← cyberarmor.ai/research · Report PDF · Second edition, revised August 4, 2026
Source Table — The Cost of Untrusted AI, August 2026 edition
Every load-bearing claim in the report, its source, URL, and verification status. Two statuses are used honestly and deliberately:
- Re-verified 2026-07-29 — fetched and read from the cited URL during this revision.
- Carried (verified 2026-07) — verified against the cited primary source during the July 2026 edition's verification pass; URL carried forward unchanged. Not re-fetched this revision.
Anything that could not be placed in either category was cut from the report, or is listed in could-not-verify.md.
A. Measurements
| # | Claim in report | Source | URL | Status |
|---|---|---|---|---|
| A1 | Global average breach cost US$4.99M (2026); rose from US$4.44M (2025) | IBM press release for Cost of a Data Breach 2026, July 29, 2026 (Ponemon-conducted, 602 orgs, Mar 2025–Feb 2026) | https://www.prnewswire.com/news-releases/ibm-study-one-in-four-malicious-breaches-are-ai-enabled-costing-companies-6-million-on-average-302837049.html | Re-verified 2026-07-29 |
| A2 | 1 in 4 malicious breaches AI-enabled; +56% YoY; most common: deepfake impersonation and AI-enabled malware | Same | Same | Re-verified 2026-07-29 |
| A3 | AI-enabled breaches average ≈US$6M (~US$1M above average) | Same | Same | Re-verified 2026-07-29 |
| A4 | Security AI/automation users cut breach costs ≈US$2M on average; 1 in 4 orgs have not adopted | Same | Same | Re-verified 2026-07-29 |
| A5 | >20% of orgs report breaches targeting AI models/apps; top causes compromised APIs/apps/plug-ins (27%) and cloud misconfigurations affecting AI workloads (27%) | Same | Same | Re-verified 2026-07-29 |
| A6 | 62% of AI-driven attacks target critical infrastructure; financial services US$6.3M; energy US$5.2M | Same | Same | Re-verified 2026-07-29 |
| A7 | 2025-edition figures used with explicit "2025 edition" label: US$4.44M global (first decline in 5 yrs); shadow-AI premium +US$670K; 63% no AI governance policy; 97% of AI-breached orgs lacked AI access controls; 13% breached own AI models/apps (2025) | IBM Cost of a Data Breach 2025 (July 30, 2025); IBM's own AI-findings summary page | https://www.ibm.com/reports/data-breach · https://www.ibm.com/think/insights/data-matters/cost-of-a-data-breach | Re-verified 2026-07-29 (think page fetched; figures stated there) |
| A8 | IC3 2025: US$20.877B total losses; 1,008,597 complaints; BEC US$3,046,598,558 | FBI IC3, Internet Crime Report 2025 (released April 2026) | https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf | Re-verified 2026-07-29 (PDF fetched) |
| A9 | IC3 AI section: 22,364 complaints referencing AI; US$893,346,472 losses; voice-clone "distress scams" >US$5M; section titled "Artificial Intelligence (AI) Used in Cybercrime" | Same | Same | Re-verified 2026-07-29 |
| A9a | AI-section loss breakdown: investment fraud US$632,041,188 (dominant; AI-generated video/voices of celebrities, CEOs and trusted figures); AI-enabled BEC US$30,256,592; tech/customer-support scams US$19,457,078; confidence/romance US$19,041,653 | Same (AI section, by-crime-type figures) | Same | Re-verified 2026-07-29 (second targeted fetch of the section) |
| A10 | Deloitte projection: GenAI "could enable fraud losses to reach US$40B in the US by 2027, from US$12.3B in 2023" — labelled projection | Deloitte Center for Financial Services, May 2024 | https://www2.deloitte.com/us/en/insights/industry/financial-services/financial-services-industry-predictions/2024/deepfake-banking-fraud-risk-on-the-rise.html | Carried (verified 2026-07) |
B. Regulation and statute
| # | Claim in report | Source | URL | Status |
|---|---|---|---|---|
| B1 | EU AI Act penalties: Art. 99(3) €35M/7%; 99(4) €15M/3%; 99(5) €7.5M/1%; 99(6) SME lower-of | Regulation (EU) 2024/1689, Art. 99 | https://eur-lex.europa.eu/eli/reg/2024/1689/oj (text mirror re-read at https://artificialintelligenceact.eu/article/99/) | Re-verified 2026-07-29 |
