Daily Tech Briefing
AI 科技速览
每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。
The Decoder · 2026/8/3 15:47:08

IBM finds 92% of companies hit by AI security breaches lacked basic access controls
AI 中文解读
核心亮点:IBM最新报告爆出惊人数据,92%遭遇AI安全事件的企业,竟然连最基础的访问权限管理都没做。
通俗解读:IBM这次调查了全球602家公司,发现AI出事的公司里,绝大多数都栽在一个很“低级”的问题上:谁都能碰AI系统,没有设置门禁。就好比你花大价钱买了个金库,结果大门钥匙就挂在门框上。更意外的是,问题源头多半不在AI本身,而是边边角角的“后门”被钻了空子,比如老旧接口没加密、云服务配置出错。有意思的是,用开源还是付费模型,出事概率没差多少。
实际影响:对企业来说,这次事故平均要赔533万美元,比普通数据泄露贵了60多万美元。而且AI本身还可能变成“帮凶”——如果黑客也学会用AI搞攻击,损失直接飙到604万美元。对普通人来说,这意味着以后使用AI服务时要多留个心眼:你授权的那些APP和平台,后台的安全管理可能比想象中粗心。反过来看,这也给企业提了个醒,与其追着新技术跑,不如先把最基础的“门锁”换好,别让AI成了黑客的提款机。
IBM finds 92% of companies hit by AI security breaches lacked basic access controls
Thomas Joos
Aug 3, 2026
In nearly every AI security incident, the affected company lacked access controls for its AI systems. That's the finding of IBM's Cost of a Data Breach Report 2026, based on research by the Ponemon Institute across 602 companies. Among firms that experienced an AI-related incident, 92 percent had inadequate access controls in place.
The problem rarely starts with the model itself: In about one in five affected companies, the entry point was a compromised API, a connected application, or a misconfigured cloud service. Whether a company runs an open-source or proprietary model made almost no difference.
IBM traces the gaps back to basic oversights that don't require sophisticated attackers to exploit. Incidents involving AI cost an average of $5.33 million, compared to $4.70 million for those without an AI component. The global average across all data breaches rose 12 percent to $4.99 million. When attackers themselves used AI, costs jumped to $6.04 million. Without AI, they came in at $5.03 million.AdDEC_D_Incontent-1Ad
AI News Without the Hype – Curated by Humans
Subscribe to THE DECODER for ad-free reading, a weekly AI newsletter, our exclusive "AI Radar" frontier report six times a year, full archive access, and access to our comment section.
Subscribe now
Source: IBM
Ask about this article…
Search
分享
阅读原文 ↗