Skip to content

Posts from the ‘Louis Columbus’ blog’ Category

Gartner’s AI security forecast exposes 162x services growth that still trails software 2 to 1 in new spending

Gartner AI-amplified security forecast, growth multiple versus net-new dollars by segment, 2024 to 2030

Growth multiple versus net-new dollars added, 2024 to 2030. The segment ranking inverts between the two measures.

Every chart and table in this analysis opens full size when you click it.

Security services inside Gartner’s AI-amplified security market were worth $364 million in 2024. Gartner now projects $59 billion by 2030. That is 162 times larger in six years, compounding at 133.5% annually, the steepest curve anywhere in the forecast. I have tracked this forecast through every quarterly update, and no segment has ever moved like this one.

What Is AI-Amplified Security?

Gartner’s term for the share of existing security spending flowing to products with AI built in. Endpoint protection, firewalls, identity, and network security that now embed AI-driven detection, autonomous remediation, and agent-based response. Not a new category. Existing budgets redirecting toward AI-native capabilities. The companion forecast for securing AI itself reaches $16.4 billion in 2030. Gartner publicly confirms the 75%-by-2028 adoption projection.

The share table and the dollar table tell different stories. Software’s share of this market falls from 87.1% to 61.3%, and services picks up almost every point software gives up. Read only that and you conclude software is losing. Run the arithmetic on net-new spending and software still collects $116.5 billion of the $194.4 billion the market adds between 2024 and 2030. That is 60 cents of every new dollar, and it puts software ahead of services 2 to 1 on net-new spending.

Both things are true at once, and the gap between them is where security budgets get set wrong.

The numbers come from Gartner’s Forecast Analysis: AI-Amplified Security, Worldwide, 2026 (G00846160, August 4, 2026) by Shailendra Upadhyay. It is the first time Gartner has split AI-amplified security into software, services, and network security across a full seven-year window. The totals reconcile cleanly with the 2Q26 AI spending forecast, which carried AI-amplified security at $204.5 billion in 2030 without breaking out the segments underneath it.

This is a slice of the security budget, not an addition to it

The note states plainly that AI-amplified security is a subset of the information security forecast and that the spending is not additive. It points readers to the 2Q26 information security forecast, the one where securing AI became the only accelerating segment, for the parent view.

Keep the two straight. AI-amplified security is AI defending the enterprise, and it reaches $204 billion by 2030. Securing AI is the enterprise defending its own models, pipelines, and agents, at $16.4 billion in the same year. Roughly twelve dollars of AI-powered defense for every dollar spent protecting the AI doing the defending.

Key findings

  • $204.5 billion by 2030, up from $10.0 billion in 2024. A 65.3% CAGR and 20.4x expansion. Gartner projects that by 2028, over 75% of enterprises will use AI-amplified cybersecurity products for most use cases, up from less than 25% in 2025. AI inside the product is table stakes, not a differentiator.
  • Security services grows from $364 million to $59.0 billion. Share climbs from 3.6% to 28.9%, absorbing 25.3 of the 25.8 points software gives up. The skills gap is the engine.
  • Security software reaches $125.3 billion and still wins the dollars. Share drops 25.8 points, but software adds $116.5 billion in net-new spending against services’ $58.7 billion. Services leads on rate and share. Software leads on absolute money.
  • Network security reaches $20.1 billion at a 66.8% CAGR. Its share dips to 8.3% in 2027 before recovering to 9.8% in 2030. Autonomous agents for network security operations are the catalyst.
  • The largest annual increment lands at the end. The market adds $14.3 billion in 2024-25 and $44.0 billion in 2029-30. Growth rates fall from 143% to 27% over the same span. Budget to increments, not rates.
  • 72% of organizations already deploy AI with a third-party vendor. Only 27% rely primarily on internal resources, per Gartner’s 2025 AI Buying Behavior Survey of 556 respondents. That split is where the services forecast comes from.
  • Code analysis leads GenAI security adoption at 22% in production. Combined in-use and piloting reaches 52%. Threat hunting sits at 18% in use with the highest planning rate of any use case at 44%.
  • About one-third of network security tasks are automated today. Even fewer use AI. That gap is where the $20.1 billion network security forecast originates.
Gartner AI-amplified security market by segment, US dollars, 2024 to 2030

AI-amplified security by segment, 2024 to 2030.

Gartner AI-amplified security market forecast by segment, US dollars millions, 2024 to 2030

Why services is the story, and where that story stops

Gartner’s 2025 AI Buying Behavior Survey quantifies the build-versus-buy split across 556 respondents. 57% deploy AI using both internal resources and third-party vendors. 27% rely primarily on internal resources. 15% go primarily through third-party vendors. Add the first and third and 72% of AI deployments already run through an outside partner.

Services did not grow 162x because buyers developed a taste for consultants. It grew because most organizations cannot staff the alternative. ISC2 measured a global cybersecurity workforce gap of 4.8 million professionals in its 2024 study, a gap that widened 19% year over year while the active workforce stayed flat. Gartner’s note describes service providers investing heavily to claim early leadership and running well ahead of their own clients in applying AI internally.

Here is the part the share chart hides. Software still captures 59.9% of all net-new spending in this market through 2030, against 30.2% for services and 9.9% for network security. A vendor reading the share decline as an exit signal would be misreading it. The software line is growing 14.3x in absolute terms while losing share to a segment growing from almost nothing.

Some CISOs will argue that services dependency creates lock-in they will pay for later. That argument is sound. It also lost. Gartner’s own numbers show in-house operation of AI security tooling has not scaled for the majority, and the 72% third-party figure is the receipt.

Growth rates decelerate while dollar increments keep climbing

Year-over-year growth falls from 142.7% in 2024-25 to 27.4% in 2029-30. That deceleration is normal for a market scaling from $10 billion to $204 billion. Services alone stays above 35% every year of the forecast, ending at 35.1% in 2029-30 after starting at 403%.

Year-over-year growth rate by segment, Gartner AI-amplified security forecast

Year-over-year growth rate by segment.

Net-new dollars move the opposite direction. The market adds $14.3 billion in 2024-25, $38.0 billion in 2027-28, and $44.0 billion in 2029-30. Growth rates fall by four-fifths. Annual dollar increments triple. A business case anchored to “the market grows 143%” reads as broken by 2028. A business case anchored to “the market adds $38 billion that year” still holds.

Net-new AI-amplified security spending added per year, services versus software and network

Net new spending added per year, split by services versus software and network.

Look at the split inside those bars. In 2029-30, services contributes $15.4 billion of the $44.0 billion increment. Software and network contribute $28.7 billion. Even in the final year of the forecast, when services carries its highest share of the market, it is still the minority of new money.

The structural shift that defines this forecast

Software’s share falls 25.8 points across the forecast period. Services absorbs 25.3 of them. Network security ends roughly where it started, though not in a straight line, dipping to 8.3% in 2027 before recovering to 9.8% by 2030.

AI-amplified security segment share shift, 2024 to 2030

Segment share of the total AI-amplified security market.

AI-amplified security segment share shift, 2024 to 2030

The mechanism is staffing, not preference. Organizations bought AI security software intending to run it themselves. The services curve records what happened next. The $3.6 billion in venture funding flowing to agentic AI security startups confirms where the market believes the answer sits, and the acquisition wave underneath it says incumbents agree.

GenAI security adoption is broader than the in-use numbers suggest

Gartner’s 2025 Cybersecurity Innovations in AI Risk Management and Use Survey polled 302 cybersecurity leaders between March 21 and May 9, 2025. Fewer than 25% of organizations use GenAI for cybersecurity today. More than 60% are piloting or planning it. Gartner warns that without a clear strategy, many of these initiatives land as superficial implementations with high project turnover, driven by executive pressure rather than operational need.

Piloting is not aspiration. It means budget allocated, vendor selected, and a proof of concept running. Combine in-use and piloting and code analysis reaches 52%, user behavior analytics 51%, vulnerability detection 47%, and incident response 46%. The $204 billion endpoint assumes most of those pilots convert.

GenAI cybersecurity adoption by use case, 2025 Gartner survey

GenAI cybersecurity adoption by use case.

GenAI cybersecurity adoption by use case, 2025 Gartner survey

Threat hunting carries the highest planning rate in the survey at 44%, against 18% in production. No other use case has that much committed intent sitting ahead of deployment. When those budgets convert, threat hunting moves fastest in the next survey update.

Autonomous agents move from concept to production in network security

Human-centric operating models cannot absorb the scale, threat velocity, and traffic diversity that AI-driven workloads generate. Gartner describes AI-amplified network security agents that operate without predetermined workflows, adapt to security events nobody scripted, and handle threat detection, policy enforcement, and incident response while people supervise and validate rather than execute.

The trust curve is the constraint. By 2029, Gartner projects 10% of organizations will run autonomous agents with no human oversight for network security operations, up from less than 1% in 2026. Ten percent in three years is not a mass market. It is enough to reprice the segment, and the $20.1 billion forecast reflects that repricing. For how these agent numbers stack against other estimates, see my roundup of agentic AI forecasts and market estimates.

One number in the note worth checking before you quote it

Gartner’s note carries two different 2026 figures. The opening summary describes the market rising from $49 billion in 2026 to $204 billion by 2030. A later passage describes it reaching $204 billion in 2030, up from $81 billion in 2026. Table 1 puts 2026 at $48.5 billion and 2027 at $81.2 billion.

The table is the authority, and $49 billion is the number consistent with it. It also matches the $48.5 billion AI-amplified figure I reported in March from the prior forecast cycle. Anyone quoting $81 billion as a 2026 figure is quoting 2027.

What this forecast changes for CISOs and security vendors

  • Reassess build versus buy, then budget for both. The 72% third-party figure is an organizational verdict on in-house feasibility. Plan services into the operating model rather than bolting it on. Do not read the share shift as permission to stop buying software, because software still takes 60% of the new dollars.
  • Anchor business cases to dollar increments. The market adds $38.0 billion in 2027-28 and $44.0 billion in 2029-30. Those numbers stay correct. Growth percentages will look wrong inside two years.
  • Move on threat hunting next. It has the highest planning rate in Gartner’s survey at 44% against 18% in production. Organizations that move before the pipeline converts will have more mature detection models when it does.
  • Grade vendors on services delivery, not just features. A pure software licensing model captures a shrinking share of a growing market. Gartner’s note is direct about the consequence, warning that vendors who fail to operationalize AI for real-time threat detection and adaptive defense risk rapid obsolescence.
  • Start network security agent pilots now. Gartner projects 10% trusted autonomy by 2029. That leaves three budget cycles to build guardrails, validation workflows, and the evidence trail an auditor will ask for. Waiting until 2028 means arriving late with an unproven control set.
  • Watch the governance layer in parallel. Gartner’s first Hype Cycle for AI Governance puts most security-relevant governance capabilities two to five years from mainstream adoption, which is the same window in which these agents reach production.

Bottom line

I have tracked Gartner’s information security forecast through multiple quarterly updates. This is the first time the firm has published segment-level detail underneath AI-amplified security, and the segments say more than the total does. Traditional security spending is reorganizing around AI-native capability, and the delivery model is reorganizing with it.

