Gartner’s AI security forecast exposes 162x services growth that still trails software 2 to 1 in new spending

Growth multiple versus net-new dollars added, 2024 to 2030. The segment ranking inverts between the two measures.
Every chart and table in this analysis opens full size when you click it.
Security services inside Gartner’s AI-amplified security market were worth $364 million in 2024. Gartner now projects $59 billion by 2030. That is 162 times larger in six years, compounding at 133.5% annually, the steepest curve anywhere in the forecast. I have tracked this forecast through every quarterly update, and no segment has ever moved like this one.
What Is AI-Amplified Security?
Gartner’s term for the share of existing security spending flowing to products with AI built in. Endpoint protection, firewalls, identity, and network security that now embed AI-driven detection, autonomous remediation, and agent-based response. Not a new category. Existing budgets redirecting toward AI-native capabilities. The companion forecast for securing AI itself reaches $16.4 billion in 2030. Gartner publicly confirms the 75%-by-2028 adoption projection.
The share table and the dollar table tell different stories. Software’s share of this market falls from 87.1% to 61.3%, and services picks up almost every point software gives up. Read only that and you conclude software is losing. Run the arithmetic on net-new spending and software still collects $116.5 billion of the $194.4 billion the market adds between 2024 and 2030. That is 60 cents of every new dollar, and it puts software ahead of services 2 to 1 on net-new spending.
Both things are true at once, and the gap between them is where security budgets get set wrong.
The numbers come from Gartner’s Forecast Analysis: AI-Amplified Security, Worldwide, 2026 (G00846160, August 4, 2026) by Shailendra Upadhyay. It is the first time Gartner has split AI-amplified security into software, services, and network security across a full seven-year window. The totals reconcile cleanly with the 2Q26 AI spending forecast, which carried AI-amplified security at $204.5 billion in 2030 without breaking out the segments underneath it.
This is a slice of the security budget, not an addition to it
The note states plainly that AI-amplified security is a subset of the information security forecast and that the spending is not additive. It points readers to the 2Q26 information security forecast, the one where securing AI became the only accelerating segment, for the parent view.
Keep the two straight. AI-amplified security is AI defending the enterprise, and it reaches $204 billion by 2030. Securing AI is the enterprise defending its own models, pipelines, and agents, at $16.4 billion in the same year. Roughly twelve dollars of AI-powered defense for every dollar spent protecting the AI doing the defending.
Key findings
- $204.5 billion by 2030, up from $10.0 billion in 2024. A 65.3% CAGR and 20.4x expansion. Gartner projects that by 2028, over 75% of enterprises will use AI-amplified cybersecurity products for most use cases, up from less than 25% in 2025. AI inside the product is table stakes, not a differentiator.
- Security services grows from $364 million to $59.0 billion. Share climbs from 3.6% to 28.9%, absorbing 25.3 of the 25.8 points software gives up. The skills gap is the engine.
- Security software reaches $125.3 billion and still wins the dollars. Share drops 25.8 points, but software adds $116.5 billion in net-new spending against services’ $58.7 billion. Services leads on rate and share. Software leads on absolute money.
- Network security reaches $20.1 billion at a 66.8% CAGR. Its share dips to 8.3% in 2027 before recovering to 9.8% in 2030. Autonomous agents for network security operations are the catalyst.
- The largest annual increment lands at the end. The market adds $14.3 billion in 2024-25 and $44.0 billion in 2029-30. Growth rates fall from 143% to 27% over the same span. Budget to increments, not rates.
- 72% of organizations already deploy AI with a third-party vendor. Only 27% rely primarily on internal resources, per Gartner’s 2025 AI Buying Behavior Survey of 556 respondents. That split is where the services forecast comes from.
- Code analysis leads GenAI security adoption at 22% in production. Combined in-use and piloting reaches 52%. Threat hunting sits at 18% in use with the highest planning rate of any use case at 44%.
- About one-third of network security tasks are automated today. Even fewer use AI. That gap is where the $20.1 billion network security forecast originates.

AI-amplified security by segment, 2024 to 2030.

