GenAI Misuse to Boost AI Data Breaches by 2027
By 2027, more than 40% of AI-related data breaches will be caused by the improper use of GenAI across borders, according to Gartner.
By 2027, more than 40% of AI-related data breaches will be caused by the improper use of GenAI across borders, according to Gartner. The swift adoption of GenAI technologies by end-users has outpaced the development of data governance and security measures, raising concerns about data localization due to the centralized computing power required to support these technologies.
“Unintended cross-border data transfers often occur due to insufficient oversight, particularly when GenAI is integrated into existing products without clear descriptions or announcements,” said Joerg Fritsch, VP analyst at Gartner. “Organizations are noticing changes in the content produced by employees using GenAI tools. While these tools can be used for approved business applications, they pose security risks if sensitive prompts are sent to AI tools and APIs hosted in unknown locations.”
The lack of consistent global best practices and standards for AI and data governance exacerbates challenges by causing market fragmentation and forcing enterprises to develop region-specific strategies. This can limit their ability to scale operations globally and benefit from AI products and services.
“The complexity of managing data flows and maintaining quality due to localized AI policies can lead to operational inefficiencies,” said Fritsch. “Organizations must invest in advanced AI governance and security to protect sensitive data and ensure compliance. This need will likely drive growth in AI security, governance, and compliance services markets, as well as technology solutions that enhance transparency and control over AI processes.”
Gartner predicts that by 2027, AI governance will become a requirement of all sovereign AI laws and regulations worldwide. “Organizations that cannot integrate required governance models and controls may find themselves at a competitive disadvantage, especially those lacking the resources to quickly extend existing data governance frameworks,” said Fritsch. To mitigate the risks of AI data breaches, particularly from cross-border GenAI misuse, and to ensure compliance, Gartner recommends several strategic actions for enterprises: