Skip to content

Posts tagged ‘agentic AI security’

Gartner’s AI security forecast exposes 162x services growth that still trails software 2 to 1 in new spending

Gartner AI-amplified security forecast, growth multiple versus net-new dollars by segment, 2024 to 2030

Growth multiple versus net-new dollars added, 2024 to 2030. The segment ranking inverts between the two measures.

Every chart and table in this analysis opens full size when you click it.

Security services inside Gartner’s AI-amplified security market were worth $364 million in 2024. Gartner now projects $59 billion by 2030. That is 162 times larger in six years, compounding at 133.5% annually, the steepest curve anywhere in the forecast. I have tracked this forecast through every quarterly update, and no segment has ever moved like this one.

What Is AI-Amplified Security?

Gartner’s term for the share of existing security spending flowing to products with AI built in. Endpoint protection, firewalls, identity, and network security that now embed AI-driven detection, autonomous remediation, and agent-based response. Not a new category. Existing budgets redirecting toward AI-native capabilities. The companion forecast for securing AI itself reaches $16.4 billion in 2030. Gartner publicly confirms the 75%-by-2028 adoption projection.

The share table and the dollar table tell different stories. Software’s share of this market falls from 87.1% to 61.3%, and services picks up almost every point software gives up. Read only that and you conclude software is losing. Run the arithmetic on net-new spending and software still collects $116.5 billion of the $194.4 billion the market adds between 2024 and 2030. That is 60 cents of every new dollar, and it puts software ahead of services 2 to 1 on net-new spending.

Both things are true at once, and the gap between them is where security budgets get set wrong.

The numbers come from Gartner’s Forecast Analysis: AI-Amplified Security, Worldwide, 2026 (G00846160, August 4, 2026) by Shailendra Upadhyay. It is the first time Gartner has split AI-amplified security into software, services, and network security across a full seven-year window. The totals reconcile cleanly with the 2Q26 AI spending forecast, which carried AI-amplified security at $204.5 billion in 2030 without breaking out the segments underneath it.

This is a slice of the security budget, not an addition to it

The note states plainly that AI-amplified security is a subset of the information security forecast and that the spending is not additive. It points readers to the 2Q26 information security forecast, the one where securing AI became the only accelerating segment, for the parent view.

Keep the two straight. AI-amplified security is AI defending the enterprise, and it reaches $204 billion by 2030. Securing AI is the enterprise defending its own models, pipelines, and agents, at $16.4 billion in the same year. Roughly twelve dollars of AI-powered defense for every dollar spent protecting the AI doing the defending.

Key findings

  • $204.5 billion by 2030, up from $10.0 billion in 2024. A 65.3% CAGR and 20.4x expansion. Gartner projects that by 2028, over 75% of enterprises will use AI-amplified cybersecurity products for most use cases, up from less than 25% in 2025. AI inside the product is table stakes, not a differentiator.
  • Security services grows from $364 million to $59.0 billion. Share climbs from 3.6% to 28.9%, absorbing 25.3 of the 25.8 points software gives up. The skills gap is the engine.
  • Security software reaches $125.3 billion and still wins the dollars. Share drops 25.8 points, but software adds $116.5 billion in net-new spending against services’ $58.7 billion. Services leads on rate and share. Software leads on absolute money.
  • Network security reaches $20.1 billion at a 66.8% CAGR. Its share dips to 8.3% in 2027 before recovering to 9.8% in 2030. Autonomous agents for network security operations are the catalyst.
  • The largest annual increment lands at the end. The market adds $14.3 billion in 2024-25 and $44.0 billion in 2029-30. Growth rates fall from 143% to 27% over the same span. Budget to increments, not rates.
  • 72% of organizations already deploy AI with a third-party vendor. Only 27% rely primarily on internal resources, per Gartner’s 2025 AI Buying Behavior Survey of 556 respondents. That split is where the services forecast comes from.
  • Code analysis leads GenAI security adoption at 22% in production. Combined in-use and piloting reaches 52%. Threat hunting sits at 18% in use with the highest planning rate of any use case at 44%.
  • About one-third of network security tasks are automated today. Even fewer use AI. That gap is where the $20.1 billion network security forecast originates.
Gartner AI-amplified security market by segment, US dollars, 2024 to 2030

AI-amplified security by segment, 2024 to 2030.

Gartner AI-amplified security market forecast by segment, US dollars millions, 2024 to 2030

Why services is the story, and where that story stops

Gartner’s 2025 AI Buying Behavior Survey quantifies the build-versus-buy split across 556 respondents. 57% deploy AI using both internal resources and third-party vendors. 27% rely primarily on internal resources. 15% go primarily through third-party vendors. Add the first and third and 72% of AI deployments already run through an outside partner.

