Agents, Token Bills and AI-Enabled Breaches: What the 2026 Reports Say
Two of the reference surveys on enterprise AI came out this summer: McKinsey’s The state of AI in 2026 in August, and IBM’s Cost of a Data Breach Report 2026 at the end of July. Read together, they describe AI moving from pilots into production, with the bill and the attack surface arriving at the same time. Three signals stand out.
1. Agents are scaling, mostly in large enterprises
- 40 percent of McKinsey’s respondents from large organisations (annual revenues above $1 billion) report scaling AI agents, up from 27 percent a year earlier. Among smaller organisations the share stayed flat at 22 percent.
- About two in ten respondents report scaling software coding agents, 31 percent at larger enterprises.
- 32 percent report that their organisation decided against buying at least one software product or feature because it could be built in-house with agentic coding tools.
An agent acts with whatever access it is given: mailboxes, CRM records, code repositories, payment systems. Scaling agents therefore scales credentials, and an agent that reads a document or a web page can be steered by instructions hidden in it. The questions that matter are which agents exist, what each can touch, and which actions need a person’s approval. Code written by coding agents needs the same review as any other code, plus checks for leaked secrets and packages nobody chose.
2. The AI bill now constrains one organisation in five
- About 20 percent of respondents report that AI-related operating costs, including token costs, constrained their organisation’s AI use. Most still plan to increase AI investment.
- 37 percent attribute at least some EBIT impact to AI, about the same share as a year earlier, and the high performers (5 percent or more of EBIT from AI, with significant value reported) remain about 6 percent of respondents.
“Even as per-token costs have declined, the number of tokens consumed and generated has increased even faster.”Michael Chui, McKinsey senior fellow, in the report
Falling prices per token do not mean falling bills. Agent loops, long contexts and reasoning models multiply the tokens behind each task, and spend is often spread across individual API keys and seat licences that nobody checks against use. The report notes that the organisations moving fastest treat operating costs as a design constraint, not an afterthought. In practice that means metering spend per team and per use case, routing routine work to smaller models, and measuring cost per completed task against the value it produces. Our whitepaper The Token Paradox sets out the five places where AI spend leaks and the controls that close them.
3. AI is now on both sides of a breach
- One in four malicious breaches in IBM’s study was AI-enabled, a 56 percent increase over the previous year. These breaches cost an average of $6 million, against a global average of $4.99 million for all breaches.
- The AI-enabled attacks were mostly deepfake impersonation and AI-enabled malware.
- More than 20 percent of organisations reported a breach targeting AI models or applications.
- Organisations using AI and automation in their security operations cut breach costs by almost $2 million on average.
Deepfake impersonation goes after processes rather than systems: a convincing voice or video asking finance for an urgent payment. The control that holds is procedural, with confirmation on a known, separate channel and approvals a single call cannot bypass. At the same time, the AI applications an organisation runs are themselves targets, so they belong in security testing and monitoring like any other production system.
Four checks for this quarter
- List every AI agent in use, the tools it can call and the credentials behind them.
- Put one gateway in front of model calls and report AI cost per team and per completed task.
- Require confirmation on a separate, known channel for payments and changes of bank details.
- Include your AI applications in penetration tests and security monitoring.
More problems of this kind, with how we approach each one, are in our AI use cases.
Related reading
References
- McKinsey & Company, “The state of AI in 2026: On the road to ROI”, August 2026. McKinsey Global Survey, 1,719 participants, 4 May to 8 June 2026. https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
- IBM, “IBM Study: One in Four Malicious Breaches are AI-Enabled, Costing Companies $6 Million on Average”, press release on the Cost of a Data Breach Report 2026, 29 July 2026. Research by Ponemon Institute, 602 organisations, breaches between March 2025 and February 2026. https://newsroom.ibm.com/2026-07-29-ibm-study-one-in-four-malicious-breaches-are-ai-enabled,-costing-companies-6-million-on-average