Most future personal data breaches will not stem from the direct leakage of personally identifiable information (PII), such as resident registration numbers or financial details, but from inferences generated by artificial intelligence (AI) about individuals, according to a new outlook.
Gartner said in its report published on the 3rd, "Privacy outlook: strategies to address disruption from the spread of AI and surveillance technologies and protect individuals," that privacy risks based on AI inference will grow through 2029, and stated accordingly.
Gartner explained that corporations are reducing the amount of personal data they hold due to regulatory and expense burdens, but advances in Generative AI and Machine Learning have enabled attackers to infer sensitive information, such as personal health status or behavior patterns, even from anonymous and aggregated data alone.
Bart Willemsen, a senior analyst at Gartner, said, "The pattern of privacy breaches is shifting from data leakage to insight leakage," adding, "Privacy risks arise more from what AI algorithms infer about individuals than from data exposure."
Gartner warned that inference attacks are more dangerous because they often evade existing detection systems. Even if actual information is not leaked, sensitive personal information can be exposed through conclusions derived by AI. Analyst Willemsen said, "This undermines data integrity and creates privacy risks that are difficult to detect, explain, and mitigate."
Accordingly, corporations are expected to reassess their privacy strategies. Gartner said security officers must not stop at protecting personal data but also manage how AI systems generate and use insights about individuals, and how they act based on them.
Gartner forecast that as corporations strengthen responses to the risks of errors, bias, and unauthorized generation in AI profiles, expenditure on data integrity protection will reach a level similar to investments in confidentiality protection by 2028.
Analyst Willemsen said, "Corporations that view privacy solely as a data protection issue will become increasingly vulnerable to privacy breaches caused by AI-generated inferences," adding, "Future privacy risks will depend more on how AI interprets data than on how corporations store data."