Services did not grow 162x because buyers developed a taste for consultants. It grew because most organizations cannot staff the alternative. ISC2 measured a global cybersecurity workforce gap of 4.8 million professionals in its 2024 study, a gap that widened 19% year over year while the active workforce stayed flat. Gartner’s note describes service providers investing heavily to claim early leadership and running well ahead of their own clients in applying AI internally.

Here is the part the share chart hides. Software still captures 59.9% of all net-new spending in this market through 2030, against 30.2% for services and 9.9% for network security. A vendor reading the share decline as an exit signal would be misreading it. The software line is growing 14.3x in absolute terms while losing share to a segment growing from almost nothing.

Some CISOs will argue that services dependency creates lock-in they will pay for later. That argument is sound. It also lost. Gartner’s own numbers show in-house operation of AI security tooling has not scaled for the majority, and the 72% third-party figure is the receipt.

Growth rates decelerate while dollar increments keep climbing

Year-over-year growth falls from 142.7% in 2024-25 to 27.4% in 2029-30. That deceleration is normal for a market scaling from $10 billion to $204 billion. Services alone stays above 35% every year of the forecast, ending at 35.1% in 2029-30 after starting at 403%.

Year-over-year growth rate by segment, Gartner AI-amplified security forecast

Year-over-year growth rate by segment.

Net-new dollars move the opposite direction. The market adds $14.3 billion in 2024-25, $38.0 billion in 2027-28, and $44.0 billion in 2029-30. Growth rates fall by four-fifths. Annual dollar increments triple. A business case anchored to “the market grows 143%” reads as broken by 2028. A business case anchored to “the market adds $38 billion that year” still holds.

Net-new AI-amplified security spending added per year, services versus software and network

Net new spending added per year, split by services versus software and network.

Look at the split inside those bars. In 2029-30, services contributes $15.4 billion of the $44.0 billion increment. Software and network contribute $28.7 billion. Even in the final year of the forecast, when services carries its highest share of the market, it is still the minority of new money.

The structural shift that defines this forecast

Software’s share falls 25.8 points across the forecast period. Services absorbs 25.3 of them. Network security ends roughly where it started, though not in a straight line, dipping to 8.3% in 2027 before recovering to 9.8% by 2030.

AI-amplified security segment share shift, 2024 to 2030

Segment share of the total AI-amplified security market.

AI-amplified security segment share shift, 2024 to 2030

The mechanism is staffing, not preference. Organizations bought AI security software intending to run it themselves. The services curve records what happened next. The $3.6 billion in venture funding flowing to agentic AI security startups confirms where the market believes the answer sits, and the acquisition wave underneath it says incumbents agree.

GenAI security adoption is broader than the in-use numbers suggest

Gartner’s 2025 Cybersecurity Innovations in AI Risk Management and Use Survey polled 302 cybersecurity leaders between March 21 and May 9, 2025. Fewer than 25% of organizations use GenAI for cybersecurity today. More than 60% are piloting or planning it. Gartner warns that without a clear strategy, many of these initiatives land as superficial implementations with high project turnover, driven by executive pressure rather than operational need.

Piloting is not aspiration. It means budget allocated, vendor selected, and a proof of concept running. Combine in-use and piloting and code analysis reaches 52%, user behavior analytics 51%, vulnerability detection 47%, and incident response 46%. The $204 billion endpoint assumes most of those pilots convert.

GenAI cybersecurity adoption by use case, 2025 Gartner survey

GenAI cybersecurity adoption by use case.

GenAI cybersecurity adoption by use case, 2025 Gartner survey

Threat hunting carries the highest planning rate in the survey at 44%, against 18% in production. No other use case has that much committed intent sitting ahead of deployment. When those budgets convert, threat hunting moves fastest in the next survey update.

Autonomous agents move from concept to production in network security

Human-centric operating models cannot absorb the scale, threat velocity, and traffic diversity that AI-driven workloads generate. Gartner describes AI-amplified network security agents that operate without predetermined workflows, adapt to security events nobody scripted, and handle threat detection, policy enforcement, and incident response while people supervise and validate rather than execute.

The trust curve is the constraint. By 2029, Gartner projects 10% of organizations will run autonomous agents with no human oversight for network security operations, up from less than 1% in 2026. Ten percent in three years is not a mass market. It is enough to reprice the segment, and the $20.1 billion forecast reflects that repricing. For how these agent numbers stack against other estimates, see my roundup of agentic AI forecasts and market estimates.

