AI-generated conclusions will be the primary cause of privacy problems

The majority of privacy breaches will come from AI-generated inferences about people by 2029 rather than from direct exposure of personally identifiable information (PII).
According to a Gartner, Inc. report, developments in generative AI and machine learning allow attackers to glean private information from data that appears to be innocuous, anonymized, or aggregated, including health problems or behavioral patterns.
Because regulatory and cost constraints are pushing companies to save less personal information, threat actors may now execute inference-based attacks using their access to AI.
Gartner Vice President Analyst Bart Willemsen stated, “There is a fundamental shift occurring from data exposure to insight exposure. ”
“Traditionally, groups have concentrated on safeguarding sensitive personal information, but AI can now recreate highly private knowledge without ever breaking conventional data controls. He continued, “Privacy concerns are more and more arising from what AI algorithms infer about people rather than what data is immediately exposed. ”
According to Willemsen, inference attacks are especially dangerous since they frequently avoid conventional detection measures. “Individuals may be subjected to privacy concerns via AI-generated findings rather than leaked records, which compromise data integrity and are difficult to identify, explain, and mitigate,” he stated.
According to the study, expenditures on data integrity protections will reach parity with investments in data confidentiality by 2028 as companies address the hazards posed by biased, inaccurate, or unauthorized AI-generated profiles.
Companies that continue to see privacy as just a data protection problem will be increasingly prone to privacy incidents brought on by AI-generated conclusions.
The business advised security professionals to incorporate AI governance into their privacy policies, utilize privacy-enhancing technologies like differential privacy and synthetic data, and reinforce data lifecycle and reduction controls.
It said that to lower the amount of information that might be utilized for inference-based assaults, data collecting should be restricted to necessary business needs and that data should be promptly deleted and access control strictly enforced.