Why services is the story, and where that story stops
Gartner’s 2025 AI Buying Behavior Survey quantifies the build-versus-buy split across 556 respondents. 57% deploy AI using both internal resources and third-party vendors. 27% rely primarily on internal resources. 15% go primarily through third-party vendors. Add the first and third and 72% of AI deployments already run through an outside partner.
Services did not grow 162x because buyers developed a taste for consultants. It grew because most organizations cannot staff the alternative. ISC2 measured a global cybersecurity workforce gap of 4.8 million professionals in its 2024 study, a gap that widened 19% year over year while the active workforce stayed flat. Gartner’s note describes service providers investing heavily to claim early leadership and running well ahead of their own clients in applying AI internally.
Here is the part the share chart hides. Software still captures 59.9% of all net-new spending in this market through 2030, against 30.2% for services and 9.9% for network security. A vendor reading the share decline as an exit signal would be misreading it. The software line is growing 14.3x in absolute terms while losing share to a segment growing from almost nothing.
Some CISOs will argue that services dependency creates lock-in they will pay for later. That argument is sound. It also lost. Gartner’s own numbers show in-house operation of AI security tooling has not scaled for the majority, and the 72% third-party figure is the receipt.
Growth rates decelerate while dollar increments keep climbing
Year-over-year growth falls from 142.7% in 2024-25 to 27.4% in 2029-30. That deceleration is normal for a market scaling from $10 billion to $204 billion. Services alone stays above 35% every year of the forecast, ending at 35.1% in 2029-30 after starting at 403%.

Year-over-year growth rate by segment.
Net-new dollars move the opposite direction. The market adds $14.3 billion in 2024-25, $38.0 billion in 2027-28, and $44.0 billion in 2029-30. Growth rates fall by four-fifths. Annual dollar increments triple. A business case anchored to “the market grows 143%” reads as broken by 2028. A business case anchored to “the market adds $38 billion that year” still holds.

Net new spending added per year, split by services versus software and network.
Look at the split inside those bars. In 2029-30, services contributes $15.4 billion of the $44.0 billion increment. Software and network contribute $28.7 billion. Even in the final year of the forecast, when services carries its highest share of the market, it is still the minority of new money.
The structural shift that defines this forecast
Software’s share falls 25.8 points across the forecast period. Services absorbs 25.3 of them. Network security ends roughly where it started, though not in a straight line, dipping to 8.3% in 2027 before recovering to 9.8% by 2030.

Segment share of the total AI-amplified security market.

The mechanism is staffing, not preference. Organizations bought AI security software intending to run it themselves. The services curve records what happened next. The $3.6 billion in venture funding flowing to agentic AI security startups confirms where the market believes the answer sits, and the acquisition wave underneath it says incumbents agree.
GenAI security adoption is broader than the in-use numbers suggest
Gartner’s 2025 Cybersecurity Innovations in AI Risk Management and Use Survey polled 302 cybersecurity leaders between March 21 and May 9, 2025. Fewer than 25% of organizations use GenAI for cybersecurity today. More than 60% are piloting or planning it. Gartner warns that without a clear strategy, many of these initiatives land as superficial implementations with high project turnover, driven by executive pressure rather than operational need.
Piloting is not aspiration. It means budget allocated, vendor selected, and a proof of concept running. Combine in-use and piloting and code analysis reaches 52%, user behavior analytics 51%, vulnerability detection 47%, and incident response 46%. The $204 billion endpoint assumes most of those pilots convert.

GenAI cybersecurity adoption by use case.

