$69.3M
Total reported enterprise losses across all 36 incidents
99.85%
Of that total sits in one class: AI-enabled social-engineering fraud, principally deepfake executive impersonation
US$104,600
Produced by every input attack, every runtime failure and every output failure in the database, between them
Source: incident database compiled in Part II of the report, 36 incidents 2023–2026, each verified against primary sources. Reported losses are a floor — a tally of what victims disclosed — not an estimate of total market loss.
CyberArmor does not address this
Deepfake and voice-authenticity detection is not implemented in CyberArmor's codebase — it is roadmap. The costliest incidents in the report therefore carry the platform's lowest applicability rating.
The report states this finding first, explicitly because it cuts against the company’s own commercial interest. The same boundary is published on /status, where synthetic-media detection is listed as roadmap with nothing implemented.
The same deception, counted nationally.
In April 2026 the FBI's Internet Crime Complaint Center published its first dedicated AI-fraud section. It records the same phenomenon as the finding above — a person deceived — across a national complaint population rather than a 36-incident sample.
IC3 2025 — first dedicated AI-fraud section
Nearly US$893M
Reported losses across 22,364 complaints referencing AI.
IC3 attributes them to voice clones and fabricated videos — the same class of attack that carries 99.85% of this report's realized-loss ledger, and the same class CyberArmor does not address.
Source: FBI Internet Crime Complaint Center (IC3), Internet Crime Report 2025, released April 2026; §13 of the report. Victim-reported losses — see the measurement note below.
US$20.877B
Total reported losses across 1,008,597 complaints, all crime types
Source: FBI Internet Crime Complaint Center, Internet Crime Report 2025, released April 2026.
US$3.05B
Business email compromise
Source: FBI Internet Crime Complaint Center, Internet Crime Report 2025, released April 2026.
Three numbers, three measurement classes
IC3 counts dollars that victims themselves reported to the FBI over one year — a national tally of self-reported complaint losses. IBM's figures are modelled averages and per-factor deviations drawn from a survey of 600 breached organizations. The two are different measurement classes and cannot be combined: a national victim-reported total may not be added to, netted against, or divided into a modelled per-breach average, and no arithmetic joining them produces a meaningful number. The report never performs it, and neither should a reader of this page.
Nor are US$69.3M and US$893M competing figures. US$69.3M is what 36 individually verified incidents disclosed in this report's own ledger. US$893M is what IC3 recorded nationally across 22,364 AI-referencing complaints in a single year. Same phenomenon, counted once by incident sample and once by victim report. The larger number does not correct the smaller one — it sizes the field the smaller one samples.
HK$200,000,000
Approximately US$25.6M — Arup, January 2024. The largest verified corporate loss from a staged multi-party deepfake video conference.
Source: §13 of the report. The report narrows this superlative deliberately to the video-conference pattern: a 2020 voice-clone fraud in the same incident database, entry D-2, is larger still at US$35M.
3 new technique IDs
Deepfake fraud now carries first-class coverage in both major threat frameworks, rather than being mapped by analogy.
Sources: MITRE ATLAS AML.T0088 (Generate Deepfakes) and AML.T0052.001 (Deepfake-Assisted Phishing); MITRE ATT&CK T1683.002 (Audio-Visual Content). All added between late 2025 and April 2026; §13 of the report.
Why the case does not rest on the realized-loss ledger.
The realized-loss table is a lagging indicator, and a young one. The leading indicators are the near-misses.
- A zero-click exfiltration flaw in Microsoft 365 Copilot, patched before exploitation.
- Remote code execution in a developer IDE from a one-line configuration edit.
- Roughly a hundred genuinely malicious models live on a public model hub.
- In July 2026, an autonomous agent framework that escaped an evaluation sandbox and reached production infrastructure at Hugging Face.
Each was found by a researcher, not by the victim’s own controls.
Sources: each near-miss is documented in Part II of the report with its primary source, disclosure timeline, and taxonomy mapping.
