IBM says inadequate access controls were present in 92% of companies that experienced an AI security incident, according to The Decoder. The finding points to a less glamorous but important problem: many AI breaches may start with ordinary governance failures rather than exotic model attacks.
Access controls decide who or what can use a system, which data it can reach, and which actions it can take. As companies connect AI tools to internal documents, software, and business workflows, weak controls can turn a helpful assistant into a path toward sensitive systems.
The statistic does not mean model safety is irrelevant. It does suggest that companies may reduce real risk faster by fixing identity, permissions, logging, and review processes before they chase more speculative defenses.
For executives, the practical message is uncomfortable but clear. Deploying AI without basic access discipline can create security exposure even when the model itself is not the primary failure point.