International Edition
Latest News
Technology

Data Breach Costs Fall, But AI Governance Gap Widens in 2025

The Rising Cost of Ungoverned AI in Cybersecurity: A 2026 Perspective The global average cost of a data breach experienced a slight decline in 2025, falling to $4.44 million, a 9% decrease and the first drop in five…

Data Breach Costs Fall, But AI Governance Gap Widens in 2025

The Rising Cost of Ungoverned AI in Cybersecurity: A 2026 Perspective

The global average cost of a data breach experienced a slight decline in 2025, falling to $4.44 million, a 9% decrease and the first drop in five years, according to IBM’s 2025 Cost of a Data Breach Report. While this appears positive, the report reveals a more nuanced reality: organizations with extensive automation are seeing significantly lower breach costs – nearly $1.9 million less – than those relying on manual processes. This widening gap highlights the critical need for governance as organizations increasingly adopt artificial intelligence (AI) in their security operations.

The Automation Paradox: Efficiency vs. Risk

Security operations centers (SOCs) have rapidly embraced AI to combat analyst burnout and staffing shortages. Burnout-driven churn rates in SOC teams often exceed 25% annually, and replacing a trained analyst can take six to twelve months. Automation offers a solution, particularly in areas like alert triage, log correlation, and repetitive enrichment tasks. In 2025, industry telemetry reached 308 petabytes across more than four million identities, endpoints, and cloud assets, generating nearly 30 million investigative leads. Although, analysts only confirmed around 93,000 genuine threats, a hit rate of just 0.3%. Without automation, managing this volume would be impossible.

Despite these benefits, Gartner’s 2025 Hype Cycle for Security Operations places AI SOC agents at the “Peak of Inflated Expectations,” cautioning that claims of improvement often outpace actual results. Initial AI adoption can even increase workload due to false positives and “hallucinations.”

The core issue is that automation without governance doesn’t reduce risk. it redistributes it. Ungoverned AI introduces blind spots, and IBM’s 2025 report found that “shadow AI” – staff using unsanctioned generative AI tools to process sensitive data – added an average of $670,000 to breach costs. A staggering 97% of breached organizations that experienced an AI-related security incident lacked proper AI access controls, and 63% admitted to having no AI governance policies in place.

The Human Cost: Alert Fatigue and its Consequences

The strain on SOC teams extends beyond budgetary concerns. Studies show that analysts routinely ignore or dismiss up to 30% of incoming alerts, not due to negligence, but necessity. When alerts lack context and appear identical, analysts are forced to rely on instinct rather than evidence.

This is particularly critical in sectors like healthcare, where data breaches average $7.42 million per incident and take 279 days to contain. IBM’s 2025 report highlights that 54% of healthcare incidents between 2021 and 2023 involved ransomware, with patient data as the primary target in 30% of cases. Hospitals have reported diverted ambulances and delayed surgeries due to overwhelmed staff and detection pipelines.

In manufacturing and energy, where NIS2 enforcement began in 2025, downtime at high-throughput plants can cost millions of euros. Adversaries are increasingly targeting industrial control systems by exploiting ambiguous alerts that overwhelmed analysts often dismiss.

Breaches contained in under 200 days averaged $3.87 million in 2025, while those exceeding that timeframe averaged $5.01 million. Multi-environment incidents, spanning cloud, SaaS, and on-premises infrastructure, were even costlier, averaging $5.05 million with lifecycles approaching 276 days.

Europe’s Regulatory Convergence: A New Era of Accountability

Three regulatory frameworks are converging to demand continuous resilience: the Digital Operational Resilience Act (DORA), the NIS2 Directive, and the EU AI Act. DORA, effective across the EU in January 2025, reframes cybersecurity for financial services around operational resilience and requires incident reports within hours, backed by forensic evidence. NIS2, transposed into national law in 2024-2025, expanded the regulatory perimeter to eighteen essential and important sectors. The EU AI Act, taking effect on August 2, 2026, will require high-risk AI systems – including many security automation tools – to demonstrate compliance with risk management, data governance, and transparency requirements.

These frameworks necessitate that cybersecurity AI be auditable, explainable, and governed. Organizations must now demonstrate their security posture to regulators within hours, not just report it after an incident.

The Case for Governed Autonomy

The industry is shifting from rule-based automation to “governed autonomy,” where AI assists human judgment with built-in compliance guardrails. In this model, AI narrows the decision space by correlating data at ingestion and ranking risks, allowing analysts to focus on critical issues. Every investigation timeline serves as a compliance artifact, digitally signed and ready for regulator export.

Platforms like Nextgen Software’s CYBERQUEST are designed to unify detection, investigation, and compliance reporting, generating audit trails automatically. Agentless OT monitoring modules provide visibility into industrial control systems without intrusive endpoint agents.

The evolution from AI assistants to AI agents is underway, with systems capable of executing detection, investigation, and response workflows. However, Gartner recommends treating these agents as workflow augmentation tools, maintaining human oversight to mitigate risks associated with flawed assumptions.

What 2026 Demands: Trustworthy AI

The organizations best positioned for 2026 will be those that can prove their AI is trustworthy. Compliance must be embedded in the detection-to-resolution workflow, generated automatically as a byproduct of incident handling. Platforms that deliver audit-ready evidence as a natural output of operations will set the new standard.

The cybersecurity industry has spent the past decade automating. In 2026, the focus shifts to governing that automation and proving to regulators, insurers, and boards that the defending machines are themselves accountable. The winners will not be those with the most AI, but those whose AI can demonstrate its working.

About the author: Anika Shah - Technology

MSc in Computer Science, senior reporter. Anika focuses on AI ethics, cybersecurity, and emerging hardware—frequently moderating panels at CES and Web Summit. “Anika Shah decodes tech breakthroughs and startup disruption shaping tomorrow’s digital landscape.”