After learning about the cyber capabilities of frontier artificial intelligence models, a higher percentage of organizations plan to increase their security spending, IBM said in a July 29 press release.
The share of organizations planning to increase security spending rose to 85% in May, up from 64% in the year from March 2025 to February 2026, according to the release.
IBM attributed the increase to organizations “becoming aware of advanced frontier AI cyber capabilities.”
About 75% of organizations said frontier AI threats have prompted them to rethink how they deploy AI agents across their security operations. More than half of organizations use agents for threat detection and containment, but only 18% apply agents to vulnerability management, according to the release.
“When organizations have an extended gap between discovery and remediation, that imbalance shows up directly in breach costs,” Suja Viswesan, vice president, IBM Security Software, said in the release. “The priority now is to eliminate that lag—building remediation into development workflows, securing identity at runtime and fixing risks at the speed attackers are already moving.”
Research conducted between March 2025 and February 2026 found that AI-enabled attacks accounted for about 25% of the malicious breaches reported during that period, IBM said in the release.
The share of breaches that were enabled by AI increased by 56% over the previous year, according to the release.
AI-enabled breaches cost the victims an average of $6 million, a figure that is about $1 million higher than the $4.99 million average. For financial services organizations, the average cost was $6.3 million, the release said.
Most of the AI-enabled attacks involved either deepfake impersonation or AI-enabled malware, per the release.
“What’s changing is the economics of cyberattacks,” Viswesan said in the release. “AI is making attacks faster and cheaper, while breaches keep getting more expensive.”
When OpenAI announced July 21 that its models had caused a security incident during tests of their cyber capabilities, the company said it considered this to be “an unprecedented cyber incident.”
It was reported Aug. 5 that in separate incidents, Meta and Anthropic models hacked other companies during cybersecurity testing.
The FBI’s Internet Crime Complaint Center said in April that it received 22,364 internet crime complaints that contained reference to AI in 2025.
For all PYMNTS AI coverage, subscribe to the daily AI Newsletter.