IBM's latest security report reveals that nearly all companies hit by AI security incidents failed to implement fundamental access controls. The vulnerabilities stemmed from poor security practices rather than flaws in the AI models themselves.
IBM's findings expose a critical gap in enterprise AI security practices. According to the analysis, 92 percent of companies that suffered an AI security breach had inadequate access controls governing their AI systems.
The data underscores a fundamental truth: companies are not failing due to sophisticated AI vulnerabilities, but rather basic security hygiene failures.
■ The Root Problem
Access controls represent one of the most elementary security measures. They determine who can access AI systems, what actions they can perform, and under what conditions. When absent or improperly configured, they create wide-open doors for unauthorized access, data theft, and system manipulation.
The fact that such basic protections were missing in 92 percent of breached organizations suggests widespread underestimation of AI-specific security requirements. Many companies appear to be treating AI systems with the same casual approach they use for non-critical infrastructure, rather than the heightened vigilance these powerful tools demand.
■ Implications
The findings carry serious implications for enterprise risk management. If nearly all AI security incidents stem from access control failures, the remediation path becomes clear: companies must prioritize implementation of proper identity and access management protocols before deploying AI systems at scale.
This is not a technical innovation problem. The solutions exist. It's an execution problem. Companies need to apply proven security frameworks—role-based access control, multi-factor authentication, audit logging, and least-privilege principles—to their AI infrastructure.
■ Moving Forward
The IBM report suggests enterprises should audit their AI systems immediately to assess access control configurations. Organizations deploying generative AI, machine learning models, or other AI technologies should treat access management as a foundational requirement, not an afterthought.
As AI systems increasingly handle sensitive data and critical business functions, the cost of these basic oversights will only grow. The message is simple: implement access controls now, or face predictable breach scenarios later.
Researchers have used large genome models to create genetically distant versions of bacteriophages—viruses that infect bacteria. The AI system successfully generated novel viral designs without human intervention.
Security researchers exploited vulnerabilities in a children's GPS smartwatch to track and eavesdrop on a WIRED reporter, exposing critical flaws in the supply chain of location-enabled devices.
Artificial intelligence models have demonstrated the ability to generate novel viral sequences, raising biosecurity concerns among researchers and policymakers. The development highlights potential dual-use risks of increasingly powerful AI systems.
The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days.