AI adoption in business is outpacing security and it’s costing companies dearly. IBM’s newly released 2025 Cost of a Data Breach report reveals that data breaches involving unmonitored or “shadow” AI are significantly more expensive, especially in sectors like healthcare, where personal information is a high-value target.
📉 By the numbers
- $4.63M — average cost of a data breach involving shadow AI
- $670,000 — added cost for breaches in organizations with high shadow AI usage
- 97% — of AI-related breaches lacked proper access controls
- 63% — of breached companies had no AI governance policy
- 13% — of all breaches involved an AI model or application
- 16% — of all breaches involved attackers using AI (e.g., phishing, deepfakes)
- $10.22M — average breach cost in the U.S., highest globally
- $7.42M — average breach cost in the healthcare industry
Why it matters: Healthcare remains the most expensive industry for breaches, even after a year-over-year drop from $9.77M to $7.42M. With AI increasingly integrated into patient engagement and billing systems, unmonitored tools introduce new vulnerabilities. Collection agencies and RCM firms working with healthcare data face heightened risks if AI tools are being used without governance.
Compromised healthcare data, such as customer PII (65%), was the most frequent and most expensive outcome of shadow AI breaches. This is the same data often accessed by revenue cycle firms and debt collectors managing medical debts, making strong governance an urgent priority.
⚠️ Shadow AI and supply chains: a dangerous combo: The most common source of AI-related breaches? Compromised supply chain tools, like third-party apps, APIs, or plug-ins. These backdoors often go unnoticed, particularly in operations using off-the-shelf AI or SaaS platforms without IT oversight.
🔍 Recommendations: IBM recommends organizations:
- Establish and enforce AI governance policies
- Monitor for unsanctioned AI deployments
- Conduct adversarial testing on AI models
- Fortify access controls on all AI platforms
Failing to do so could expose sensitive consumer data and result in operational downtime, financial loss, reputational damage, and regulatory fines — especially in regulated environments like healthcare and financial services.
.