| B2 | Art. 50 transparency duties (AI-interaction disclosure; machine-readable marking of synthetic content; deployer deepfake disclosure) apply from Aug 2, 2026; prohibitions since Feb 2, 2025; GPAI obligations since Aug 2, 2025; enforcement begins Aug 2, 2026 | Regulation (EU) 2024/1689 Arts. 50/113; European Commission AI Act Service Desk implementation timeline | https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline/timeline-implementation-eu-ai-act | Re-verified 2026-07-29 |
| B3 | Digital Omnibus on AI = Regulation (EU) 2026/1744; OJ publication July 24, 2026; entry into force July 27, 2026 | EUR-Lex record (document dated 2026-07-08; in-force date 2026-07-27 in EUR-Lex metadata) | https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng | Re-verified 2026-07-29 (metadata; see caveat C-2 in could-not-verify.md) |
| B4 | Omnibus deferrals: Annex III stand-alone high-risk → Dec 2, 2027; Art. 6(1)/Annex I embedded → Aug 2, 2028; new Art. 5 prohibition (NCII/CSAM) applying Dec 2, 2026; synthetic-content marking transition to Dec 2, 2026 for systems on market before Aug 2, 2026 | Gibson Dunn client alert; Hunton Andrews Kurth analysis (two independent firms), consistent with EUR-Lex metadata | https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ · https://www.hunton.com/privacy-and-cybersecurity-law-blog/eu-digital-omnibus-on-ai-enters-into-force | Re-verified 2026-07-29 (secondary-corroborated; see caveat C-2) |
| B5 | GDPR Art. 83(5) €20M/4%; 83(4) €10M/2% | Regulation (EU) 2016/679 | https://eur-lex.europa.eu/eli/reg/2016/679/oj | Carried (verified 2026-07) |
| B6 | SEC FY2026 exam priorities: accuracy of AI representations; P&Ps to monitor/supervise AI use (fraud prevention, AML, back-office, trading); AI + polymorphic-malware risk controls and training | SEC Division of Examinations, FY2026 Examination Priorities | https://www.sec.gov/files/2026-exam-priorities.pdf | Re-verified 2026-07-29 (PDF fetched — resolves the 403 flag in decision record 0001) |
| B7 | FINRA 2026: GenAI in supervisory systems — "integrity, reliability and accuracy of the AI model" under Rule 3110; RN 24-09; third-party GenAI diligence incl. contract language against sensitive-data ingestion; deepfakes from social-media images circumventing security checks; added verification on anomalies, likeness checks, MFA | FINRA 2026 Annual Regulatory Oversight Report (Dec 2025) | https://www.finra.org/sites/default/files/2025-12/2026-annual-regulatory-oversight-report.pdf | Re-verified 2026-07-29 (PDF fetched; quotes verbatim) |
| B8 | NYDFS Part 500 final phase-in Nov 1, 2025 | NYDFS cybersecurity resource center | https://www.dfs.ny.gov/industry_guidance/cybersecurity | Re-verified 2026-07-29 |
| B9 | NYDFS Oct 16, 2024 AI letter: deepfakes to authorize fraudulent transfers and defeat biometric verification; AI in risk assessments; deepfake-resistant MFA factors (avoid SMS/voice/video); training on "procedures for what to do when personnel receive unusual requests such as … an urgent money transfer," verification protocols, human review | NYDFS Industry Letter, Oct 16, 2024 | https://www.dfs.ny.gov/industry-guidance/industry-letters/il20241016-cyber-risks-ai-and-strategies-combat-related-risks | Re-verified 2026-07-29 (letter fetched; quotes verbatim) |
| B10 | NYDFS May 21, 2026 frontier-AI letter: accelerated vulnerability remediation; dependency maps with critical third parties; restrict/validate inputs before scripts or processes run; human oversight of AI-generated code; monitoring and updated risk assessments | NYDFS Industry Letter, May 21, 2026 | https://www.dfs.ny.gov/industry-guidance/industry-letters/20260521-heightened-cybersecurity-risks-assoc-with-frontier-ai-models | Re-verified 2026-07-29 (letter fetched) |