Every CISO reading this should ask one question of their AI security strategy. Is it built around software licensing or around services delivery? The honest answer for most organizations is that it needs to be built around both, weighted differently than it is today. Services is where the growth rate lives. Software is where the money still goes.

The risk of getting this wrong is not theoretical. Forrester predicts an agentic AI deployment will cause a publicly disclosed data breach this year, leading to employee dismissals, a prediction Infosecurity Magazine reported when senior analyst Paddy Harrington framed it as a cascade of failures rather than a single point of error. Gartner’s forecast prices the defense. It does not schedule it.

Related on Software Strategies Blog

Source and methodology

All market sizing data from Gartner, Forecast Analysis: AI-Amplified Security, Worldwide, 2026, published August 4, 2026 (ID G00846160), by Shailendra Upadhyay. AI-amplified security is a subset of the information security forecast and this is not additive spending. Survey data from the 2025 Gartner AI Buying Behavior Survey (n=556, fielded November through December 2025 across North America, Western Europe, and Asia/Pacific, organizations with $50 million or more in enterprisewide revenue) and the 2025 Gartner Cybersecurity Innovations in AI Risk Management and Use Survey (n=302, fielded March 21 through May 9, 2025, organizations with $250 million or more in fiscal 2024 revenue). Gartner notes that neither survey represents global findings or the market as a whole.

CAGR, growth multiples, market share percentages, year-over-year growth rates, incremental spending, net-new dollar allocation, and combined adoption rates computed by Software Strategies Blog from Gartner’s published segment data. Segment values are independently rounded by Gartner and do not always sum to the stated totals. All charts are original visualizations created by Software Strategies Blog.

This post is my personal reflection on Gartner’s AI-amplified security research from an industry analyst perspective. It does not represent my employer.

34% of enterprises govern AI with policies they only partly follow. Gartner’s first AI Governance Hype Cycle shows CISOs what to fund first.

Gartner Hype Cycle for AI Governance, 2026, showing AI cybersecurity governance, AI governance platforms, and agentic AI risk innovations plotted across the innovation trigger, peak, trough, slope, and plateau phases. Please click on the graphic to expand for easier reading.

Gartner’s 2026 AI Leaders Effectiveness Survey found that 34% of organizations have well-defined AI governance structures and policies for managing risks, ethics, and compliance. Those same organizations report only partial adherence to the rules they wrote, while another 22% still rely on basic or ad hoc policies. Only 7% qualify as recognized leaders in ethical AI.

That gap between writing the policy and living by it is what Gartner’s first Hype Cycle for AI Governance, 2026 is built to address. Published July 21, 2026, the inaugural cycle plots 32 innovations and ranks each by benefit rating and years to mainstream adoption. CISOs and enterprise architects get a planning map that builds on Gartner’s forecast that agentic AI will overtake chatbot spending by 2027. Throughout this post, I use “rogue agents” as my editorial shorthand for unsanctioned AI agents operating outside governance perimeters.

The two clusters that carry the security agenda

The report organizes its 32 innovations around six enterprise trends. Two carry the security agenda. Agentic AI oversight and life cycle governance is the first, grouping agentic AI governance, agent development life cycle, AI agent identity, AI engineering, AI gateways and AI governance platforms under one trend. Advancing AI security is the second, covering AI TRiSM, AI cybersecurity governance, disinformation security, zero-trust data governance, mechanistic interpretability and AI product attribution and transparency. Together they define where governance stacks connect to identity systems, traffic controls and incident response playbooks. For how these gaps show up in spending data, see my analysis of Gartner’s $248.9B security forecast.

Five innovations that pay off in under two years

Table 1, the Priority Matrix, ranks every innovation by benefit rating and adoption timeline. Only five entries land in the “Less Than 2 Years” column. Responsible AI sits alone in the Transformational row, Gartner’s highest rating. AI guardrails, data access governance, digital ethics and ontologies all carry High benefit ratings at the same timeline. Gartner calls these the near-term priorities for scalable governance. CISOs should fund them first.

Please click on the image to expand for easier reading.

The two-to-five-year column is the densest band. Thirteen innovations carry a High benefit rating there, including agentic AI governance, AI agent identity, AI TRiSM, zero-trust data governance and third-party risk management. That band is where CISOs will build governance stacks over the next several budget cycles. For context on spending already flowing to AI-related capabilities, see my breakdown of Gartner’s $244.2B security forecast.

Where AI cybersecurity governance actually lands

AI cybersecurity governance carries a Moderate benefit rating at the Innovation Trigger, five to ten years from mainstream adoption. That placement may surprise CISOs who expected Gartner to rate it higher. The profile’s key goals are to prevent shadow AI, minimize attack surfaces and ensure visibility and response to incidents. The placement is a market signal, not a dismissal. Tooling is early, but the need is urgent enough that CISOs should treat AI cybersecurity governance as an architecture requirement today.

What the Priority Matrix tells your board

The report leads with two strategic planning assumptions that carry board-level weight. Enterprises implementing AI governance will outperform ungoverned competitors in AI adoption by 25% by 2029. The downside is just as concrete. Autonomous agents identifying minor consumer rights violations and turning them into lawsuits will increase corporate settlement costs by 15% over the same period. Growth-oriented executives respond to the first number. Risk-averse ones respond to the second.

Turning the curve into controls

Start by mapping your AI agent footprint, sanctioned and unsanctioned, across SaaS platforms, internal applications and shadow IT. From there, match the Hype Cycle’s innovations to four governance domains. The identity and access layer runs on AI agent identity and AI governance platforms. Data classification draws on AI guardrails, data access governance and zero-trust data governance, while AI gateways and AI TRiSM handle traffic mediation. Agent risk management anchors in agentic AI governance and the agent development life cycle. Build all four as shared services. For how agent sprawl is reshaping security spending, see my roundup of agentic AI forecasts and market estimates, 2026.

What these numbers add up to

Gartner’s inaugural Hype Cycle for AI Governance puts 32 innovations on the curve. Only five reach mainstream adoption in under two years. The security-relevant capabilities cluster in the two-to-five-year band, which means CISOs have a narrow window to build governance stacks before agent footprints outpace controls. The 34% adherence stat is the warning, and the Priority Matrix is the roadmap out of it.

This post is my personal reflection on Gartner’s AI governance research from a CISO and enterprise architecture perspective. It does not represent any employer or client.

Source: Gartner, Hype Cycle for AI Governance, 2026, Svetlana Sicular, Var Shankar, Lauren Kornutick, Sumit Agarwal, 21 July 2026, G00854164.

Gartner’s $5.95 trillion AI forecast puts the chatbot era on a 2027 deadline

Spending on the chatbots and assistants embedded in enterprise software peaks at $272.6 billion in 2027 and then shrinks every year through 2030. Gartner buried that projection inside the 2Q26 update of its worldwide AI spending forecast, published July 24, and it matters more than the headline total. By 2030, embedded chatbot spending falls back to $205.8 billion, a hair above its 2025 starting point.

Embedded agenticAI takes the money instead, growing from $88.2 billion in 2025 to $1 trillion by 2030, an 11.4x expansion inside a single software category.

None of that slows the topline. Worldwide AI spending reaches $2.67 trillion in 2026, up 49.5% from 2025, on its way to $5.95 trillion by 2030. The figure Gartner published in May was $2.59 trillion for this year. Ninety days later, the client-facing number runs $74.8 billion higher, and the firm added $496.8 billion to its comparable 2025 through 2030 outlook in a single quarter.

Four tables below show where the money lands, which segments stall, and what Gartner changed its mind about between April and July.

Where $5.95 trillion lands

Infrastructure stays the biggest line through 2030 at $2.79 trillion, even as its share of total spending slides from 55% in 2025 to 46.9% at the end of the window. AI-optimized servers alone reach $981.7 billion by 2030, a 3.4x jump from 2025, and AI processing semiconductors add another $656.4 billion. O

One caution before quoting the total anywhere. Gartner’s note flags the forecast as a view across the whole AI value chain, so the chip and the server it ships inside both get counted. Read $5.95 trillion as the size of the AI economy, not as net end-user budgets.

Devices carry more of the infrastructure number than most readers expect. Business and consumer AI devices combine for $904.4 billion in 2030, and $647.4 billion of that is consumer hardware, the AI PCs and phones landing in shopping carts rather than data centers.

Growth flattens fast after next year. Total spending rises 49% in 2026 and 36% in 2027, then steps down to 21%, 18% and 15% through 2030, while infrastructure decelerates from 51% growth this year to 9% at the end of the forecast.

Of the $883.8 billion in net-new AI spending arriving in 2026, infrastructure absorbs $502.5 billion, or 57 cents of every new dollar. The shape of the curve says the buildout peaks now and software inherits the growth.

Farther down the board, AI cybersecurity at $220.9 billion and AI agents and assistants at $219.9 billion finish 2030 within $1 billion of each other. Gartner created the agents category only this quarter.

Agentic AI crosses $1 trillion inside enterprise software

Gartner rebuilt its segmentation this quarter, splitting cross-functional and consumer agents out of AI software and adding consumer agents to the forecast for the first time. The new structure exposes a replacement cycle the old rollup hid. Inside enterprise software, agentic AI overtakes chatbots in 2027, the same year chatbot spending tops out, and from that peak to 2030 the embedded chatbot line surrenders $66.8 billion.

Cross-functional agents, the ones that work across software from multiple vendors, start from a base of zero. Gartner books $347 million for cross-functional agentic AI in 2026 and $78.1 billion in 2030, a number it raised this quarter on the thesis that these agents begin cannibalizing traditional SaaS by decade’s end. The ceiling matters as much as the curve. Against $1.21 trillion in total 2030 AI software spending, $78.1 billion says the incumbents hold the decade, because data access, integration complexity and execution reliability hold the category back from serious SaaS competition until 2030, in Gartner’s read.

The buy-versus-build verdict is just as lopsided. Agent builder platforms, the tooling for constructing your own agents, reach only $12.6 billion by 2030, so embedded agentic AI outspends them nearly 80 to 1. The first production agent most companies run will ship inside software they already own. Gartner describes exactly that race, with vendors across software categories embedding agentic AI to defend their installed bases against cross-functional challengers.

Consumer agents barely register yet in dollar terms. Gartner carries $26.9 million for consumer agentic AI in 2026, then $17.7 billion in 2027 as paid consumer agents arrive at scale, building to $51.8 billion by 2030. Adding consumer agents and assistants lifted Gartner’s 2030 total by $133 billion. For how these agent numbers stack against other analyst estimates, see my roundup of agentic AI forecasts and market estimates, 2026.

AI security expands 8.5x and splits in two

AI cybersecurity grows from $25.9 billion in 2025 to $220.9 billion in 2030, an 8.5x expansion at a 53.5% compound rate. Spending in the category grew 140% in 2025, and Gartner models another 98% jump this year. AI cybersecurity and AI data were also the only two markets left completely untouched between the 1Q26 and 2Q26 forecasts, which makes security the steadiest conviction in the entire model. For the standalone security spending outlook, see my breakdown of Gartner’s 2Q26 information security forecast.

Two markets move at different speeds inside the category. AI-amplified security, meaning AI capability inside security tooling, carries the volume and reaches $204.5 billion by 2030. Securing AI, the discipline of protecting AI systems themselves, runs smaller and faster, from $1.5 billion in 2025 to $16.4 billion in 2030 at a 60.4% compound rate.