Finding 04 — The rating discipline
An earlier draft produced five High ratings. External review cut it to one.
A High applicability rating requires a shipped enforcement point in the relevant execution path — not merely a control of the right category. Applied honestly, that rule produces a table that is deliberately unflattering in places.
1 of 36
Incidents earning a High applicability rating
19 of 36
Incidents rated Low
Low
The rating carried by the single costliest incident
3 of 10
OWASP LLM Top 10 categories with no incident behind them at all — stated rather than filled
External review found the standard had been applied too loosely, so every rating was re-derived against the published rubric. That restraint is the reason the rest of the document can be trusted.
Source: rating rubric and per-incident derivations are published in Part II of the report; the capability-to-code map is Appendix A.
Everything else the report is able to cite.
Every figure below carries its source. None is a CyberArmor estimate.
US$10.22M
US average breach cost — a record
Source: IBM/Ponemon, Cost of a Data Breach 2025
US$4.44M
Global average breach cost
Source: IBM/Ponemon, Cost of a Data Breach 2025
US$5.56M
Financial industry average breach cost
Source: IBM/Ponemon, Cost of a Data Breach 2025
+US$670,000
Shadow-AI premium per breach, versus little or no shadow AI
Source: IBM/Ponemon 2025. A two-group cohort comparison — not the same measurement as IBM's +$200,321 per-factor 'Shadow AI' entry, and never to be added to it.
13% / 97%
Breached their own AI models or applications — and of those, the share lacking AI access controls
Source: IBM/Ponemon 2025. The 97% is a prevalence statistic only; IBM publishes no dollar figure for AI access controls.
63%
Have no AI governance policy, or are still writing one
Source: IBM/Ponemon, Cost of a Data Breach 2025
241 days
Mean breach lifecycle — identify plus contain; a nine-year low
Source: IBM/Ponemon, Cost of a Data Breach 2025
US$3.87M vs US$5.01M
Breaches contained in under 200 days, versus those running over 200 days
Source: IBM/Ponemon, Cost of a Data Breach 2025
Statutory maxima
Unlike breach costs, statutory penalties are not estimates — they are published maxima in legislative text.
EU AI Act, Art. 99(3) — prohibited practices
Regulation (EU) 2024/1689. General application from 2 August 2026.
€35,000,000 or 7% of total worldwide annual turnover, whichever is higher
GDPR, Art. 83(5)
Regulation (EU) 2016/679.
€20,000,000 or 4% of total worldwide annual turnover
HIPAA civil monetary penalties — annual cap
Inflation-adjusted, effective 28 January 2026. Federal Register 2026-01688.
US$2,190,294
A correction to the common narrative
In November 2025 the SEC dismissed its SolarWinds case with prejudice, and no penalty has ever been imposed for an Item 1.05 filing failure as such. A report claiming active SEC cyber-disclosure enforcement pressure would be describing 2024, not the present — so this one does not.
Source: Part I, §3.3 of the report.
A projection, not a measurement
Deloitte's Center for Financial Services projects that generative AI “could enable fraud losses to reach US$40 billion in the United States by 2027, from US$12.3 billion in 2023.” That is a modelled scenario endpoint — nobody has counted US$40 billion, and the figure describes a future that may not arrive. It is set apart here for that reason: it does not belong in a table beside measured figures, and it cannot be compared with IBM's per-breach averages or with the FBI's victim-reported totals.
Source: Deloitte Center for Financial Services, May 2024; §13 of the report.
Ask every vendor for the same two things.
“A buyer comparing vendors should ask each of them for the same thing: the list of incidents their product would not have helped with, and the code path for every incident they claim it would.”
— The Cost of Untrusted AI, §10, “How to read Part II”
That is a question this report was written to be able to survive. The list of incidents CyberArmor would not have helped with is in Part II, and it is long: 19 of 36 rated Low, including the single costliest incident in the database. The code path for every incident where applicability is claimed is in Appendix A, named file by named file.
Ask us the same question you ask everyone else. Then ask them for the two lists, and see who can produce both.