| B11 | FinCEN deepfake alert: GenAI-altered identity documents; GenAI social engineering in BEC/spear-phishing/elder exploitation; mitigations MFA incl. phishing-resistant + live identity-verification checks; enumerated red flags (third-party webcam plugin, changing communication methods, declining MFA) | FinCEN Alert FIN-2024-Alert004, Nov 13, 2024 | https://www.fincen.gov/sites/default/files/shared/FinCEN-Alert-DeepFakes-Alert508FINAL.pdf | Re-verified 2026-07-29 (PDF fetched) |
| B12 | HIPAA CMPs effective Jan 28, 2026: US$145–$73,011 per violation by tier; annual cap US$2,190,294 per provision | Federal Register doc. 2026-01688 (HHS annual civil-penalty inflation adjustment) | https://www.federalregister.gov/d/2026-01688 | Carried (verified 2026-07); corroborated 2026-07-29 via trade coverage of the same FR doc — see caveat C-3 |
| B13 | Texas TRAIGA (HB 149): effective Jan 1, 2026; exclusive AG enforcement; penalties US$10–12K curable / US$80–200K uncurable / US$2–40K per day continuing; prohibited practices incl. non-consensual deepfakes; no private right of action | Texas Attorney General, Consumer AI Rights page | https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-ai-rights | Re-verified 2026-07-29 (page fetched) |
C. Frameworks
| # | Claim in report | Source | URL | Status |
|---|---|---|---|---|
| C1 | OWASP LLM Top 10 2025 IDs (LLM01–LLM10 as used); OWASP Agentic Top 10 2026 IDs (ASI01–ASI10 as used) | OWASP GenAI Security Project | https://genai.owasp.org/llm-top-10/ · https://genai.owasp.org/ | Carried (verified 2026-07 against the official lists) |
| C2 | MITRE ATLAS IDs: AML.T0010.002/.003/.005; AML.T0011; AML.T0016.002; AML.T0018.002; AML.T0024; AML.T0025; AML.T0048.000; AML.T0051.000/.001; AML.T0052.001; AML.T0073; AML.T0088 | MITRE ATLAS data release 2026.06 | https://github.com/mitre-atlas/atlas-data | Carried (verified 2026-07 against the published dataset; atlas.mitre.org renders client-side) |
| C3 | MITRE ATT&CK v19 IDs: T1683.002; T1684.001; T1566 / T1566.004; T1588.007; T1656 revoked in v19 (superseded by T1684.001) | MITRE ATT&CK Enterprise v19.1 STIX distribution and release notes | https://github.com/mitre-attack/attack-stix-data · https://attack.mitre.org | Carried (verified 2026-07) |
D. Incident record (36 entries)
Primary sources as carried in the incident entries; all verified in the July 2026 edition's pass unless marked re-verified.
F. Product capability statements (About page)
| # | Claim in report | Source | URL | Status |
|---|---|---|---|---|
| F1 | Every product capability named in the About page — including behavioural ransomware/mass-deletion detection, host-isolation and process-termination response actions, response-side policy evaluation on model outputs, and the 58 policy templates across 17 frameworks validated against the live policy engine | CyberArmor.AI public capability status page, as re-verified against the live platform 2026-08-02 | https://cyberarmor.ai/status | Verified 2026-08-04 against the updated status page in the repository (every claim maps to a Production, Pilot-ready or Configurable row; no Roadmap row is claimed) |
E. Derived figures (arithmetic on the record — no external source)
| # | Figure | Derivation |
|---|---|---|
| E1 | US$69,308,411.64 enterprise-loss aggregate; 99.85% in Surface 4; US$104,600 all other surfaces | Sum of D-1 (US$25.6M source conversion) + D-2 (US$35M) + D-3 (US$511,968) + D-5 (US$8,091,843.64) = US$69,203,811.64; plus C-2 orders (US$57,600) + B-1 (≈US$47,000). CA$812.02 excluded per currency rule; D-6/D-7 held out (victim class); C-1 held out (IP). Reconstruction stated in Part 7 of the report. |
| E2 | "12 percent rise" (US$4.44M → US$4.99M) | Arithmetic on A1/A7 primary figures; also stated as 12% in contemporaneous coverage of the 2026 report. |
© 2026 CyberArmor.AI — AI Security, Governance and Trust Infrastructure. This table may be shared freely in unmodified form.