AI news story
IBM finds 92% of companies hit by AI security breaches lacked basic access controls
According to IBM, 92 percent of companies that experienced an AI security incident had inadequate access controls for their AI systems. The model itself was rarely the problem. The article IBM finds 92% of companies hit by AI security breaches lacked
Editor's take
A significant majority of organizations experiencing AI-related security incidents failed to implement fundamental access control measures for their AI systems, according to IBM's recent findings. The issue consistently stemmed from poor management of who or what could interact with AI models, rather than vulnerabilities within the AI models themselves, such as those from OpenAI or Google.
This revelation underscores a critical operational gap in enterprise AI adoption. It suggests that the rush to deploy AI, from generative chatbots to predictive analytics, has outpaced essential cybersecurity hygiene. Businesses are therefore exposing themselves to data exfiltration, manipulation, and unauthorized access, impacting not only their own sensitive information but potentially customer data and intellectual property.
Future developments will hinge on how quickly organizations can rectify these basic security flaws. The focus needs to shift from solely evaluating model performance to rigorously auditing access protocols and identity management for AI deployments. A widespread failure to address these foundational issues could lead to significant reputational damage and regulatory scrutiny for companies that have rushed AI integration without adequate safeguards.
Signal score: 5
This event was corroborated by 3 independent sources. The signal score weighs cross-source corroboration, recency, source weight and topic salience. How we rank stories.
Original reporting
This story summarises reporting published by The Decoder. Read the original article at The Decoder.