IBM’s 2026 Cost of a Data Breach Report reveals India’s average breach cost hit INR 25.5 crore (up 15.9% YoY), with organizations having 39,500 records compromised on average. Breaches are now major financial and operational events, not just technical incidents. While organizations are slowly but steadily leveraging AI to counter security threats, just implementing an AI solution is not enough.
Where Does the Gap Lie?
Shashank Bajpai, CISO & CTSO at Yotta Data Services, says most large enterprises already have the full security stack, such as firewalls, EDR, SIEM, IAM, vulnerability management, SOCs, and AI-enabled controls; but the real gap is measuring cybersecurity by controls deployed, not by controls that hold up under attack.

“A control on an architecture diagram isn’t resilience,” he says. “The operational question is: when an attacker is inside, does that control actually prevent, detect, contain, and recover?”His prescription is simple: move from asking, “Do we have the right controls?” to “Can we prove they work?”
This is where offensive AI comes in. IBM estimates that offensive security can reduce breach costs for Indian organizations by INR 2.47 crore. Offensive AI helps security teams simulate attacks, test defences, and expose weaknesses before attackers exploit them. AI and automation can then help detect, alert, and contain threats faster.
This matters especially for AI security. An AI policy, an approved model, and a data loss prevention system are not enough on their own. Organizations must be able to identify risky data flows, flag unauthorized transfers, alert the right teams, and contain damage when controls fail.
For AI systems, testing must go beyond infrastructure. It should cover prompt injection, insecure plugins, excessive permissions, data leakage, and unauthorized AI use. The aim is continuous validation of the connections, data, and access points around every AI system.
Managing Shadow IT
AI can also be a double-edged sword. While it can help counter cybersecurity threats, it can also be the source of such threats.
“Shadow AI is not just an employee-awareness problem. It is often a security-by-design problem,” says Bajpai.
Sometimes, organizations unintentionally develop a parallel AI ecosystem outside formal oversight. Employees looking for alternate options when access to various technology tools becomes difficult results in shadow AI.
According to the IBM report, Shadow AI, as a factor, is associated with higher breach costs, with its presence adding approximately INR 1.79 crore to the average cost of a breach in India.
To counter this phenomenon, Bajpai says, “Give employees a secure AI path that is easier than the insecure one.”
This approach would require organizations to provide approved AI tools supported by data classification, identity controls, data-loss prevention, usage monitoring, and clear policies. Sensitive information should be prevented through technical controls from reaching unauthorized models, rather than being protected only by written instructions.
This means providing approved AI tools backed by data classification, identity controls, data-loss prevention, and usage monitoring, with clear policies. Sensitive information should be blocked from reaching unauthorized models through technical controls, not just written rules. The Cloud Security Alliance’s 2026 research on shadow AI supports this, finding that 89% of enterprise AI usage is invisible to security teams and that unauthorized AI use drops by 89% when organizations provision sanctioned tools.
Governance Must Match Risk
Against the backdrop of AI and cybersecurity, Meheriar Patel, CDTO at Continental Carriers, approaches the issue from a governance perspective. He argues that organizations should not frame innovation and governance as competing priorities.

“The key principle is that innovation and governance should not be treated as opposing forces.” He identifies two common mistakes: Some organizations move too slowly because they fear the risks associated with AI, while others move quickly without establishing adequate safeguards.
“Neither approach is sustainable, particularly when AI applications begin handling sensitive data or influencing important business decisions,” he says.
The IBM findings strengthen his argument that security and governance need to evolve together. The report indicates that organizations combining AI adoption with strong governance is better positioned to respond to cyberattacks. It also shows that organizations with more extensive AI and security automation generally experienced lower breach costs and faster breach identification than organizations with little or no such automation.
Conclusion
AI is arming cyber thefts by improving the speed, scale, and sophistication of their campaigns; strict policies alone cannot stop cyberattacks. It is important to connect employees and technology with clearer guidance, tested processes, and practical controls.
The organizations that will thrive are those that can demonstrate, with evidence, that their controls work when the environment becomes hostile, and that their use of AI is both trusted and trustworthy.
