Your next privacy breach might not leak any data at all
Gartner: most privacy incidents will soon come from AI inferences
Latest
Deep tech | Sustainability | Ecosystems | Data and security | Fintech and ecommerce | Future of work
By 2029, most privacy incidents will stem not from leaked personal data but from what AI infers about people, according to a Gartner prediction. This shift from “data exposure to insight exposure” poses a new challenge for companies, as the risk extends beyond the records they hold.
From data exposure to insight exposure
As stated by Gartner analyst Bart Willemsen, AI models can now reconstruct sensitive information—like health conditions or behavioral patterns—from seemingly anonymous, aggregated, or harmless data. This irony arises despite companies storing less personal data due to regulations and costs, which is supposed to reduce risk.
The difficulty of catching inference attacks
Unlike traditional breaches that leave a trail, inference attacks leave no leaked record. These attacks are hard to detect because they don’t involve the direct exposure of personal data.
"Inference attacks are particularly dangerous because they often evade conventional detection mechanisms," said Willemsen.
The growing blind spot
The threat posed by inference attacks falls outside most privacy laws, which primarily govern the collection, storage, and sharing of personal data. As everyday tools record and analyze more aspects of our lives, this gap in regulation becomes a growing concern.
Gartner‘s recommendations for security chiefs
To address these challenges, Gartner suggests:
- Governing AI conclusions rather than just the data it stores.
- Achieving parity between spending on data integrity protections and data confidentiality by 2028.
- Implementing privacy-enhancing tools like differential privacy and synthetic data.
- Minimizing the amount of data available.
- Keeping a human involved in the approval process before AI acts on sensitive inferences.
These measures aim to protect against both malicious and accidental exposure resulting from AI-generated profiles. As Gartner notes, these recommendations are practical steps towards mitigating the risks associated with AI inferences.