SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
AI security incidents cost large firms millions, study finds

AI security incidents cost large firms millions, study finds

Sat, 25th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

WitnessAI has released research on the financial impact of AI-related security incidents in large organisations. It found that 43% of surveyed enterprise decision-makers said such incidents had cost their organisation USD $2 million or more over the past year.

The findings point to a gap between AI adoption and the controls used to govern it. While 70% of respondents said they are already using or piloting AI agents that can take autonomous actions, only 18% said all such agents are formally inventoried and approved by their security team.

The survey covered 300 enterprise decision-makers at organisations with 1,000 employees or more. It included 200 respondents with Vice President, Senior Vice President, and Executive Vice President titles, and 100 respondents from the C-suite.

Incident costs

Most respondents said they had already dealt with problems linked to AI use. The survey found that 86% had investigated at least one AI-related security or operational incident in the past 12 months.

On the financial impact, 21% said the cost of their single most significant AI-related security incident had reached USD $1 million or more. Nearly one in five, or 17%, said the total annual cost of AI-related incidents was between USD $10 million and USD $24.9 million.

The report also examined potential regulatory exposure from AI failures. More than a third of respondents, or 36%, estimated that between 3% and 5% of annual revenue could be at risk from penalties if a rogue AI agent exposed sensitive company or customer data. Another 18% said the regulatory impact could be twice that level.

Returns questioned

While many organisations are still expanding their use of AI, the survey suggests the financial return is often unclear. Only 9% of respondents said more than three-quarters of their AI initiatives had delivered a measurable financial return.

Budget discipline also emerged as an issue. One-third of respondents said AI projects undertaken during the past year were always or mostly over budget, while 30% said unmanaged or poorly governed AI use had caused cost overruns. Another 27% said it had led to delayed or cancelled AI initiatives.

WitnessAI linked some of this difficulty to fragmented internal reporting, with vendor bills, productivity reports, and other information spread across separate business units. This can leave executives making investment decisions without a single view of whether AI spending is producing a return.

Concern about risk was widespread even among companies moving ahead with deployment. The survey found that 91% of respondents were concerned AI agents increase financial risk exposure, yet 64% still said the value of using agentic AI outweighs the risks.

Responsibility gap

The research also highlighted uncertainty over who should own AI risk inside large organisations. Thirty per cent of respondents said the Chief Information Officer or IT leader is primarily responsible for managing AI risk, while 15% pointed to the Chief Information Security Officer or information security function.

The gap widened when respondents were asked who would be liable if an AI agent caused financial or regulatory harm. Just 6% identified the Chief Information Security Officer as primarily liable, compared with 26% who named the Chief Information Officer.

Finance teams appeared to play a limited role despite the scale of the potential exposure. Fewer than half of respondents, or 46%, said their Chief Financial Officer actively models AI-specific risk and return on investment, while 38% said finance reviews AI spending but does not separately model AI-related risk exposure.

Control gaps

Other findings suggested governance processes are consuming a sizeable share of AI budgets without fully closing oversight gaps. More than half of respondents, or 54%, said they allocate between 21% and 45% of their AI budgets to risk management and governance. At the same time, 17% said governance bottlenecks are the main reason AI initiatives underperform against return expectations.

The survey also found a difference in confidence between senior executives and those closer to deployment. Among C-suite respondents, 68% said they had full confidence in their visibility into AI tools and agents. Among Vice Presidents overseeing implementation, the figure was 46%.

So-called shadow AI activity was reported most often in IT and infrastructure departments, cited by 47% of respondents. That put those departments ahead of sales, business development, and marketing as the biggest single source of unsanctioned AI use.

Monitoring of autonomous systems remained incomplete. Among organisations that had deployed AI agents, 49% said they had continuous monitoring in place, while 12% reported minimal or no oversight.

A company statement accompanied the report's publication. "The shift to agentic AI introduces a completely new tier of financial and operational liability, with single incidents now topping millions of dollars," said Rick Caccia, Chief Executive Officer and Co-founder of WitnessAI. "Establishing complete visibility into AI environments isn't just about playing defense or stopping threats; it is the direct path to unlocking AI's true ROI. When organizations can actually see into every interaction, they bridge the execution gap, eliminate costly bottlenecks, and identify exactly which tools are driving measurable business value."