Set the security numbers against the agent forecast and an exposure gap opens. The 2030 outlook has enterprises running $1.08 trillion of embedded and cross-functional agentic software while spending $16.4 billion to secure AI systems, roughly $66 of agentic software for every $1 of securing-AI budget. AI observability and governance tooling adds just $3.9 billion more. A software wave that large riding on a security ratio that thin is the budget argument CISOs should be starting now.

The fastest growth goes to whatever cuts the bill

Rank every segment by compound growth and one pattern jumps out, because the fastest-growing lines are the ones that make AI cheaper. Synthetic data generation leads the entire forecast at a 142.5% compound rate, expanding 84x from $146 million in 2025 to $12.2 billion in 2030. AI-ready datasets, the licensed real-data alternative, peak at $583 million in 2029 and then decline, leaving synthetic data outselling licensed data 22 to 1 by 2030. Gartner is forecasting the substitution of purchased data itself.

Domain-specific language models tell the same cost story at larger scale. DSLMs and specialized models grow 210% in 2026 and compound at 84.5% through 2030, rising from 12.2% of all model spend to 24.3%. Cost pressure also explains the strangest revision in the update. Gartner cut $57.8 billion in cumulative dollars from its generative AI model forecast while raising the segment’s 2026 growth rate from 110% to 117%, which nets out to more deployments running on cheaper models and smaller checks. Arunasree Cheparthi, a senior principal research analyst at Gartner and one of the forecast’s authors, said in the firm’s July 20 platforms and models announcement that spending “is shifting toward providers who can demonstrate clear value.”

What Gartner changed in 90 days

Between the April forecast and this one, Gartner added $500.8 billion to AI infrastructure across the 2025 through 2030 window, the largest revision in the update, and did it while flagging memory-related price increases. The note calls infrastructure demand inelastic to that pricing pressure, because hyperscalers keep buying AI-optimized servers on the conviction that model capabilities improve through 2030.

Software took the other side of the trade. AI software gained $191.9 billion and application development platforms picked up $10.7 billion. Gartner lifted the 2026 app-dev growth rate from 28% to 39% as enterprises build custom AI applications and demand usage tracking to prove the spend. The cuts land on everything that resembles consulting or plumbing. AI services lost $80.7 billion across the window, with every single year revised down, and platforms for data science and machine learning lost $68.2 billion, including an 8% cut to 2027 alone.

The services cut hides a structural shift rather than a retreat. Gartner still sizes AI services at $1.25 trillion in 2030, but the growth belongs to indirect services, which compound at 34.5% and pass direct, consulting-led engagements in 2028. Direct AI services compound at 15.7%, less than half the indirect rate. Buyers are routing transformation budgets through software and cloud purchases instead of billable hours.

Three dates to plan against

2027 is the year chatbot spending tops out and agentic AI takes over inside enterprise software, which gives any vendor still selling assistant-branded features through the end of next year to ride what growth remains. By 2028, indirect services pass consulting-led engagements and infrastructure growth drops to 15%, so the buildout stops flattering everyone’s numbers. And 2030 arrives with $1.08 trillion of agentic software guarded by $16.4 billion of securing-AI spend. The first two dates decide where the money goes, and the third decides what happens when it arrives unprotected.

This post is my personal reflection on Gartner’s AI spending research from an industry analyst perspective. It does not represent my employer.

Source: Gartner, Forecast: AI Spending, Worldwide, 2025-2030, 2Q26, Kay Arnott, Jon Erensen, Amarendra, Adrian O’Connell, Arunasree Cheparthi, Naresh Singh, Peter Middleton, Hardeep Singh, Shailendra Upadhyay, Rishi Padhi, 24 July 2026, G00855896.

Gartner’s $248.9B security forecast makes securing AI the only segment accelerating through 2030

Gartner 2Q26 forecast, securing AI turns Other Security Software into the only accelerating segment, 16.3% to 20.1% by 2030

Gartner published its 2Q26 information security forecast on June 25. Worldwide spending reaches $248.9 billion in 2026, up 12.7% in constant currency, and hits $372.6 billion by 2030. The total is not the story. For the first time, Gartner is counting what enterprises spend to secure AI itself. Securing AI flips the only accelerating growth curve in Gartner’s forecast. It captures more new dollars than any other category. By 2029 it is the largest line item in enterprise security.

I’ve tracked this forecast through every quarterly update, and the 2026 projection keeps climbing. In March, I had it at $244.2 billion. The 1Q26 update raised it to $246.2 billion. Now it stands at $248.9 billion. Two upward revisions in one quarter. The second one changes what the forecast measures, not just what it totals.

Where securing AI landed in Gartner’s forecast

Gartner folded securing AI spending into its Other Security Software segment, which now grows from $15.6 billion in 2025 to $37.6 billion by 2030. One accounting decision reshaped the entire forecast.

Start with the growth curve. The 1Q26 version of this segment decelerated from 7.3% growth in 2026 down to 3.6% by 2030. With securing AI counted, the same segment accelerates from 16.3% to 20.1% across the same window. I ran all 41 categories in Gartner’s detailed forecast file. This is the only one whose annual growth rate increases every single year through 2030.

Then the size ranking flips. Endpoint protection platforms hold the top category spot through 2028 at $27.3 billion. In 2029, the securing AI segment passes them, $31.2 billion versus $30.1 billion. By 2030, the gap will widen to $37.6 billion against $33.0 billion. The largest line item in enterprise security will be one that Gartner’s 1Q26 forecast had growing at 5.1% a year. The 2Q26 forecast has the same segment compounding at 18.5%.

Gartner 2Q26 forecast, securing AI segment passes endpoint protection in 2029 at $31.2B vs $30.1B, reaching $37.6B by 2030

The 10 fastest-growing categories through 2030

The table ranks the 41 detailed categories underneath Gartner’s 11 headline segments by 2025 to 2030 CAGR in constant currency. Market sizes are in current U.S. dollars.

# Category (Parent Segment) 2025 ($B) 2030 ($B) CAGR New $ ($B)
1 Cloud Security Posture Management $4.7B $16.1B 27.6% $+11.5B
2 Cloud Access Security Brokers $2.2B $6.6B 24.3% $+4.4B
3 Cloud Workload Protection Platforms $5.9B $15.7B 21.0% $+9.8B
4 Zero Trust Network Access $2.4B $6.4B 20.9% $+4.0B
5 Threat Intelligence $2.5B $6.1B 19.0% $+3.6B
6 Consent and Preference Management $0.8B $2.0B 18.6% $+1.2B
7 Other Security Software (incl. securing AI) $15.6B $37.6B 18.5% $+21.9B
8 Network Detection and Response $2.2B $4.1B 12.4% $+1.9B
9 Subject Rights Request Automation $1.3B $2.3B 12.3% $+1.1B
10 Vulnerability Assessment $3.5B $6.4B 12.0% $+2.8B
Total information security market $218.2B $372.6B 10.7% $154.4B

Source: Gartner, Forecast: Information Security, Worldwide, 2024–2030, 2Q26 (G00855892, June 25, 2026). CAGR is computed from constant-currency values. Dollar figures in current U.S. dollars.

Gartner 2Q26 forecast, top 10 fastest growing security categories, CSPM leads at 27.6% CAGR, securing AI at 18.5%

Seven categories compound at 18.5% or better. The whole market runs at 10.7%. Then the ranking falls off a cliff to 12.4%. Cloud security posture management leads everything at 27.6%, growing from $4.7 billion to $16.1 billion. The three cloud security categories together triple to $38.4 billion by 2030, extending the run I flagged when cloud security led the 4Q25 update at 28.8%. Zero trust network access grows 2.65x to $6.4 billion while the category it replaces, network access control, falls 61% to $382 million. That is a migration, not a decline. NAC dollars are showing up in ZTNA line items instead.

I update this Top 10 ranking every quarter as Gartner releases new forecast data. Get the next one in your inbox.

Where the next $154 billion lands

The market adds $154.4 billion in new annual spending between 2025 and 2030. Six categories capture just under half of it. The securing AI segment takes $21.9 billion, more than any other line. Endpoint protection adds $14.6 billion. CSPM adds $11.5 billion. Firewall equipment, the legacy line everyone keeps writing off, adds $9.9 billion, the fourth most in the entire forecast. The other 35 categories fight over what remains.

Gartner 2Q26 forecast, securing AI captures $21.9B of $154.4B in new security spending through 2030, most of any category

The bottom of the table tells the same story from the other direction. Consumer security software crawls at 3.5%. User authentication grows 3.1% a year, the slowest line in identity, while IDPS shrinks 8.3% and NAC contracts 17.7% annually. The standalone products that anchored enterprise security budgets a decade ago are being folded into the platforms that grew up around them, and the consolidation story vendors have pitched for years is now visible in Gartner’s own numbers.

In my 1Q26 breakdown of the Top 10 fastest growers, the securing AI segment did not exist as a distinct growth driver. One quarter later, it leads every category in new dollars. That is how fast the forecast structure moved.

What these numbers add up to

Gartner now expects more than half of the overall security market to include AI by 2030. This update prices the other side of that trade for the first time. In March, I wrote that enterprises were spending 17x more on AI tools than on securing AI itself. The catch-up spend now has its own line in the forecast, and it is the only number in the entire table that keeps accelerating.

Gartner raised its 2030 total outlook by $19.5 billion. The securing AI segment accounts for $20.3 billion of that revision. Every other segment combined has a net cut of roughly $780 million. The money is moving, and it is moving in one direction.

Gartner’s 3Q26 forecast update lands in the fall, and I’ll break down whether the securing AI acceleration holds or whether Gartner revises the trajectory once early enterprise adoption data comes in. That update will also be the first to reflect a full year of post-inclusion spending data.

Top 10 security categories where VC funding trails Gartner’s 2026 growth forecast, Crunchbase data

Top 10 security categories where VC funding trails Gartner’s 2026 growth forecast, Crunchbase data

Two of Gartner’s 10 fastest-growing security categories have zero venture-backed startups. Firewall equipment, a $26.7 billion market by 2030, and pure-play cloud access security brokers, projected at $7.1 billion, are controlled entirely by incumbent vendors. No startup has raised a dollar in either category since January 2025.

I cross-referenced Gartner’s 1Q26 Information Security forecast against CB Insights, Crunchbase, and PitchBook funding data for every one of the 10 fastest-growing security categories. The question: where is venture capital following Gartner’s growth signal, and where is it missing?

The answer is stark. $93.2 billion in projected 2030 spending across these 10 categories. $11.2 billion in total VC raised by 59 funded startups. That is an 8.3:1 gap between where enterprise demand is heading and where startup capital is flowing. In 5 of 10 categories, the gap exceeds 12:1. As I detailed in last week’s analysis of the 10 fastest-growing categories, growth is concentrating in cloud infrastructure, proactive intelligence, and privacy compliance. The VC data tells you whether anyone is building what CISOs need to buy.

“Cybersecurity leaders are navigating uncharted territory this year as these forces converge, testing the limits of their teams in an environment defined by constant change,” said Alex Michaels, Director at Gartner. The spending data confirms it. The startup funding data shows the supply side has not caught up.

