The Cyber Threat Nobody's Watching
The story everyone expects is that AI-powered cybercrime is driving breach costs into freefall. The actual 2026 data tell a stranger story.
The story everyone expects is that AI-powered cybercrime is driving breach costs into freefall. The actual 2026 data tell a stranger story: global breach costs just fell for the first time in five years, even as AI supercharges specific new fraud tactics, and security leaders’ biggest AI worry has quietly flipped from attackers to their own tools.
Every year brings a new version of the same cybersecurity headline: costs are exploding, attackers are getting smarter, and artificial intelligence is making everything worse. The 2025 and 2026 data mostly agree with that story, but not in the way most coverage suggests, and the exceptions matter more than the trend line.
What Actually Happened to Breach Costs
IBM’s 2025 Cost of a Data Breach Report found that the global average cost of a data breach fell to $4.44 million, down 9 percent from $4.88 million the year before, the first decline in five years. The reported driver was not less crime; it was faster containment. Organizations using AI-powered defenses extensively cut their breach lifecycle by 80 days and saved close to $1.9 million on average compared with those that did not, and the mean time to identify and contain a breach dropped to 241 days, the lowest in nine years (IBM, 2025).
That global figure hides a sharp regional divergence. In the United States specifically, the average cost of a data breach hit a record $10.22 million in 2025, up 9 percent year over year (IBM, 2025). AI is cutting costs on average worldwide while a country with some of the most valuable data and most attractive targets is seeing the opposite. Both facts are true at once, and neither cancels the other out.
The Common Misunderstanding
The instinctive read on “AI and cybersecurity” is that generative AI is primarily a weapon in the attacker’s hands, making phishing more convincing and attacks more scalable. That is true, but it is no longer the dominant worry inside the security profession, and the shift is recent enough to be genuinely surprising.
The World Economic Forum’s Global Cybersecurity Outlook 2026, based on a survey of security leaders worldwide, found that concern about data leaks linked to organizations’ own generative AI tools (34 percent) has overtaken concern about adversaries’ AI capabilities (29 percent) for the first time. In 2025, the ranking was reversed and far more lopsided: 47 percent worried primarily about adversarial AI capability, versus just 22 percent worried about GenAI data leaks (World Economic Forum, 2026). In one year, the center of gravity in AI risk perception moved from “what attackers might do to us” to “what our own employees might accidentally leak through a chatbot.” Ninety-four percent of respondents now call AI the single most significant driver of cybersecurity change heading into 2026 (World Economic Forum, 2026), but the reason has shifted from offense to internal governance.
Where AI Is Genuinely Making Attacks Worse
None of this means the offensive threat is overstated, it is simply more specific than “AI-powered attacks in general.” The clearest evidence is in voice and identity fraud. Pindrop recorded a rise of more than 1,300 percent in deepfake fraud attempts across contact centers in 2024, and deepfake vishing (voice phishing) attacks surged roughly 1,600 percent in the first quarter of 2025 compared with the last quarter of 2024 in the United States. Deepfake voice impersonation attempts reportedly targeted around 37 percent of large enterprises in 2025. Detection has not kept pace: independent testing puts human accuracy at identifying AI-generated audio, video, and images at only about 53.7 percent, barely better than a coin flip, and the share of cybersecurity professionals who say they feel least prepared for deepfake attacks specifically rose from 3 percent in 2024 to 21 percent in 2025. Projections for generative-AI-enabled fraud losses in the United States alone range from $12.3 billion to $40 billion between 2024 and 2027.
This is a narrower and more actionable threat than “AI attacks are rising.” It points specifically at voice and video verification as a weak point that most organizations built their identity processes around before synthetic media was convincing enough to defeat them.
The Unglamorous Risk That’s Actually Bigger
While deepfakes generate headlines, the more structurally significant threat remains less exciting: third parties. Verizon’s 2026 Data Breach Investigations Report, covering incidents from November 2024 through October 2025, found that breaches involving a third party jumped 60 percent year over year and now account for 48 percent of all confirmed breaches, nearly half. Remediation lags badly behind the risk: only 23 percent of third-party organizations had fully resolved multi-factor authentication issues on their cloud accounts, and fixing permission misconfigurations and weak vendor passwords typically takes about eight months (Verizon, 2026). This is not a forecast or a prediction anymore. It is a measured, current majority-adjacent share of the breaches that already happened.
The Response: Spending Is Following the Threat, Roughly
Security budgets are moving in response, though not always at the pace the threat data would justify. Gartner projects worldwide information security spending will reach $244.2 billion in 2026, up 13.3 percent, with security software as the fastest-growing segment amid rising adoption of AI-amplified security tools, projected to be used by more than 75 percent of enterprises by 2028, up from under 25 percent in 2025 (Gartner, as cited in Columbus, 2026). Geopolitics is now the top factor shaping cyber risk strategy for 64 percent of organizations, reflecting how state-linked threats have merged with criminal ones in most security planning (World Economic Forum, 2026).
What Remains Uncertain
Whether the 2025 global cost decline holds or was a one-year artifact of early AI-defense adoption is not yet established; IBM’s own report frames rapid AI adoption without governance as creating new vulnerabilities that could offset today’s gains. It is also unclear whether the WEF’s finding, that internal GenAI data leaks now worry security leaders more than external adversarial AI, reflects a genuine shift in relative risk or simply reflects which risk feels newer and less familiar to survey respondents. Both are reasonable readings, and the data available cannot fully adjudicate between them yet.
The Larger Pattern
The honest 2026 cybersecurity story is not “AI is making everything worse” or “defenses are winning.” It is that AI has become dual-use at a scale that makes single-number headlines misleading. The same technology cutting global containment times and saving money on average is enabling deepfake fraud that most organizations cannot reliably detect. The same organizations racing to deploy generative AI defensively are now more worried about their own tools leaking data than about attackers weaponizing AI against them. And the biggest measured driver of breaches, third-party and vendor risk, has nothing to do with generative AI at all; it is a decades-old supply-chain problem that has simply gotten worse on its own timeline. Leaders who chase the most dramatic AI headline risk missing the boring, structural vulnerability sitting in their vendor contracts, which the data says is already responsible for close to half of what goes wrong.
W3 Evidence Index™
W3 Evidence Index™ Score: 7.5/10
Confidence Level: High Confidence
Full category breakdown, assessment, and limits available below for paid subscribers.