Threat hunting carries the highest planning rate in the survey at 44%, against 18% in production. No other use case has that much committed intent sitting ahead of deployment. When those budgets convert, threat hunting moves fastest in the next survey update.
Autonomous agents move from concept to production in network security
Human-centric operating models cannot absorb the scale, threat velocity, and traffic diversity that AI-driven workloads generate. Gartner describes AI-amplified network security agents that operate without predetermined workflows, adapt to security events nobody scripted, and handle threat detection, policy enforcement, and incident response while people supervise and validate rather than execute.
The trust curve is the constraint. By 2029, Gartner projects 10% of organizations will run autonomous agents with no human oversight for network security operations, up from less than 1% in 2026. Ten percent in three years is not a mass market. It is enough to reprice the segment, and the $20.1 billion forecast reflects that repricing. For how these agent numbers stack against other estimates, see my roundup of agentic AI forecasts and market estimates.
One number in the note worth checking before you quote it
Gartner’s note carries two different 2026 figures. The opening summary describes the market rising from $49 billion in 2026 to $204 billion by 2030. A later passage describes it reaching $204 billion in 2030, up from $81 billion in 2026. Table 1 puts 2026 at $48.5 billion and 2027 at $81.2 billion.
The table is the authority, and $49 billion is the number consistent with it. It also matches the $48.5 billion AI-amplified figure I reported in March from the prior forecast cycle. Anyone quoting $81 billion as a 2026 figure is quoting 2027.
What this forecast changes for CISOs and security vendors
- Reassess build versus buy, then budget for both. The 72% third-party figure is an organizational verdict on in-house feasibility. Plan services into the operating model rather than bolting it on. Do not read the share shift as permission to stop buying software, because software still takes 60% of the new dollars.
- Anchor business cases to dollar increments. The market adds $38.0 billion in 2027-28 and $44.0 billion in 2029-30. Those numbers stay correct. Growth percentages will look wrong inside two years.
- Move on threat hunting next. It has the highest planning rate in Gartner’s survey at 44% against 18% in production. Organizations that move before the pipeline converts will have more mature detection models when it does.
- Grade vendors on services delivery, not just features. A pure software licensing model captures a shrinking share of a growing market. Gartner’s note is direct about the consequence, warning that vendors who fail to operationalize AI for real-time threat detection and adaptive defense risk rapid obsolescence.
- Start network security agent pilots now. Gartner projects 10% trusted autonomy by 2029. That leaves three budget cycles to build guardrails, validation workflows, and the evidence trail an auditor will ask for. Waiting until 2028 means arriving late with an unproven control set.
- Watch the governance layer in parallel. Gartner’s first Hype Cycle for AI Governance puts most security-relevant governance capabilities two to five years from mainstream adoption, which is the same window in which these agents reach production.
Bottom line
I have tracked Gartner’s information security forecast through multiple quarterly updates. This is the first time the firm has published segment-level detail underneath AI-amplified security, and the segments say more than the total does. Traditional security spending is reorganizing around AI-native capability, and the delivery model is reorganizing with it.
Every CISO reading this should ask one question of their AI security strategy. Is it built around software licensing or around services delivery? The honest answer for most organizations is that it needs to be built around both, weighted differently than it is today. Services is where the growth rate lives. Software is where the money still goes.
The risk of getting this wrong is not theoretical. Forrester predicts an agentic AI deployment will cause a publicly disclosed data breach this year, leading to employee dismissals, a prediction Infosecurity Magazine reported when senior analyst Paddy Harrington framed it as a cascade of failures rather than a single point of error. Gartner’s forecast prices the defense. It does not schedule it.
Related on Software Strategies Blog
- Top 10 security categories where VC funding trails Gartner’s 2026 growth forecast (April 2026)
- Gartner forecasts agentic AI will overtake chatbot spending by 2027 (February 2026)
- Top 6 cybersecurity trends from Gartner’s 2026 Security Forecast (February 2026)
- Gartner 4Q25: $4.71T AI market proves agentic AI and data readiness are the only race that matters (January 2026)
- AI Security market 2025 funding data, top startups, and the ServiceNow factor (December 2025)
- Data readiness and security are driving AI’s $4.7 trillion run (December 2025)
- Top 10 fastest-growing segments from Gartner’s information security forecast, Q4 2024 (January 2025)
Source and methodology
All market sizing data from Gartner, Forecast Analysis: AI-Amplified Security, Worldwide, 2026, published August 4, 2026 (ID G00846160), by Shailendra Upadhyay. AI-amplified security is a subset of the information security forecast and this is not additive spending. Survey data from the 2025 Gartner AI Buying Behavior Survey (n=556, fielded November through December 2025 across North America, Western Europe, and Asia/Pacific, organizations with $50 million or more in enterprisewide revenue) and the 2025 Gartner Cybersecurity Innovations in AI Risk Management and Use Survey (n=302, fielded March 21 through May 9, 2025, organizations with $250 million or more in fiscal 2024 revenue). Gartner notes that neither survey represents global findings or the market as a whole.
CAGR, growth multiples, market share percentages, year-over-year growth rates, incremental spending, net-new dollar allocation, and combined adoption rates computed by Software Strategies Blog from Gartner’s published segment data. Segment values are independently rounded by Gartner and do not always sum to the stated totals. All charts are original visualizations created by Software Strategies Blog.
This post is my personal reflection on Gartner’s AI-amplified security research from an industry analyst perspective. It does not represent my employer.



















