One number in the note worth checking before you quote it

Gartner’s note carries two different 2026 figures. The opening summary describes the market rising from $49 billion in 2026 to $204 billion by 2030. A later passage describes it reaching $204 billion in 2030, up from $81 billion in 2026. Table 1 puts 2026 at $48.5 billion and 2027 at $81.2 billion.

The table is the authority, and $49 billion is the number consistent with it. It also matches the $48.5 billion AI-amplified figure I reported in March from the prior forecast cycle. Anyone quoting $81 billion as a 2026 figure is quoting 2027.

What this forecast changes for CISOs and security vendors

  • Reassess build versus buy, then budget for both. The 72% third-party figure is an organizational verdict on in-house feasibility. Plan services into the operating model rather than bolting it on. Do not read the share shift as permission to stop buying software, because software still takes 60% of the new dollars.
  • Anchor business cases to dollar increments. The market adds $38.0 billion in 2027-28 and $44.0 billion in 2029-30. Those numbers stay correct. Growth percentages will look wrong inside two years.
  • Move on threat hunting next. It has the highest planning rate in Gartner’s survey at 44% against 18% in production. Organizations that move before the pipeline converts will have more mature detection models when it does.
  • Grade vendors on services delivery, not just features. A pure software licensing model captures a shrinking share of a growing market. Gartner’s note is direct about the consequence, warning that vendors who fail to operationalize AI for real-time threat detection and adaptive defense risk rapid obsolescence.
  • Start network security agent pilots now. Gartner projects 10% trusted autonomy by 2029. That leaves three budget cycles to build guardrails, validation workflows, and the evidence trail an auditor will ask for. Waiting until 2028 means arriving late with an unproven control set.
  • Watch the governance layer in parallel. Gartner’s first Hype Cycle for AI Governance puts most security-relevant governance capabilities two to five years from mainstream adoption, which is the same window in which these agents reach production.

Bottom line

I have tracked Gartner’s information security forecast through multiple quarterly updates. This is the first time the firm has published segment-level detail underneath AI-amplified security, and the segments say more than the total does. Traditional security spending is reorganizing around AI-native capability, and the delivery model is reorganizing with it.

Every CISO reading this should ask one question of their AI security strategy. Is it built around software licensing or around services delivery? The honest answer for most organizations is that it needs to be built around both, weighted differently than it is today. Services is where the growth rate lives. Software is where the money still goes.

The risk of getting this wrong is not theoretical. Forrester predicts an agentic AI deployment will cause a publicly disclosed data breach this year, leading to employee dismissals, a prediction Infosecurity Magazine reported when senior analyst Paddy Harrington framed it as a cascade of failures rather than a single point of error. Gartner’s forecast prices the defense. It does not schedule it.

Related on Software Strategies Blog

Source and methodology

All market sizing data from Gartner, Forecast Analysis: AI-Amplified Security, Worldwide, 2026, published August 4, 2026 (ID G00846160), by Shailendra Upadhyay. AI-amplified security is a subset of the information security forecast and this is not additive spending. Survey data from the 2025 Gartner AI Buying Behavior Survey (n=556, fielded November through December 2025 across North America, Western Europe, and Asia/Pacific, organizations with $50 million or more in enterprisewide revenue) and the 2025 Gartner Cybersecurity Innovations in AI Risk Management and Use Survey (n=302, fielded March 21 through May 9, 2025, organizations with $250 million or more in fiscal 2024 revenue). Gartner notes that neither survey represents global findings or the market as a whole.

CAGR, growth multiples, market share percentages, year-over-year growth rates, incremental spending, net-new dollar allocation, and combined adoption rates computed by Software Strategies Blog from Gartner’s published segment data. Segment values are independently rounded by Gartner and do not always sum to the stated totals. All charts are original visualizations created by Software Strategies Blog.

This post is my personal reflection on Gartner’s AI-amplified security research from an industry analyst perspective. It does not represent my employer.

Gartner’s $248.9B security forecast makes securing AI the only segment accelerating through 2030

Gartner 2Q26 forecast, securing AI turns Other Security Software into the only accelerating segment, 16.3% to 20.1% by 2030

Gartner published its 2Q26 information security forecast on June 25. Worldwide spending reaches $248.9 billion in 2026, up 12.7% in constant currency, and hits $372.6 billion by 2030. The total is not the story. For the first time, Gartner is counting what enterprises spend to secure AI itself. Securing AI flips the only accelerating growth curve in Gartner’s forecast. It captures more new dollars than any other category. By 2029 it is the largest line item in enterprise security.

