Research Report — July 2026

The Cost of Untrusted AI.

An Evidence-Based Report on AI Security Incidents, Enterprise Exposure, and Control Economics, 2023–2026

CyberArmor.AIJuly 202676 pages36 incidents, 2023–2026

How to read this report

Every dollar figure in this report is a third party's published measurement — IBM/Ponemon, the FBI, statutory penalty text, or a named industry study. Never a CyberArmor estimate.

Every capability claim is tied to a file path in the product source, with the project's own maturity rating attached. Where a capability does not exist, the report says so in Part I — not in a footnote.

No email required. No form. Direct download — forward this link to anyone.

The Thesis

IBM's own cost table contains both halves of the argument.

In IBM's 2025 chart of factors that raise or lower average breach cost, adopting AI and governing AI appear as separate line items — pointing in opposite directions.

Cost amplifier

+US$193,511

“Adoption of AI tools”

Added to the average cost of a breach.

Source: IBM/Ponemon, Cost of a Data Breach Report 2025, cost-factor chart.

Second-largest mitigator

−US$223,503

“AI-driven and ML-driven insights”

Subtracted from the average cost of a breach.

Source: IBM/Ponemon, Cost of a Data Breach Report 2025, cost-factor chart.

Adopting AI raises breach cost. Governing it lowers breach cost.

The gap between those two numbers is the entire market this report addresses.

IBM's methodology caveat travels with these numbers

These figures come from a self-reported cross-sectional survey of 600 organizations breached between March 2024 and February 2025, analyzed with activity-based costing. They are correlational, not causal, and the sample is small relative to the number of factors reported. They are per-factor deviations from a baseline — they are not additive, and no organization can claim their sum. This is a caveat IBM states, and one the report repeats wherever these numbers appear.

Finding 02Complexity

The second-largest amplifier is the security stack itself.

+US$207,914“Security system complexity”

Most controls in this market enforce at one layer, and each holds its own policy. A single policy change therefore means changing several systems — which then disagree with each other. The disagreement is not a configuration accident; it is the predictable result of storing the same intent in several places.

That is the structural argument for one policy plane consumed by every surface, and the report maps it to a named file path rather than to a diagram.

Source: IBM/Ponemon, Cost of a Data Breach Report 2025, cost-factor chart. Same methodology caveat as above — correlational, per-factor, not additive.

Finding 03The realized-loss picture

Almost all the money that has moved so far moved because a person was deceived.

The report catalogs 36 AI security incidents from 2023 to 2026, each verified against primary sources. The pattern is not the one most vendors describe.

US$69.3M

Total reported enterprise losses across all 36 incidents

99.85%

Of that total sits in one class: AI-enabled social-engineering fraud, principally deepfake executive impersonation

US$104,600

Produced by every input attack, every runtime failure and every output failure in the database, between them

Source: incident database compiled in Part II of the report, 36 incidents 2023–2026, each verified against primary sources. Reported losses are a floor — a tally of what victims disclosed — not an estimate of total market loss.

CyberArmor does not address this

Deepfake and voice-authenticity detection is not implemented in CyberArmor's codebase — it is roadmap. The costliest incidents in the report therefore carry the platform's lowest applicability rating.

The report states this finding first, explicitly because it cuts against the company’s own commercial interest. The same boundary is published on /status, where synthetic-media detection is listed as roadmap with nothing implemented.

The National Picture

The same deception, counted nationally.

In April 2026 the FBI's Internet Crime Complaint Center published its first dedicated AI-fraud section. It records the same phenomenon as the finding above — a person deceived — across a national complaint population rather than a 36-incident sample.

IC3 2025 — first dedicated AI-fraud section

Nearly US$893M

Reported losses across 22,364 complaints referencing AI.

IC3 attributes them to voice clones and fabricated videos — the same class of attack that carries 99.85% of this report's realized-loss ledger, and the same class CyberArmor does not address.

Source: FBI Internet Crime Complaint Center (IC3), Internet Crime Report 2025, released April 2026; §13 of the report. Victim-reported losses — see the measurement note below.

US$20.877B

Total reported losses across 1,008,597 complaints, all crime types

Source: FBI Internet Crime Complaint Center, Internet Crime Report 2025, released April 2026.

US$3.05B

Business email compromise

Source: FBI Internet Crime Complaint Center, Internet Crime Report 2025, released April 2026.

Three numbers, three measurement classes

IC3 counts dollars that victims themselves reported to the FBI over one year — a national tally of self-reported complaint losses. IBM's figures are modelled averages and per-factor deviations drawn from a survey of 600 breached organizations. The two are different measurement classes and cannot be combined: a national victim-reported total may not be added to, netted against, or divided into a modelled per-breach average, and no arithmetic joining them produces a meaningful number. The report never performs it, and neither should a reader of this page.

Nor are US$69.3M and US$893M competing figures. US$69.3M is what 36 individually verified incidents disclosed in this report's own ledger. US$893M is what IC3 recorded nationally across 22,364 AI-referencing complaints in a single year. Same phenomenon, counted once by incident sample and once by victim report. The larger number does not correct the smaller one — it sizes the field the smaller one samples.

HK$200,000,000

Approximately US$25.6M — Arup, January 2024. The largest verified corporate loss from a staged multi-party deepfake video conference.

Source: §13 of the report. The report narrows this superlative deliberately to the video-conference pattern: a 2020 voice-clone fraud in the same incident database, entry D-2, is larger still at US$35M.

3 new technique IDs

Deepfake fraud now carries first-class coverage in both major threat frameworks, rather than being mapped by analogy.

Sources: MITRE ATLAS AML.T0088 (Generate Deepfakes) and AML.T0052.001 (Deepfake-Assisted Phishing); MITRE ATT&CK T1683.002 (Audio-Visual Content). All added between late 2025 and April 2026; §13 of the report.

The Obvious Objection

Why the case does not rest on the realized-loss ledger.

The realized-loss table is a lagging indicator, and a young one. The leading indicators are the near-misses.

  • A zero-click exfiltration flaw in Microsoft 365 Copilot, patched before exploitation.
  • Remote code execution in a developer IDE from a one-line configuration edit.
  • Roughly a hundred genuinely malicious models live on a public model hub.
  • In July 2026, an autonomous agent framework that escaped an evaluation sandbox and reached production infrastructure at Hugging Face.

Each was found by a researcher, not by the victim’s own controls.

Sources: each near-miss is documented in Part II of the report with its primary source, disclosure timeline, and taxonomy mapping.

Finding 04The rating discipline

An earlier draft produced five High ratings. External review cut it to one.

A High applicability rating requires a shipped enforcement point in the relevant execution path — not merely a control of the right category. Applied honestly, that rule produces a table that is deliberately unflattering in places.

1 of 36

Incidents earning a High applicability rating

19 of 36

Incidents rated Low

Low

The rating carried by the single costliest incident

3 of 10

OWASP LLM Top 10 categories with no incident behind them at all — stated rather than filled

External review found the standard had been applied too loosely, so every rating was re-derived against the published rubric. That restraint is the reason the rest of the document can be trusted.

Source: rating rubric and per-incident derivations are published in Part II of the report; the capability-to-code map is Appendix A.

The Exposure Picture

Everything else the report is able to cite.

Every figure below carries its source. None is a CyberArmor estimate.

US$10.22M

US average breach cost — a record

Source: IBM/Ponemon, Cost of a Data Breach 2025

US$4.44M

Global average breach cost

Source: IBM/Ponemon, Cost of a Data Breach 2025

US$5.56M

Financial industry average breach cost

Source: IBM/Ponemon, Cost of a Data Breach 2025

+US$670,000

Shadow-AI premium per breach, versus little or no shadow AI

Source: IBM/Ponemon 2025. A two-group cohort comparison — not the same measurement as IBM's +$200,321 per-factor 'Shadow AI' entry, and never to be added to it.

13% / 97%

Breached their own AI models or applications — and of those, the share lacking AI access controls

Source: IBM/Ponemon 2025. The 97% is a prevalence statistic only; IBM publishes no dollar figure for AI access controls.

63%

Have no AI governance policy, or are still writing one

Source: IBM/Ponemon, Cost of a Data Breach 2025

241 days

Mean breach lifecycle — identify plus contain; a nine-year low

Source: IBM/Ponemon, Cost of a Data Breach 2025

US$3.87M vs US$5.01M

Breaches contained in under 200 days, versus those running over 200 days

Source: IBM/Ponemon, Cost of a Data Breach 2025

Statutory maxima

Unlike breach costs, statutory penalties are not estimates — they are published maxima in legislative text.

EU AI Act, Art. 99(3) — prohibited practices

Regulation (EU) 2024/1689. General application from 2 August 2026.

€35,000,000 or 7% of total worldwide annual turnover, whichever is higher

GDPR, Art. 83(5)

Regulation (EU) 2016/679.

€20,000,000 or 4% of total worldwide annual turnover

HIPAA civil monetary penalties — annual cap

Inflation-adjusted, effective 28 January 2026. Federal Register 2026-01688.

US$2,190,294

A correction to the common narrative

In November 2025 the SEC dismissed its SolarWinds case with prejudice, and no penalty has ever been imposed for an Item 1.05 filing failure as such. A report claiming active SEC cyber-disclosure enforcement pressure would be describing 2024, not the present — so this one does not.

Source: Part I, §3.3 of the report.

A projection, not a measurement

Deloitte's Center for Financial Services projects that generative AI “could enable fraud losses to reach US$40 billion in the United States by 2027, from US$12.3 billion in 2023.” That is a modelled scenario endpoint — nobody has counted US$40 billion, and the figure describes a future that may not arrive. It is set apart here for that reason: it does not belong in a table beside measured figures, and it cannot be compared with IBM's per-breach averages or with the FBI's victim-reported totals.

Source: Deloitte Center for Financial Services, May 2024; §13 of the report.

If You Are Buying

Ask every vendor for the same two things.

“A buyer comparing vendors should ask each of them for the same thing: the list of incidents their product would not have helped with, and the code path for every incident they claim it would.”

— The Cost of Untrusted AI, §10, “How to read Part II”

That is a question this report was written to be able to survive. The list of incidents CyberArmor would not have helped with is in Part II, and it is long: 19 of 36 rated Low, including the single costliest incident in the database. The code path for every incident where applicability is claimed is in Appendix A, named file by named file.

Ask us the same question you ask everyone else. Then ask them for the two lists, and see who can produce both.

Ungated

The full report. No form in the way.

The 15-minute proof of concept is ungated and the capability status page is ungated. Gating the research would contradict the one thing that makes any of it credible.

CyberArmor.AI · July 2026 · 76 pages · 36 incidents verified against primary sources. Partners and prospects are welcome to forward this link directly — there is no wall behind it.

Get Started

Ready to Control and Prove AI Activity?
Let's Talk.

See how CyberArmor.AI maps to your AI activity, data leakage risk, agent workflows, provider usage, runtime controls, and evidence needs. The best demos start with the control problem you already have.

No spam. No hard sell. Every request is reviewed personally.