Two months ago I quoted an IBM report: an average data breach costs a company 4.4 million dollars. In late July IBM released its new Cost of a Data Breach 2026 report — and the numbers got worse across the board. An average breach now costs 4.99 million. One in four malicious breaches was AI-enabled — 56 percent more than a year earlier — and those attacks cost the victim 6 million dollars on average. The study covers 602 organizations worldwide, March 2025 through February 2026.
But the most telling number is a different one. More than 20 percent of organizations reported a breach that targeted AI models and AI applications themselves. And the leading causes are mundane: compromised APIs, applications and plug-ins — 27 percent of cases, and cloud misconfigurations affecting AI workloads — another 27. Companies are moving data into cloud AI services at scale — and getting a new class of holes that attackers have already learned to monetize. Meanwhile, only 37 percent of breached organizations fully encrypt sensitive data both at rest and in transit.
The resulting economics are unpleasant: AI made attacks faster and cheaper, and the consequences more expensive. And taking anyone’s word for it is still not an option.. )
Now the practical question that executives of banks, state corporations and large enterprises ask me at almost every meeting: what do we do about AI if our documents are contracts, personal data, trade secrets — and sometimes restricted information? For a Silicon Valley startup the question of where to send data barely exists — to the cloud. For regulated business the same question can stop a project cold: Security, Legal and Compliance ask where the documents go, who has access, what happens to personal data, and whether any of this is acceptable in a legally significant process. After IBM’s fresh numbers, those questions sound less like over-caution and more like common sense.
In plain terms, the answer is called a closed loop. It is not a slogan but a verifiable set of requirements: data stays inside the perimeter; access is role-based; every action is traceable; documents move along approved routes; legally significant steps are never lost; and the knowledge base the agent answers from is controlled. If AI is not embedded in a governed process, the company gets a new risk instead of automation.
We build d8n.ai exactly this way, because for 19 years we have worked with the most sensitive thing an organization owns — its documents. For us the closed loop means concrete things: processing on infrastructure in Kazakhstan, client data never leaving the country, national legal and digital-signature requirements respected where they apply, and platform security confirmed not by our words but by independent certification under ISO/IEC 15408 at Evaluation Assurance Level 4. We have a separate piece on what enterprise AI governance has to prove.
The conclusion I have reached over more than two years of deep work with AI is simple. The question is not “AI or security” — that is a false fork. The question is: which AI is compatible with your responsibility? A regulated business cannot move its documents into a public cloud — but it can get the same AI on its own side of the fence, inside the loop, with all the routes, roles and audit trails. The technology has allowed this for a while now. What remains is to stop choosing between speed and control — the fresh six-million-dollar price tag per breach is a reminder of how that choice ends.