I’ve tracked this forecast through every quarterly update, and the 2026 projection keeps climbing. In March, I had it at $244.2 billion. The 1Q26 update raised it to $246.2 billion. Now it stands at $248.9 billion. Two upward revisions in one quarter. The second one changes what the forecast measures, not just what it totals.

Where securing AI landed in Gartner’s forecast

Gartner folded securing AI spending into its Other Security Software segment, which now grows from $15.6 billion in 2025 to $37.6 billion by 2030. One accounting decision reshaped the entire forecast.

Start with the growth curve. The 1Q26 version of this segment decelerated from 7.3% growth in 2026 down to 3.6% by 2030. With securing AI counted, the same segment accelerates from 16.3% to 20.1% across the same window. I ran all 41 categories in Gartner’s detailed forecast file. This is the only one whose annual growth rate increases every single year through 2030.

Then the size ranking flips. Endpoint protection platforms hold the top category spot through 2028 at $27.3 billion. In 2029, the securing AI segment passes them, $31.2 billion versus $30.1 billion. By 2030, the gap will widen to $37.6 billion against $33.0 billion. The largest line item in enterprise security will be one that Gartner’s 1Q26 forecast had growing at 5.1% a year. The 2Q26 forecast has the same segment compounding at 18.5%.

Gartner 2Q26 forecast, securing AI segment passes endpoint protection in 2029 at $31.2B vs $30.1B, reaching $37.6B by 2030

The 10 fastest-growing categories through 2030

The table ranks the 41 detailed categories underneath Gartner’s 11 headline segments by 2025 to 2030 CAGR in constant currency. Market sizes are in current U.S. dollars.

# Category (Parent Segment) 2025 ($B) 2030 ($B) CAGR New $ ($B)
1 Cloud Security Posture Management $4.7B $16.1B 27.6% $+11.5B
2 Cloud Access Security Brokers $2.2B $6.6B 24.3% $+4.4B
3 Cloud Workload Protection Platforms $5.9B $15.7B 21.0% $+9.8B
4 Zero Trust Network Access $2.4B $6.4B 20.9% $+4.0B
5 Threat Intelligence $2.5B $6.1B 19.0% $+3.6B
6 Consent and Preference Management $0.8B $2.0B 18.6% $+1.2B
7 Other Security Software (incl. securing AI) $15.6B $37.6B 18.5% $+21.9B
8 Network Detection and Response $2.2B $4.1B 12.4% $+1.9B
9 Subject Rights Request Automation $1.3B $2.3B 12.3% $+1.1B
10 Vulnerability Assessment $3.5B $6.4B 12.0% $+2.8B
Total information security market $218.2B $372.6B 10.7% $154.4B

Source: Gartner, Forecast: Information Security, Worldwide, 2024–2030, 2Q26 (G00855892, June 25, 2026). CAGR is computed from constant-currency values. Dollar figures in current U.S. dollars.

Gartner 2Q26 forecast, top 10 fastest growing security categories, CSPM leads at 27.6% CAGR, securing AI at 18.5%

Seven categories compound at 18.5% or better. The whole market runs at 10.7%. Then the ranking falls off a cliff to 12.4%. Cloud security posture management leads everything at 27.6%, growing from $4.7 billion to $16.1 billion. The three cloud security categories together triple to $38.4 billion by 2030, extending the run I flagged when cloud security led the 4Q25 update at 28.8%. Zero trust network access grows 2.65x to $6.4 billion while the category it replaces, network access control, falls 61% to $382 million. That is a migration, not a decline. NAC dollars are showing up in ZTNA line items instead.

I update this Top 10 ranking every quarter as Gartner releases new forecast data. Get the next one in your inbox.

Where the next $154 billion lands

The market adds $154.4 billion in new annual spending between 2025 and 2030. Six categories capture just under half of it. The securing AI segment takes $21.9 billion, more than any other line. Endpoint protection adds $14.6 billion. CSPM adds $11.5 billion. Firewall equipment, the legacy line everyone keeps writing off, adds $9.9 billion, the fourth most in the entire forecast. The other 35 categories fight over what remains.

Gartner 2Q26 forecast, securing AI captures $21.9B of $154.4B in new security spending through 2030, most of any category

The bottom of the table tells the same story from the other direction. Consumer security software crawls at 3.5%. User authentication grows 3.1% a year, the slowest line in identity, while IDPS shrinks 8.3% and NAC contracts 17.7% annually. The standalone products that anchored enterprise security budgets a decade ago are being folded into the platforms that grew up around them, and the consolidation story vendors have pitched for years is now visible in Gartner’s own numbers.