Two of Gartner’s 10 fastest-growing security categories have zero venture-backed startups. Firewall equipment, a $26.7 billion market by 2030, and pure-play cloud access security brokers, projected at $7.1 billion, are controlled entirely by incumbent vendors. No startup has raised a dollar in either category since January 2025. I cross-referenced Gartner’s 1Q26 Information Security forecast against CB Insights, Crunchbase, and PitchBook funding data for every one of the 10 fastest-growing security categories. The question: where is venture capital following Gartner’s growth signal, and where is it missing? The answer is stark. $93.2 billion in projected 2030 spending across these 10 categories. $11.2 billion in total VC raised by 59 funded startups. That is an 8.3:1 gap between where enterprise demand is heading and where startup capital is flowing. In 5 of 10 categories, the gap exceeds 12:1. As I detailed in last week’s analysis of the 10 fastest-growing categories, growth is concentrating in cloud infrastructure, proactive intelligence, and privacy compliance. The VC data tells you whether anyone is building what CISOs need to buy. “Cybersecurity leaders are navigating uncharted territory this year as these forces converge, testing the limits of their teams in an environment defined by constant change,” said Alex Michaels, Director at Gartner. The spending data confirms it. The startup funding data shows the supply side has not caught up. ▼ GRAPHIC: GRAPHIC 2 — Paired bar chart: Gartner 2030 projection vs. VC raised (insert before master table) ▼ Figure 2: Gartner 2030 projections (dark) vs. total VC raised (light) for each of the 10 categories. The master table: Gartner forecast vs. startup funding by category I mapped each Gartner category against every cybersecurity startup that raised equity or debt since January 2025. Each company is assigned to one primary category to avoid double-counting. Gap Ratio is the Gartner 2030 market projection divided by total VC raised. Higher means wider gap. # Gartner Security Category 2025-26 GR 5yr CAGR 2030 Proj Startups Total VC Gap Ratio Verdict 1 Cloud Access Security Brokers (CASB) 27.2% 24.3% $7.1B 4 $182M 39:1 Critical Gap 2 Firewall Equipment (NGFW/FWaaS) 15.9% 9.1% $26.7B 0 $0 ∞ Incumbent Lock 3 Cloud Security Posture Mgmt (CSPM) 33.4% 27.6% $16.2B 6 $752M 21.5:1 Underfunded 4 Vulnerability Assessment 15.7% 12.0% $6.4B 6 $306M 20.9:1 Underfunded 5 Cloud Workload Protection (CWPP) 25.9% 21.0% $16.1B 8 $1.28B 12.6:1 Underfunded 6 Subject Rights Request Automation 16.2% 12.3% $2.3B 2 $240M 9.6:1 M&A Absorbed 7 Network Detection & Response (NDR) 15.6% 12.4% $4.1B 4 $701M 5.9:1 Moderate Gap 8 Zero Trust Network Access (ZTNA) 23.0% 20.9% $6.4B 10 $1.94B 3.3:1 VC Ahead 9 Threat Intelligence 27.3% 21.1% $6.9B 12 $3.16B 2.2:1 Oversupplied 10 Consent & Preference Mgmt 22.1% 18.6% $2.0B 7 $2.61B 0.8:1 Oversupplied Source: Gartner 1Q26 Information Security Market Current Outlook (G00846158, March 2026). Growth rates in constant currency. Funding data from CB Insights, Crunchbase, PitchBook. Analysis by Software Strategies Blog, April 2026. The table splits cleanly into three tiers. Five categories are underfunded or locked out (Gap Ratio above 9:1). Two sit in the middle. Three are oversupplied or ahead of the Gartner signal. I update this comparison every quarter as Gartner releases new forecast data. Get the next one in your inbox. The 3 widest gaps Gap #1: CASB — 39:1, and the category is disappearing Gartner projects cloud access security brokers reaching $7.1 billion by 2030 at a 24.3% CAGR. Total startup funding since January 2025: $182 million across just 4 companies. Company Total Funding Last Round Lead Investor HQ Founded Reco $85M $30M Series B Zeev Ventures New York 2020 Seraphic Security $44M $29M Series A GreatPoint Ventures Palo Alto / Israel 2020 Nudge Security $35M $22.5M Series A Cerberus Ventures Austin, TX 2021 Spin.AI $18M+ Undisclosed (K1) K1 Investment Mgmt Palo Alto 2017 The gap is structural, not cyclical. Pure-play CASB startups no longer exist as a standalone category. The buying motion has shifted to SASE platforms. Cato Networks raised $409 million in a Series G in June 2025, but that money funds a unified SASE platform spanning CASB, ZTNA, and SD-WAN. For CISOs, the implication is direct. If your CASB requirement is standalone, your vendor options are Netskope, Skyhigh, Forcepoint, and a handful of sub-$50 million startups. Expect fewer competitive bids and less pricing leverage than in categories where VC is abundant. Gap #2: CSPM — 21.5:1, the fastest-growing category is still starved Cloud security posture management is the single fastest-growing category in Gartner’s entire information security forecast. 33.4% growth in 2026. $16.2 billion by 2030 at a 27.6% five-year CAGR. Total startup funding: $752 million across 6 companies. Company Total Funding Last Round Lead Investor HQ Founded Upwind Security $430M $250M Series B Bessemer Venture Partners San Francisco 2022 Noma Security $132M $100M Series B Evolution Equity Partners New York / Tel Aviv 2023 Sentra $100M+ $50M Series B Key1 Capital New York / Tel Aviv 2021 Native Security $42M $31M Series A Ballistic Ventures Tel Aviv / Seattle 2024 Mondoo $32.5M $17.5M Series A Ext HV Capital San Francisco 2020 AccuKnox $15M $4M Venture DreamIt Ventures Menlo Park 2020 Upwind alone accounts for 57% of all CSPM startup capital. It hit unicorn status at a $1.5 billion valuation in January 2026. But one company cannot fill a $16.2 billion market. Alphabet’s $32 billion acquisition of Wiz in March 2026 removed the largest independent cloud security company from the startup market entirely. In my analysis of $3.6 billion in agentic AI security funding, I tracked how M&A is filling gaps that VC has not. CSPM is a category where that pattern is accelerating. Gap #3: Vulnerability Assessment — 20.9:1, the most active seed-stage category Gartner projects vulnerability assessment at $6.4 billion by 2030. Total VC: $306 million across 6 companies. Company Total Funding Last Round Lead Investor HQ Founded Zafran Security $130M $60M Series C Menlo Ventures New York 2022 Seemplicity $82M+ $50M Series B Sienna Venture Capital Tel Aviv 2020 Cogent Security $53M $42M Series A Bain Capital Ventures San Francisco 2024 Nucleus Security $20M+ $20M Series C Undisclosed Tampa, FL 2018 Onit Security $11M $11M Seed Hetz Ventures Tel Aviv 2025 ZAST.AI ~$10M $6M Pre-A Hillhouse Capital Seattle 2024 ▼ GRAPHIC: GRAPHIC 3 — Top funded startups in underfunded categories (insert after Vuln Assess table) ▼ Figure 3: Total funding by startup across the three underfunded categories (CSPM, CWPP, Vulnerability Assessment). This is the category with the most active early-stage investment. Cogent Security and Onit Security both use AI agents for autonomous vulnerability remediation. Zafran tripled ARR since its prior round. The agentic AI thesis is landing hardest in vulnerability management, and the funding trail shows it. Balbix, which had raised $98.6 million, was acquired in November 2025. For CISOs evaluating this category, the vendor field is young and fragmented. Half of the funded companies were founded in 2024 or later. Where VC is ahead of Gartner Three categories show the opposite pattern. In Consent & Preference Management, OneTrust alone has raised $2.1 billion against a $2.0 billion Gartner projection. In Threat Intelligence, $3.16 billion in VC against a $6.9 billion projection, but Dataminr ($1.24B) and ReliaQuest ($1.13B) account for 75% of the total. In ZTNA, Cato Networks’ $1.1 billion alone represents 57% of all category funding. ▼ GRAPHIC: GRAPHIC 4 — Concentration risk donut charts (insert after VC-ahead section) ▼ Figure 4: Single-company concentration in CWPP, ZTNA, and Threat Intelligence funding. The concentration risk matters. Strip out the single largest company in each oversupplied category and the gap ratios invert. Consent without OneTrust: $510 million, Gap Ratio 3.9:1. Threat Intelligence without Dataminr and ReliaQuest: $790 million, Gap Ratio 8.7:1. ZTNA without Cato: $835 million, Gap Ratio 7.7:1. M&A is filling the gaps VC won’t When startups cannot fill the gap, platform vendors acquire. The $3.6 billion in agentic AI security funding and $96 billion in M&A I tracked in March tells this story at scale. Palo Alto Networks assembled $29 billion in acquisitions. ServiceNow spent $11.6 billion. Alphabet closed $32 billion for Wiz. Veeam acquired Securiti.ai for $1.725 billion, removing the leading subject rights automation vendor from the independent market. Forrester’s 2026 cybersecurity budget data confirms the same pattern from the buyer side. Security budgets are growing, but the spend is concentrating in fewer, larger platform purchases. What this means for CISOs In underfunded categories, build internally or accept platform vendor lock-in. CSPM, vulnerability assessment, and CWPP all have Gap Ratios above 12:1. Fewer funded startups means fewer competitive alternatives. If your preferred vendor gets acquired, as Wiz, Securiti.ai, and Balbix all were, your roadmap depends on the acquirer’s priorities, not yours. In oversupplied categories, use the competition for better pricing. ZTNA, threat intelligence, and consent management have abundant VC-backed alternatives. Negotiate harder. Run competitive evaluations with three or more vendors. The funding data tells you which categories give you leverage. Watch for single-company concentration. Chainguard holds 70% of all CWPP startup funding. Cato holds 57% of ZTNA. OneTrust holds 80% of consent management. If any of these companies pivots, gets acquired, or fails, the category funding picture changes overnight. Bottom line Gartner projects $93.2 billion in 2030 spending across the 10 fastest-growing security categories. Venture capital has funded $11.2 billion in startups since January 2025. The 8.3:1 blended gap tells you the overall story. The category-level ratios tell you where to act. Cloud security posture management, vulnerability assessment, and cloud workload protection are growing at 2x to 3x the market average but remain underfunded relative to Gartner’s projections. Two categories, firewall equipment and pure-play CASB, have no startup investment at all. Platform vendors are filling gaps through acquisition at a pace that is reshaping every competitive evaluation. This is the third quarter I have tracked Gartner’s security forecast against independent funding data. The gap between enterprise demand and startup supply keeps widening. Gartner’s 2Q26 forecast lands in July. I will break down the updated Gap Ratios the week it drops. I wrote a shorter editorial take on what these gaps mean for CISO budgets on my Substack. Source: Gartner, Information Security Market Current Outlook, Worldwide, 1Q26 (G00846158), March 2026. Growth rates in constant currency. Dollar figures in current U.S. dollars. Funding data from CB Insights, Crunchbase, PitchBook, Statista. Cross-referenced against company press releases. Analysis by Software Strategies Blog.

The master table: Gartner forecast vs. startup funding by category

I mapped each Gartner category against every cybersecurity startup that raised equity or debt since January 2025. Each company is assigned to one primary category to avoid double-counting. Gap Ratio is the Gartner 2030 market projection divided by total VC raised. Higher means wider gap.

# Gartner Security Category 2025-26 GR 5yr CAGR 2030 Proj Startups Total VC Gap Ratio Verdict
1 Cloud Access Security Brokers (CASB) 27.2% 24.3% $7.1B 4 $182M 39:1 Critical Gap
2 Firewall Equipment (NGFW/FWaaS) 15.9% 9.1% $26.7B 0 $0 Incumbent Lock
3 Cloud Security Posture Mgmt (CSPM) 33.4% 27.6% $16.2B 6 $752M 21.5:1 Underfunded
4 Vulnerability Assessment 15.7% 12.0% $6.4B 6 $306M 20.9:1 Underfunded
5 Cloud Workload Protection (CWPP) 25.9% 21.0% $16.1B 8 $1.28B 12.6:1 Underfunded
6 Subject Rights Request Automation 16.2% 12.3% $2.3B 2 $240M 9.6:1 M&A Absorbed
7 Network Detection & Response (NDR) 15.6% 12.4% $4.1B 4 $701M 5.9:1 Moderate Gap
8 Zero Trust Network Access (ZTNA) 23.0% 20.9% $6.4B 10 $1.94B 3.3:1 VC Ahead
9 Threat Intelligence 27.3% 21.1% $6.9B 12 $3.16B 2.2:1 Oversupplied
10 Consent & Preference Mgmt 22.1% 18.6% $2.0B 7 $2.61B 0.8:1 Oversupplied

Source: Gartner 1Q26 Information Security Market Current Outlook (G00846158, March 2026). Growth rates in constant currency. Funding data from CB Insights, Crunchbase, PitchBook. Analysis by Software Strategies Blog, April 2026.

The table splits cleanly into three tiers. Five categories are underfunded or locked out (Gap Ratio above 9:1). Two sit in the middle. Three are oversupplied or ahead of the Gartner signal.

I update this comparison every quarter as Gartner releases new forecast data. Get the next one in your inbox.

The 3 widest gaps

Gap #1: CASB — 39:1, and the category is disappearing

Gartner projects cloud access security brokers reaching $7.1 billion by 2030 at a 24.3% CAGR. Total startup funding since January 2025: $182 million across just 4 companies.

Company Total Funding Last Round Lead Investor HQ Founded
Reco $85M $30M Series B Zeev Ventures New York 2020
Seraphic Security $44M $29M Series A GreatPoint Ventures Palo Alto / Israel 2020
Nudge Security $35M $22.5M Series A Cerberus Ventures Austin, TX 2021
Spin.AI $18M+ Undisclosed (K1) K1 Investment Mgmt Palo Alto 2017

The gap is structural, not cyclical. Pure-play CASB startups no longer exist as a standalone category. The buying motion has shifted to SASE platforms. Cato Networks raised $409 million in a Series G in June 2025, but that money funds a unified SASE platform spanning CASB, ZTNA, and SD-WAN.

For CISOs, the implication is direct. If your CASB requirement is standalone, your vendor options are Netskope, Skyhigh, Forcepoint, and a handful of sub-$50 million startups. Expect fewer competitive bids and less pricing leverage than in categories where VC is abundant.

Gap #2: CSPM — 21.5:1, the fastest-growing category is still starved

Cloud security posture management is the single fastest-growing category in Gartner’s entire information security forecast. 33.4% growth in 2026. $16.2 billion by 2030 at a 27.6% five-year CAGR. Total startup funding: $752 million across 6 companies.

Company Total Funding Last Round Lead Investor HQ Founded
Upwind Security $430M $250M Series B Bessemer Venture Partners San Francisco 2022
Noma Security $132M $100M Series B Evolution Equity Partners New York / Tel Aviv 2023
Sentra $100M+ $50M Series B Key1 Capital New York / Tel Aviv 2021
Native Security $42M $31M Series A Ballistic Ventures Tel Aviv / Seattle 2024
Mondoo $32.5M $17.5M Series A Ext HV Capital San Francisco 2020
AccuKnox $15M $4M Venture DreamIt Ventures Menlo Park 2020

Upwind alone accounts for 57% of all CSPM startup capital. It hit unicorn status at a $1.5 billion valuation in January 2026. But one company cannot fill a $16.2 billion market.

Alphabet’s $32 billion acquisition of Wiz in March 2026 removed the largest independent cloud security company from the startup market entirely. In my analysis of $3.6 billion in agentic AI security funding, I tracked how M&A is filling gaps that VC has not. CSPM is a category where that pattern is accelerating.

Gap #3: Vulnerability Assessment — 20.9:1, the most active seed-stage category

Gartner projects vulnerability assessment at $6.4 billion by 2030. Total VC: $306 million across 6 companies.

Company Total Funding Last Round Lead Investor HQ Founded
Zafran Security $130M $60M Series C Menlo Ventures New York 2022
Seemplicity $82M+ $50M Series B Sienna Venture Capital Tel Aviv 2020
Cogent Security $53M $42M Series A Bain Capital Ventures San Francisco 2024
Nucleus Security $20M+ $20M Series C Undisclosed Tampa, FL 2018
Onit Security $11M $11M Seed Hetz Ventures Tel Aviv 2025
ZAST.AI ~$10M $6M Pre-A Hillhouse Capital Seattle 2024

 

This is the category with the most active early-stage investment. Cogent Security and Onit Security both use AI agents for autonomous vulnerability remediation. Zafran tripled ARR since its prior round. The agentic AI thesis is landing hardest in vulnerability management, and the funding trail shows it.

Balbix, which had raised $98.6 million, was acquired in November 2025. For CISOs evaluating this category, the vendor field is young and fragmented. Half of the funded companies were founded in 2024 or later.

Where VC is ahead of Gartner

Three categories show the opposite pattern. In Consent & Preference Management, OneTrust alone has raised $2.1 billion against a $2.0 billion Gartner projection. In Threat Intelligence, $3.16 billion in VC against a $6.9 billion projection, but Dataminr ($1.24B) and ReliaQuest ($1.13B) account for 75% of the total. In ZTNA, Cato Networks’ $1.1 billion alone represents 57% of all category funding.

The concentration risk matters. Strip out the single largest company in each oversupplied category and the gap ratios invert. Consent without OneTrust: $510 million, Gap Ratio 3.9:1. Threat Intelligence without Dataminr and ReliaQuest: $790 million, Gap Ratio 8.7:1. ZTNA without Cato: $835 million, Gap Ratio 7.7:1.

M&A is filling the gaps VC won’t

When startups cannot fill the gap, platform vendors acquire. The $3.6 billion in agentic AI security funding and $96 billion in M&A I tracked in March tells this story at scale. Palo Alto Networks assembled $29 billion in acquisitions. ServiceNow spent $11.6 billion. Alphabet closed $32 billion for Wiz. Veeam acquired Securiti.ai for $1.725 billion, removing the leading subject rights automation vendor from the independent market.

Forrester’s 2026 cybersecurity budget data confirms the same pattern from the buyer side. Security budgets are growing, but the spend is concentrating in fewer, larger platform purchases.

What this means for CISOs

In underfunded categories, build internally or accept platform vendor lock-in. CSPM, vulnerability assessment, and CWPP all have Gap Ratios above 12:1. Fewer funded startups means fewer competitive alternatives. If your preferred vendor gets acquired, as Wiz, Securiti.ai, and Balbix all were, your roadmap depends on the acquirer’s priorities, not yours.

In oversupplied categories, use the competition for better pricing. ZTNA, threat intelligence, and consent management have abundant VC-backed alternatives. Negotiate harder. Run competitive evaluations with three or more vendors. The funding data tells you which categories give you leverage.

Watch for single-company concentration. Chainguard holds 70% of all CWPP startup funding. Cato holds 57% of ZTNA. OneTrust holds 80% of consent management. If any of these companies pivots, gets acquired, or fails, the category funding picture changes overnight.

Bottom line

Gartner projects $93.2 billion in 2030 spending across the 10 fastest-growing security categories. Venture capital has funded $11.2 billion in startups since January 2025. The 8.3:1 blended gap tells you the overall story. The category-level ratios tell you where to act.

Cloud security posture management, vulnerability assessment, and cloud workload protection are growing at 2x to 3x the market average but remain underfunded relative to Gartner’s projections. Two categories, firewall equipment and pure-play CASB, have no startup investment at all. Platform vendors are filling gaps through acquisition at a pace that is reshaping every competitive evaluation.

This is the third quarter I have tracked Gartner’s security forecast against independent funding data. The gap between enterprise demand and startup supply keeps widening. Gartner’s 2Q26 forecast lands in July. I will break down the updated Gap Ratios the week it drops. I wrote a shorter editorial take on what these gaps mean for CISO budgets on my Substack.

Source: Gartner, Information Security Market Current Outlook, Worldwide, 1Q26 (G00846158), March 2026. Growth rates in constant currency. Dollar figures in current U.S. dollars. Funding data from CB Insights, Crunchbase, PitchBook, Statista. Cross-referenced against company press releases. Analysis by Software Strategies Blog.

 

Gartner’s $246.2B Security Forecast shows 10 categories growing 2x to 3x the market

$30.6 billion in new security spending in a single year. Gartner's 1Q26 Information Security forecast projects $246.2 billion in 2026 spending across 41 categories. Cloud Security Posture Management leads at 33.4% growth, followed by Threat Intelligence at 27.3% and Cloud Access Security Brokers at 27.2%. Two legacy categories are declining. I analyzed the full dataset to rank the 10 fastest-growing categories by growth rate and what they mean for CISO budgets.

Read more

$3.6 Billion in Crunchbase funding, $96 Billion in M&A, and 10 Agentic AI security startups Reshaping 2026

Palo Alto Networks spent $29 billion acquiring three companies. ServiceNow spent $11.6 billion on three more. Alphabet paid $32 billion for Wiz. The startups building agentic AI defenses raised $3.6 billion. Total MCP security funding for 17,000+ deployed servers: $40 million. Then RSAC 2026 happened.

Read more

Gartner’s $244.2B security forecast shows enterprises spend 17x more on AI tools than securing AI itself

Inside the $244.2 billion security market: agentic AI adoption outpaces defenses 8 to 1, cloud security grows at 28.8%, and enterprises spend 17x more on AI tools than on securing the AI itself

Gartner forecasts worldwide AI spending will reach $2.52 trillion in 2026, a 44% increase year-over-year. Worldwide IT spending will hit $6.15 trillion. Within that massive build-out, information security spending accelerates to $244.2 billion, up 13.3%.

The headline looks healthy. Look closer, and it isn’t. I’ve been tracking Gartner’s information security forecast through multiple quarterly updates, and the trajectory keeps steepening. But the spending acceleration is masking a deeper problem: enterprises are deploying AI agents into production far faster than they are securing them.

  1. The 40% / 6% gap

Gartner predicts 40% of enterprise applications will include task-specific AI agents by the end of 2026. Up from less than 5% in January. These are not chatbots. Gartner’s examples include autonomous cybersecurity response agents that scan network traffic, analyze system logs, and initiate responses without human intervention.

Only roughly 6% of organizations report having an advanced AI security strategy in place, according to vendor-sourced research from BigID’s 2025 AI Risk and Readiness study. Even adjusting for methodology differences between vendor and analyst research, the gap is stark. Agents are entering production at roughly 7-8x the rate organizations are building governance around them.

Gartner’s 4Q25 AI spending forecast created a dedicated agentic AI market segment for the first time. The spending lines are dramatic. Agentic AI overtakes chatbot and assistant spending by 2027. By 2029, agentic AI will reach $752.7 billion at a 119% compound annual growth rate. Chatbot spending peaks at $264.7 billion, then declines. That crossover point is where the security model breaks, because chatbots operate within human-supervised sessions. Agents don’t.

Gartner named agentic AI oversight the number-one cybersecurity trend for 2026 in its February report (my breakdown of all six trends here). A separate Gartner poll of 147 CIOs found 24% had already deployed AI agents and 50% were actively experimenting. Guardian agents, AI systems designed to monitor and govern other AI agents, are projected to capture 10-15% of the agentic AI market by 2030.

Forrester’s 2026 cybersecurity predictions go further: an agentic AI deployment will cause a publicly disclosed data breach this year, leading to employee dismissals. Senior analyst Paddy Harrington frames it as a cascade of failures, not a single point of error. That prediction landed in October 2025. Nothing since has made it less likely.

  1. $244.2 billion, and where it goes

Gartner’s 4Q25 information security forecast projects global spending reaching $244.2 billion in 2026, up 13.3% year-over-year. That is acceleration, not continuation. Gartner’s forecast trajectory has been steepening for multiple quarters. It follows a year where many CISOs focused on consolidating tools rather than buying new ones.

The allocation matters more than the total (please click on the graphic to expand for easier reading):

Cloud security at 28.8% growth is the fastest subsegment by a wide margin. CSPM alone carries a 31.3% CAGR. These represent organizations reacting to attack surfaces that expanded when workloads moved to the cloud faster than security controls followed.

Managed security services at 11.1% tells a workforce story the spending headline misses. The ISC2 documented a global cybersecurity workforce gap of 4.8 million professionals in October 2024. That gap grew 19% year-over-year while the active workforce flatlined at 5.5 million. A quarter of organizations reported cybersecurity layoffs. So they’re buying SOC capacity from managed providers instead. The spending growth in managed services is a staffing problem wearing a procurement mask.

The 17:1 spending asymmetry

Gartner’s 4Q25 AI spending forecast splits the AI cybersecurity market into two sub-segments for the first time. AI-amplified security, using AI to defend the enterprise, reached $49 billion in 2025. Securing AI itself, protecting the models, training data, inference pipelines, agent workflows, and decision outputs, stood at $2.8 billion. That is 5.5% of the AI cybersecurity market.

Enterprises are investing 17 times more in AI-powered security tools than in securing the AI on which those tools run. Gartner projects over 75% of enterprises will use AI-amplified cybersecurity products by 2028, up from less than 25% in 2025. The tools are getting funded. What the tools actually depend on to function is not.

  1. Quantum crosses the 5% budget threshold

Forrester predicts quantum security spending will exceed 5% of overall IT security budgets in 2026. Five percent sounds modest until you consider what it represents: the shift from research line items to actual procurement.

That means consulting engagements for quantum migration planning. Cryptographic discovery tools to figure out which systems need replacing first. Post-quantum algorithm testing across live production environments. Gartner calls post-quantum cryptography a force that demands organizations identify, manage, and replace traditional encryption methods now. Not eventually. The encryption market is growing at 2.0x according to the 4Q25 forecast, and the planning horizon is 2030. Starting migration in 2028 means compounding rip-and-replace costs every quarter of delay.

Forrester also predicts the EU will establish its own known exploited vulnerability database in 2026. Regulatory fragmentation adds cost. For enterprises operating across jurisdictions, quantum migration planning cannot be separated from compliance architecture.

  1. 57% of employees are already using shadow AI

A smaller Gartner survey of 175 employees conducted between May and November 2025 found that 57% use personal GenAI accounts for work. A third admitted to uploading sensitive information to tools their organizations have not sanctioned.

I keep coming back to this stat because it reframes the entire agentic AI security conversation. The firewalls most enterprises rely on were built for human-to-application communication. Protocols like MCP now enable agent-to-agent interaction at a scale and speed those tools were never designed to see. Machine identities outnumber human employees by more than 80 to 1 in most enterprises, according to CyberArk. Traditional IAM was not built for nonhuman actors operating autonomously.

Gartner’s cybersecurity trends report identifies IAM adaptation for AI agents as a top-six trend for 2026, specifically calling out identity registration, credential automation, and policy-driven authorization for machine actors. Failure to address these issues will lead to greater access-related cybersecurity incidents as autonomous agents become more prevalent.

The investment context: AI in the trough, security in the gap

Gartner places AI in the Trough of Disillusionment throughout 2026. AI will most often be sold by incumbent software providers rather than bought as part of new moonshot projects. ROI predictability has to improve before enterprises scale their deployments.

Forrester’s 2026 predictions reinforce this: enterprises will defer 25% of planned AI spending into 2027 as financial rigor slows production deployments and kills proofs of concept. Fewer than one-third of decision-makers can tie AI value to their organization’s financial growth.

Yet Gartner’s IT spending forecast shows server spending accelerating at 36.9% year-over-year and data center spending surging 31.7% past $650 billion. GenAI model spending grows at 80.8%. The infrastructure build-out is not slowing even as enterprise application adoption pauses.

Infrastructure spending runs hot. Application-layer AI spending cools. Security spending accelerates into the gap between adoption speed and governance readiness. The $244.2 billion flowing into information security is the cost of operating in an environment where AI agents are proliferating faster than the controls designed to govern them.

What these numbers add up to

For two decades, enterprise security assumed a human on the other end of every session, every credential request, every decision. That assumption is collapsing. The autonomous agent accessing your production database at 3 AM doesn’t authenticate the way your SOC analyst does, doesn’t respect the same governance boundaries, and operates at speeds no human reviewer can match.

What makes this moment different from previous security inflection points is the speed asymmetry. When cloud migration created new attack surfaces, enterprises had years to adapt. The shift from on-prem to cloud took a decade. The shift from human-operated to agent-operated environments is measured in quarters. Gartner didn’t even have a dedicated agentic AI spending segment until this forecast cycle. By the next one, the crossover will have already happened.

The practical question for 2026 is not whether to invest in AI security. That decision has been made by the spending trajectory. It is whether to govern AI agents proactively, before the first publicly disclosed agentic breach forces a reactive scramble, or to wait and pay the premium that every late mover in cybersecurity history has paid. Forrester has already predicted which outcome is more likely this year. The 17:1 ratio suggests most enterprises are betting on the wrong side of that question.

Sources

Gartner Forecast: Information Security, Worldwide, 2023–2029, 4Q25 (December 18, 2025)

Gartner Forecast Analysis: Information Security, Worldwide, 2026 (February 5, 2026)

Gartner Forecast: AI Spending, Worldwide, 2024–2029, 4Q25 (December 2025)

Gartner, Top Trends in Cybersecurity for 2026 (February 5, 2026)

Gartner, Worldwide AI Spending Will Total $2.52 Trillion in 2026 (January 15, 2026)

Gartner, Worldwide IT Spending to Grow 10.8% in 2026 (March 2026)

Gartner, 40% of Enterprise Apps Will Feature AI Agents by 2026 (August 26, 2025)

Gartner, Guardian Agents Will Capture 10-15% of Agentic AI Market by 2030 (June 11, 2025)

Forrester Predictions 2026: Cybersecurity and Risk (October 28, 2025)

Forrester, Global Tech Spend Will Grow 7.8% in 2026 (February 2, 2026)

Forrester, 2026 Technology & Security Predictions (October 28, 2025)

ISC2, 2024 Cybersecurity Workforce Study (October 2024)

CyberArk, Machine Identities Report (April 2025)

BigID, AI Risk & Readiness in the Enterprise (2025)

Roundup of agentic AI forecasts and market estimates, 2026

Roundup of agentic AI forecasts and market estimates, 2026

Agentic AI spending is projected to reach $201.9 billion in 2026 (Gartner), overtaking chatbot spending by 2027.  Four independent firms size the standalone market at $7–8 billion with 40%+ CAGRs. But adoption lags the money: only 23% of organizations have scaled agent deployments (McKinsey), and 40% of projects face cancellation by 2027 (Gartner).

Fortune Business Insights projects $7.29 billion in 2025, reaching $139.19 billion by 2034 at 40.5% CAGR. Precedence Research sizes it at $7.55 billion in 2025, growing to $199.05 billion by 2034 at 43.84% CAGR. MarketsandMarkets puts the figure at $7.06 billion in 2025, reaching $93.20 billion by 2032 at 44.6% CAGR. Deloitte’s TMT Predictions 2025 estimates $8.5 billion in 2026, growing to $35 to $45 billion by 2030.

Every major forecast agrees on direction. None agrees on scale. The standalone agentic AI market lands between $7 billion and $8.5 billion. Gartner’s broader view, counting agentic capabilities embedded across enterprise software, reaches $201.9 billion in 2026. That 25x gap is not a contradiction. It is a measurement problem, and the takeaways below reflect both realities. The following are the key takeaways from agentic AI forecasts published in 2026 so far:

Key takeaways

Worldwide AI spending will reach $2.52 trillion in 2026, growing 44% year-over-year. That number jumped roughly $500 billion from the September forecast, which had pegged the market just above $2 trillion. Infrastructure takes $1.37 trillion, 54% of total spend. AI software follows at $452.5 billion, up 60%. AI services add $588.6 billion. AI-optimized servers alone account for $421.6 billion, growing to 49%. Gartner expects spending to grow by another 30% in 2027 and surpass $3 trillion. I have tracked these forecasts through multiple iterations. The revisions keep going in one direction. Source: Gartner press release, January 15, 2026

 

Gartner projects $4.71 trillion in global AI spending by 2029. The fastest growth isn’t in infrastructure. Synthetic data generation leads all categories at 178% CAGR, followed by the broader AI Data market at 155%. Agentic AI compounds at 119%, expanding from $15 billion to $753 billion by 2029. AI Infrastructure, the largest category by dollars, grows at just 29%. The money is following the bottlenecks. Source:  Gartner 4Q25: $4.71T AI Market Proves Agentic AI and Data Readiness Are the Only Race That Matters, Software Strategies Blog, January 22, 2026 Link: https://softwarestrategiesblog.com/2026/01/22/gartner-4q25-agentic-ai-data-readiness-4-71t-market/

 

The AI cybersecurity market is predicted to hit $51.3 billion in 2026, nearly doubling from $25.9 billion in 2025. But the category masks a structural imbalance. AI-amplified security, where AI defends the enterprise, captures 94.5% of spending at $48.5 billion. Securing AI, where the enterprise defends its own AI systems, gets $2.8 billion. Enterprises are investing 17x more in using AI as a security tool than in protecting the AI itself. Both sub-segments grow at similar CAGRs (74% vs. 72%), which means the dollar gap widens every year. By 2029, AI-amplified security reaches $160.4 billion, while securing AI hits just $11.6 billion. One is a tool. The other is the thing that needs protecting. Source: Gartner Forecasts Agentic AI Will Overtake Chatbot Spending by 2027, Software Strategies Blog, February 16, 2026 Link: https://softwarestrategiesblog.com/2026/02/16/gartner-forecasts-agentic-ai-overtakes-chatbot-spending-2027/

 

AI Data sits alone in the upper-right quadrant of Gartner’s spending map, compounding at 155% CAGR with 277% growth in 2026. AI Cybersecurity and AI Models cluster above 67% CAGR. AI Infrastructure anchors the chart as the largest bubble, but grows at just 29%. Global AI spending reaches $1.8 trillion in 2025 and $4.7 trillion by 2029. The acceleration is not in compute. It is in data readiness, security architecture, and agentic capabilities. By 2028, software with agentic capabilities crosses 50% of total application software spend, up from 2% in 2024. Non-agentic software spending starts declining in 2027. Source:Data Readiness and Security Are Driving AI’s $4.7 Trillion Run, Software Strategies Blog, December 22, 2025 Link: https://softwarestrategiesblog.com/2025/12/22/data-readiness-security-driving-ai-4-7-trillion/

Gartner’s AI spending forecast reaches $2.53 trillion in 2026 and $4.71 trillion by 2029. Eight markets. One pattern. AI Infrastructure dominates absolute dollars at $1.37 trillion in 2026 but grows at just 29% CAGR. AI Data, the smallest segment at $3.1 billion, compounds at 155%. AI Cybersecurity nearly doubles to $51.3 billion. AI Software hits $452.5 billion, growing 60% year-over-year as agentic capabilities reshape the category. The growth rates tell you where the bottlenecks are breaking. Source: Data Readiness and Security Are Driving AI’s $4.7 Trillion Run, Software Strategies Blog, December 22, 2025 Link: https://softwarestrategiesblog.com/2025/12/22/data-readiness-security-driving-ai-4-7-trillion/

Nearly nine in ten organizations now use AI in at least one business function, up from 78% a year ago, but nearly two-thirds have not begun scaling it across the enterprise. Only 6% qualify as high performers where AI contributes more than 5% to EBIT. Sixty-two percent of organizations are at least experimenting with AI agents, yet in no individual business function are more than 10% scaling them. High performers are three times more likely than peers to fundamentally redesign workflows and three times more likely to have senior leaders demonstrating ownership of AI initiatives. More than one-third of high performers commit over 20% of their digital budgets to AI, and about three-quarters have reached the scaling phase, versus one-third of other organizations. Source: McKinsey / QuantumBlack, The state of AI in 2025: Agents, innovation, and transformation, November 2025

Valued at $638.23 billion in 2024, the global AI market is projected to reach $3,680.47 billion by 2034, expanding to a CAGR of 19.20%. North America holds 31.80% market share. The software segment dominates at 51.40%, while machine learning leads by technology at 36.70%. Healthcare is expected to record the highest CAGR of 36.50% across end-use segments. Among regions, Asia-Pacific is expected to grow at 19.8% CAGR from 2025 to 2034, with AI projected to add up to $3 trillion to the region’s GDP by 2030, driven by national AI strategies in China, India, and Japan. Source: Precedence Research, AI Market Size, Growth & Trends, September 2025

Nearly $7 trillion. That’s the capital outlay data centers will require by 2030 to keep pace with demand for compute power. Of that, $5.2 trillion goes toward AI-ready facilities and $1.5 trillion toward traditional IT workloads. Global demand for data center capacity could almost triple by 2030, with about 70% of new demand coming from AI workloads. Three investment scenarios range from $3.7 trillion (constrained demand) to $7.9 trillion (accelerated demand, adding 205 incremental GW). The 60% majority of investment—$3.1 trillion—flows to technology developers and designers producing chips and computing hardware. Source: McKinsey, The cost of compute: A $7 trillion race to scale data centers, April 2025

Inference already consumed half of all AI compute in 2025. That number will grow to two-thirds in 2026 and reach 75% of all AI compute needs by 2030. Global data center capacity is projected to nearly double from 103 gigawatts to 200 GW by 2030, yet U.S. data centers already face a capacity shortfall exceeding 11 GW, with the cumulative gap expected to exceed 40 GW by 2028. North American data center capacity alone will increase eightfold, from 5.6 GW in 2024 to 44 GW by 2030. Operators are increasingly deploying edge facilities closer to end users to reduce latency as inference-dominated workloads drive a fundamental redesign of data center architectures. Source: Avid Solutions, 13 Data Center Growth Projections, January 2026

 

Generative AI could add the equivalent of $2.6 trillion to $4.4 trillion annually to the global economy, increasing the projected impact of all AI by 15 to 40%. About 75% of the value falls across four areas: customer operations, marketing and sales, software engineering, and R&D. Half of today’s work activities could be automated between 2030 and 2060, with a midpoint in 2045—roughly a decade earlier than previously estimated. When embedding effects in existing software are included, the total economic benefit rises to $6.1 trillion to $7.9 trillion annually. Source: McKinsey, The economic potential of generative AI, June 2023

The global AI market hit $294.16 billion in 2025 and is projected to grow to $2,480.05 billion by 2034, at a CAGR of 26.60%. The Banking, financial services and insurance (BFSI) segment holds 18.90% market share, while healthcare is expected to record the highest CAGR of 36.50%. In the U.S. alone, the AI market was estimated at $146.09 billion in 2024 and is predicted to reach $851.46 billion by 2034. The number of AI companies funded globally in 2024 totaled 2,049, with U.S.-funded companies accounting for 1,143, signaling strong investor confidence in the sector’s expansion potential. Source: Fortune Business Insights, AI Market Size, Growth & Trends by 2034

Big Tech’s AI capex hit $405 billion in 2025, up from a $250 billion estimate at the start of the year. Sell-side analysts have underestimated AI spending every quarter for two years running. A decade ago, Big Tech’s trailing-twelve-month capex was $24 billion—15x less than today. AI data center costs are projected at $3 trillion to $8 trillion, with gigawatt capacity expected to grow 3.5x by 2030. Source: IO Fund, Big Tech’s $405B Bet, November 2025

The global AI market was valued at $371.71 billion in 2025 and is projected to reach $2,407.02 billion by 2032, growing at a CAGR of 30.6%. Hyperscalers accounted for 53% of chip purchases in 2023, spurring 156% market growth from 2023 to 2024. While demand from hyperscalers is expected to moderate, growth of 41% is still forecast from 2025 to 2026. Enterprises are moving from cloud reliance to in-house AI infrastructure investments, particularly for cost-effective inference solutions, as edge AI gains traction through AI-enabled PCs and mobile devices. Source: Markets and Markets, AI Market Report 2025-2032

At $602 billion projected for 2026, hyperscaler capex has entered uncharted territory. Amazon, Microsoft, Google, and Meta will each exceed $100 billion individually, pushing capital intensity to 45-57% of revenue. Total hyperscaler capex from 2025-2027 is projected at $1.15 trillion, more than double the $477 billion spent from 2022-2024. Morgan Stanley and JP Morgan suggest the technology sector may need to issue $1.5 trillion in new debt over the next few years to finance AI infrastructure construction. The sheer scale of debt issuance mirrors patterns seen during the fiber-optic buildout of the late 1990s. Source: Multiple sources compiled by Introl, January 2026

The number of software companies using consumption-based pricing more than doubled between 2015 and 2024, as AI introduces new variable costs that make traditional perpetual licenses obsolete. SaaS remains dominant, but the next wave is outcome-aligned pricing that scales with actual AI usage. Software businesses that successfully adopt consumption-based pricing aligned with usage and outcomes may be better positioned to capture AI-driven value and differentiate themselves in a rapidly evolving market where the cost of each AI inference adds a new variable to the P&L. Source: McKinsey, AI adjusts the software bill, January 27, 2026

Data center capacity needs for AI and non-AI workloads could almost triple by 2030, with AI capacity increasing 3.5 times and making up roughly 70% of the total. Under a continued-momentum scenario, total capacity demand rises from 82 GW in 2025 to 219 GW by 2030, with incremental AI capacity ranging from 13 GW in 2025 to 31 GW in 2030, totaling 124 GW of new AI capacity. Non-AI workloads grow from 38 GW to 64 GW over the same period. Average power densities in AI-ready data centers have more than doubled in just two years and are expected to rise nearly four times by 2027. Source: McKinsey, Data center demands (Week in Charts), May 2025

U.S. data-center spending exceeded half a trillion dollars in 2025. The U.S. and China drove a massive expansion in AI-related computing capacity through 2024, with the U.S. pulling further ahead in the first half of 2025. AI-related trade accounted for nearly half of all merchandise trade growth in that period, despite representing only 15% of total trade volume. The infrastructure boom is reshaping international commerce, with surging demand for servers, graphics cards, and related components essential to AI training and inference now a dominant force in global supply chains. Source: Federal Reserve Board, FEDS Notes: The Global Trade Effects of the AI Infrastructure Boom, February 2026

The generative AI market is expanding from $71.36 billion in 2025 to $890.59 billion by 2032, at a CAGR of 43.4%. North America accounted for 43.05% of global revenue in 2025. Text remains the dominant data modality due to its foundational role in enterprise workflows, while the services segment is gaining traction for scalability and cost-effectiveness. Foundation model delivery platforms verticalized adoption across industries, and the rapid scaling of AI-native infrastructure are the three key forces driving the market as of 2025. The 43.4% CAGR makes this one of the fastest-expanding technology subsegments in history. Source: MarketsandMarkets, Generative AI Market Report, Global Forecast to 2032

The generative AI market reached $37.89 billion in 2025 and is projected to hit $1.2 trillion by 2035, a 37% compound annual growth rate. Transformer architectures account for more than 42% of technology revenue, driven by text-to-image and text-to-video applications. Software captures over 65% of total revenue. North America holds 41% of the market. Asia-Pacific is the fastest-growing region at a 27.6% CAGR through 2035. Financial services is expected to lead sector growth at 36.4%, fueled by fraud detection, risk management, and regulatory compliance demands. Source: Precedence Research, Generative AI Market Size, January 2026

GPUs captured 89% of AI processor revenue in 2025, but FPGA and ASIC alternatives are growing at a 17% CAGR through 2031. Hardware accounted for 68% of all AI infrastructure spending last year. North America held 40% of the market, backed by $52.7 billion in CHIPS Act grants and hyperscalers operating roughly 60% of global AI compute capacity. Liquid cooling reached 18% of AI server racks as power densities crossed 100 kilowatts per rack, the threshold where air cooling fails. Asia-Pacific is projected to grow fastest at 16.4% CAGR through 2031, driven by China’s $50 billion semiconductor fund and $15 billion in hyperscaler commitments across India. Source: Mordor Intelligence, AI Infrastructure Market Size, Trends & Growth Drivers 2031

Nearly one in four Americans has already made a purchase through AI. Morgan Stanley Research estimates agentic shoppers will drive $190 billion to $385 billion in U.S. e-commerce spending by 2030, capturing 10% to 20% of market share. Grocery and consumer packaged goods lead adoption, with 49% of AI-assisted buyers transacting in those categories. AI shopping agent users are projected to reach 126 million by 2030, up from near zero today, while traditional e-commerce users decline from 264 million to 149 million over the same period. Source: Morgan Stanley Research, Agentic Commerce Market Impact Outlook, December 2025 Link: https://www.morganstanley.com/insights/articles/agentic-commerce-market-impact-outlook

Gartner forecasts agentic AI will overtake chatbot spending by 2027

 

Agentic AI spending grows 141% in 2026 to $201.9 billion. By 2027, it will overtake chatbot and assistant spending for the first time. Then chatbot spending starts declining. I’ve tracked Gartner’s AI forecasts through multiple iterations. This crossover changes where security risk concentrates for every security professional reading this.

The crossover is in the segment-level data tables of Gartner’s Forecast: AI Spending, Worldwide, 2024–2029, 4Q25. The headline number is well known: $2.53 trillion in 2026, $4.7 trillion by 2029 at 33% CAGR. The segment breakdowns are not. Eight markets. Nineteen sub-segments. The sub-segment data tells a different story than the top line.

This is Gartner’s first dedicated AI spending forecast, and I’ve been waiting for it. Gartner states that comparisons to previous AI estimates are not meaningful because the scope widened, adding AI cybersecurity, agentic AI as a separate segment from chatbots, AI data technology, and expanded infrastructure coverage. Gartner writes, “This is the first iteration of the forecast on AI spending that Gartner has published. Gartner has significantly expanded and modified its AI forecast coverage. Spending comparisons to previous iterations are therefore not meaningful as the scope has widened. This includes both coverage of new markets and broadened definitions of the types of AI spending that are reflected in some market segments.”

Forrester’s Predictions 2026: Cybersecurity and Risk arrives at the same warning from a different angle: an agentic AI deployment will cause a publicly disclosed breach in 2026, leading to employee dismissals. Two firms. Same conclusion. The spending data explains why.

CAPTION: Total worldwide AI spending, 2024–2029. $1.14T to $4.71T. 33% CAGR. Growth decelerates from 54% (2025) to 16% (2029) as the base expands. Source: Gartner Forecast: AI Spending, 4Q25 (December 2025).

The full market breakdown

AI infrastructure dominates at $1.37 trillion, 54% of the total. AI software follows at $452.5 billion, growing 60% year-over-year. AI services add $588.6 billion. AI cybersecurity and AI data are the outliers: growing at 74% and 155% CAGR, respectively, rates that dwarf everything else in the forecast.

Source: Gartner Forecast: AI Spending, Worldwide, 2024–2029, 4Q25 (December 19, 2025). All figures in U.S. dollars. CAGR = 2024–2029. Gartner press release: https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026

Infrastructure takes 54% of every AI dollar

AI-optimized servers alone account for $421.6 billion in 2026, growing to $699.7 billion by 2029. AI processing semiconductors add $289.4 billion. AI-optimized IaaS hits $38.3 billion at 71% CAGR, the fastest-growing infrastructure sub-segment. AI network fabric, a new category in this forecast, reaches $28.7 billion.

Infrastructure’s share drops from 54% to 48% by 2029 as software and services scale faster. The capital-intensive build-out phase is not over.

The agentic crossover nobody is planning for

Gartner now splits AI software into chatbots/assistants and agentic AI. The spending lines cross in 2027.

CAPTION: Agentic AI spending overtakes chatbot/assistant spending by 2027. Chatbots peak at $264.7B then decline. Agentic AI grows at 119% CAGR to $752.7B by 2029. Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). AI Software segment, Table 1-2.

Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). CAGR = 2024–2029.

Chatbots talk to people. Agents act on behalf of people. They access databases, execute transactions, chain multi-step workflows without human approval at each step. The attack surface has moved well beyond conversation windows. Agents are autonomous decision engines with production access.

Gartner’s Top Trends in Cybersecurity for 2026 lists agentic AI oversight as the number-one trend. Forrester’s Predictions 2026: Cybersecurity and Risk goes further: an agentic AI deployment will cause a public breach this year, and employees will lose their jobs for it. Forrester senior analyst Paddy Harrington calls it a “cascade of failures,” not a single point of error. Two analyst firms. Different methodologies. Same conclusion. Security strategies built for chatbot-era risk have a shelf life measured in quarters, not years.

AI cybersecurity is two markets, not one

Gartner created a dedicated AI cybersecurity market for the first time in this forecast. It nearly doubles in 2026. But the category name hides a structural split that matters more than the growth rate.

Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). CAGR = 2024–2029.

Two sub-segments. Two very different problems.

AI-amplified security ($48.5 billion, 94.5% of the market) is what most enterprises mean when they say “AI cybersecurity.” This is AI working for your security team. Machine learning models that analyze network traffic patterns and flag anomalies faster than a human analyst can. Natural language processing that reads threat intelligence feeds and correlates indicators of compromise across millions of data points in seconds. Automated triage systems that prioritize which of the 11,000 daily alerts actually need a human response. AI-powered endpoint detection that identifies malware variants that signature-based tools miss. Behavioral analytics that learn what normal looks like for each user and flag deviations. Security orchestration platforms that automate incident response playbooks, reducing mean time to containment from hours to minutes.

This is the category where enterprises are spending aggressively. And for good reason. The math on analyst workloads demands it. Security operations centers are drowning in alerts, facing a persistent talent shortage, and defending attack surfaces that expand every quarter. AI-amplified tools address all three.

Securing AI ($2.8 billion, 5.5% of the market) is the other problem. AI-amplified security puts AI to work defending the enterprise. Securing AI reverses the relationship entirely — defending the AI itself. Protecting the models, the training data, the inference pipelines, the agent workflows, and the decision outputs that enterprises are deploying at $2.53 trillion in 2026. Prompt injection defenses. Model access controls. Training data poisoning detection. Output validation. Agent permission boundaries. Audit trails for autonomous decisions.

The distinction matters because they protect different things. AI-amplified security protects your enterprise using AI. Securing AI protects the AI itself. One is a tool. The other is the thing that needs protecting. Enterprises are investing 17 times more in the tool than in protecting the thing the tool runs on.

Shadow AI is not just employees using ChatGPT

Gartner names the mechanism driving AI software growth: vendor push. Software providers are integrating GenAI and agentic AI into existing product lines. AI software grows from $143 billion in 2024 to $981 billion by 2029 at 47% CAGR.

For CISOs, vendor push changes the equation. AI capabilities are being added to tools already in production. Often without explicit procurement decisions. The AI features embedded in your existing ERP, CRM, and developer platforms may already exceed what your security team has inventoried. Shadow AI is vendors activating AI inside products you already own.

The smallest market with the biggest growth rate

AI data technology: $134 million in 2024. $3.1 billion in 2026. $14.6 billion by 2029. The 155% CAGR is the highest in the forecast. The 277% year-over-year growth in 2026 is the steepest single-year jump of any segment.

Synthetic data generation is the standout sub-segment, going from $41 million to $6.8 billion by 2029. Gartner is direct: enterprises need AI-ready data with proper labeling, quality checks, and compliance. For organizations running AI projects on ungoverned data, the readiness gap compounds every quarter.

CAPTION: AI spending markets ranked by five-year CAGR. AI Data (155%) and AI Cybersecurity (74%) lead. AI Infrastructure is the largest by absolute dollars. Source: Gartner Forecast: AI Spending, 4Q25 (December 2025).

Indirect services are the governance blind spot

Indirect AI services, where AI is a supporting component in a larger project, grow from $78.4 billion in 2024 to $255.9 billion in 2026 at 50% CAGR. Direct AI services hit $332.8 billion. By 2028, indirect overtakes direct.

Indirect AI means capabilities embedded in consulting and implementation projects that procurement does not classify as AI. If you cannot see it in your AI inventory, you cannot govern it.

Servers are a bigger market than AI software

AI-optimized servers alone hit $421.6 billion in 2026, just below the entire AI software market at $452.5 billion. By 2029, servers reach $699.7 billion. Cloud providers are building capacity for AI workloads that have not materialized at scale. The infrastructure is ahead of the applications.

The enterprise agentic stack is showing up in spending data

Gartner’s DSML segment includes a dedicated agent builder platforms sub-segment at $5.0 billion in 2026, reaching $13.7 billion by 2029. AI observability and governance adds $1.3 billion, growing to $4.0 billion. The xOps sub-segment (MLOps, DataOps, ModelOps) is the largest at $15.0 billion.

Together, these form the tooling layer for building, monitoring, and governing agents in production. The enterprise agentic stack is materializing in the spending data. Most organizations have not formalized it in their architecture.

The numbers that belong in your next board deck

If you take one thing from this forecast into a budget meeting, take this table. I built it from the raw spreadsheet data. Six years of AI deployment spending next to AI security spending. The bottom row is the one that gets the questions.

Source: Gartner Forecast: AI Spending, 4Q25 (December 2025). All percentages derived from Gartner’s published data tables (Tables 1-1 and 1-2).

The ratio improves over time. Securing AI goes from 0.07% in 2024 to 0.25% by 2029. But watch the absolute numbers. In 2029, enterprises will spend $4.71 trillion deploying AI and $11.6 billion securing it. The percentage gets better. The dollar gap gets wider. Every year, the market grows its way into a larger exposure.

Where I think this lands

Three things worth tracking from the segment data:

The agentic crossover. Agentic AI overtakes chatbot spending in 2027. The enterprise risk profile shifts from conversational data leakage to autonomous decision-making at scale. CISOs who build agentic governance frameworks in 2026 position themselves before the inflection. The spending curve says the window is narrowing.

The securing-AI gap. $2.8 billion to protect AI systems in a year when $2.53 trillion deploys them. Enterprises are enthusiastic about using AI for defense. The investment in defending AI itself has not caught up.

Data readiness is the bottleneck. The 277% growth in AI data spending confirms that AI without governed data delivers diminished returns. Data classification investments directly enable or constrain AI ROI.

If your security budget is growing at 12% and AI deployment inside your enterprise is growing at 44%, the gap compounds every quarter. You cannot close it by holding steady. The organizations getting this right treat AI security as a proportion of AI deployment, not a fixed line item.

Sources

Gartner, Forecast: AI Spending, Worldwide, 2024–2029, 4Q25, December 19, 2025, ID G00843179.

Gartner press release (January 15, 2026): https://www.gartner.com/en/newsroom/press-releases/2026-1-15-gartner-says-worldwide-ai-spending-will-total-2-point-5-trillion-dollars-in-2026

Gartner, Top Trends in Cybersecurity for 2026 (February 5, 2026): https://www.gartner.com/en/newsroom/press-releases/2026-02-05-gartner-identifies-the-top-cybersecurity-trends-for-2026

Gartner, IT Spending Forecast 1Q26 (February 3, 2026): https://www.gartner.com/en/newsroom/press-releases/2026-02-03-gartner-forecasts-worldwide-it-spending-to-grow-10-point-8-percent-in-2026-totaling-6-point-15-trillion-dollars

Forrester, Predictions 2026: Cybersecurity and Risk (October 2025): https://www.forrester.com/blogs/predictions-2026-cybersecurity-and-risk/

All dollar figures in U.S. dollars. Growth rates and CAGR derived from Gartner’s published data tables (Tables 1-1 and 1-2).