New Delhi, July 31 — Most privacy incidents will arise from AI-generated inferences about individuals by 2029, rather than from the direct exposure of personally identifiable information, according to a report released on Friday.

The analysis from Gartner, Inc. states that advances in generative AI and machine learning now enable attackers to extract sensitive attributes—such as health conditions or behavioural patterns—from seemingly innocuous, anonymised or aggregated data. As organisations reduce the volume of personal data they store in response to regulatory and cost pressures, threat actors’ access to AI tools allows them to conduct inference-based attacks.

“There is a fundamental shift underway from data exposure to insight exposure,” said Bart Willemsen, VP Analyst at Gartner. “Organisations have historically focused on protecting raw personal data, but AI can now reconstruct deeply personal insights without ever breaching traditional data controls. Privacy risks are increasingly emerging from what AI algorithms infer about individuals rather than what data is directly exposed.”

Inference attacks are particularly concerning because they frequently bypass conventional detection mechanisms, Willemsen noted. “Individuals can be exposed through AI-generated conclusions rather than leaked records, creating privacy risks that undermine data integrity and are difficult to detect, explain and mitigate.”

The report forecasts that spending on data integrity protections will reach parity with investments in data confidentiality by 2028, as organisations respond to risks arising from inaccurate, biased or unauthorised AI-generated profiles. Firms that continue to treat privacy solely as a traditional data-protection challenge will become increasingly vulnerable to incidents driven by AI-generated inferences.

Gartner urged security leaders to integrate AI governance into privacy programmes, adopt privacy-enhancing technologies such as differential privacy and synthetic data, and strengthen data minimisation and lifecycle controls. “Limit data collection to essential business needs and ensure strict access control and timely deletion of data to reduce the information available for inference-based attacks,” the report advised.

The findings highlight a growing recognition that the protective perimeter around personal information is shifting. As AI systems become more capable of deriving sensitive insights from limited or anonymised datasets, organisations face pressure to expand their privacy strategies beyond conventional safeguards focused on raw data storage and access.