Most privacy incidents will stem from conclusions generated by artificial intelligence rather than the direct exposure of personally identifiable information by 2029, according to Gartner. The research firm said advances in generative AI and machine learning are making it possible to infer sensitive information, including health conditions and behavioural patterns, from anonymised, aggregated or otherwise non-sensitive datasets.
Bart Willemsen, vice-president analyst at Gartner, said privacy risks were shifting from the exposure of raw data to the exposure of insights derived from it. “Organisations have historically focused on protecting raw personal data, but AI can now reconstruct deeply personal insights without ever breaching traditional data controls,” Willemsen said. “Privacy risks are increasingly emerging from what AI algorithms infer about individuals rather than what data is directly exposed.”
The risk may increase as organisations retain less personal data in response to regulatory requirements and cost pressures. Threat actors with access to AI tools could use the remaining information to conduct inference-based attacks without obtaining conventional personal records.
Gartner said such attacks can be difficult to detect because they may not involve a data breach. Instead, individuals may be exposed through conclusions produced by AI systems, creating risks related to accuracy, bias and unauthorised profiling.
The development is prompting organisations to broaden privacy programmes beyond data storage and access controls. Security and privacy teams will also need to govern how AI systems generate, use and act on information about individuals.
Gartner expects organisational spending on data integrity protections to reach parity with investment in data confidentiality by 2028. The projected shift reflects concerns about inaccurate, biased or unauthorised AI-generated profiles.
The firm said organisations should incorporate AI governance into privacy programmes, assess models for bias and unintended inferences, and use technologies such as differential privacy, synthetic data and privacy-aware machine learning. It also recommended limiting data collection, strengthening lifecycle controls and monitoring for indirect exploitation patterns. Gartner said organisations should document which inferences AI systems are permitted to make, conduct regular audits and require human review before sensitive AI-generated conclusions are used to make decisions.
