# IBM报告：92%遭遇AI安全事故的企业缺乏基本访问控制

- 来源：The Decoder：AI News（RSS）
- 作者：Thomas Joos
- 发布时间：2026-08-03 23:47
- AIHOT 分数：59
- AIHOT 链接：https://aihot.virxact.com/items/cmsdf2o50031protj836bjddz
- 原文链接：https://the-decoder.com/ibm-finds-92-of-companies-hit-by-ai-security-breaches-lacked-basic-access-controls

## AI 摘要

IBM《2026年数据泄露成本报告》显示，在602家受访公司中，92%遭遇AI相关事件的企业访问控制不足。约五分之一的企业因API受损、关联应用或云服务配置错误而遭入侵，开源或专有模型差异几乎不影响风险。AI相关事件平均造成533万美元损失，高于无AI事件的470万美元；攻击者使用AI时损失升至604万美元。

## 正文

In nearly every AI security incident, the affected company lacked access controls for its AI systems. That's the finding of IBM's Cost of a Data Breach Report 2026, based on research by the Ponemon Institute across 602 companies. Among firms that experienced an AI-related incident, 92 percent had inadequate access controls in place.

The problem rarely starts with the model itself: In about one in five affected companies, the entry point was a compromised API, a connected application, or a misconfigured cloud service. Whether a company runs an open-source or proprietary model made almost no difference.

IBM traces the gaps back to basic oversights that don't require sophisticated attackers to exploit. Incidents involving AI cost an average of $5.33 million, compared to $4.70 million for those without an AI component. The global average across all data breaches rose 12 percent to $4.99 million. When attackers themselves used AI, costs jumped to $6.04 million. Without AI, they came in at $5.03 million.

AI News Without the Hype – Curated by Humans

IBM