In my 1Q26 breakdown of the Top 10 fastest growers, the securing AI segment did not exist as a distinct growth driver. One quarter later, it leads every category in new dollars. That is how fast the forecast structure moved.

What these numbers add up to

Gartner now expects more than half of the overall security market to include AI by 2030. This update prices the other side of that trade for the first time. In March, I wrote that enterprises were spending 17x more on AI tools than on securing AI itself. The catch-up spend now has its own line in the forecast, and it is the only number in the entire table that keeps accelerating.

Gartner raised its 2030 total outlook by $19.5 billion. The securing AI segment accounts for $20.3 billion of that revision. Every other segment combined has a net cut of roughly $780 million. The money is moving, and it is moving in one direction.

Gartner’s 3Q26 forecast update lands in the fall, and I’ll break down whether the securing AI acceleration holds or whether Gartner revises the trajectory once early enterprise adoption data comes in. That update will also be the first to reflect a full year of post-inclusion spending data.

Gartner’s $244.2B security forecast shows enterprises spend 17x more on AI tools than securing AI itself

Inside the $244.2 billion security market: agentic AI adoption outpaces defenses 8 to 1, cloud security grows at 28.8%, and enterprises spend 17x more on AI tools than on securing the AI itself

Gartner forecasts worldwide AI spending will reach $2.52 trillion in 2026, a 44% increase year-over-year. Worldwide IT spending will hit $6.15 trillion. Within that massive build-out, information security spending accelerates to $244.2 billion, up 13.3%.

The headline looks healthy. Look closer, and it isn’t. I’ve been tracking Gartner’s information security forecast through multiple quarterly updates, and the trajectory keeps steepening. But the spending acceleration is masking a deeper problem: enterprises are deploying AI agents into production far faster than they are securing them.

  1. The 40% / 6% gap

Gartner predicts 40% of enterprise applications will include task-specific AI agents by the end of 2026. Up from less than 5% in January. These are not chatbots. Gartner’s examples include autonomous cybersecurity response agents that scan network traffic, analyze system logs, and initiate responses without human intervention.

Only roughly 6% of organizations report having an advanced AI security strategy in place, according to vendor-sourced research from BigID’s 2025 AI Risk and Readiness study. Even adjusting for methodology differences between vendor and analyst research, the gap is stark. Agents are entering production at roughly 7-8x the rate organizations are building governance around them.

Gartner’s 4Q25 AI spending forecast created a dedicated agentic AI market segment for the first time. The spending lines are dramatic. Agentic AI overtakes chatbot and assistant spending by 2027. By 2029, agentic AI will reach $752.7 billion at a 119% compound annual growth rate. Chatbot spending peaks at $264.7 billion, then declines. That crossover point is where the security model breaks, because chatbots operate within human-supervised sessions. Agents don’t.

Gartner named agentic AI oversight the number-one cybersecurity trend for 2026 in its February report (my breakdown of all six trends here). A separate Gartner poll of 147 CIOs found 24% had already deployed AI agents and 50% were actively experimenting. Guardian agents, AI systems designed to monitor and govern other AI agents, are projected to capture 10-15% of the agentic AI market by 2030.

Forrester’s 2026 cybersecurity predictions go further: an agentic AI deployment will cause a publicly disclosed data breach this year, leading to employee dismissals. Senior analyst Paddy Harrington frames it as a cascade of failures, not a single point of error. That prediction landed in October 2025. Nothing since has made it less likely.

  1. $244.2 billion, and where it goes

Gartner’s 4Q25 information security forecast projects global spending reaching $244.2 billion in 2026, up 13.3% year-over-year. That is acceleration, not continuation. Gartner’s forecast trajectory has been steepening for multiple quarters. It follows a year where many CISOs focused on consolidating tools rather than buying new ones.

The allocation matters more than the total (please click on the graphic to expand for easier reading):

Cloud security at 28.8% growth is the fastest subsegment by a wide margin. CSPM alone carries a 31.3% CAGR. These represent organizations reacting to attack surfaces that expanded when workloads moved to the cloud faster than security controls followed.

Managed security services at 11.1% tells a workforce story the spending headline misses. The ISC2 documented a global cybersecurity workforce gap of 4.8 million professionals in October 2024. That gap grew 19% year-over-year while the active workforce flatlined at 5.5 million. A quarter of organizations reported cybersecurity layoffs. So they’re buying SOC capacity from managed providers instead. The spending growth in managed services is a staffing problem wearing a procurement mask.

The 17:1 spending asymmetry

Gartner’s 4Q25 AI spending forecast splits the AI cybersecurity market into two sub-segments for the first time. AI-amplified security, using AI to defend the enterprise, reached $49 billion in 2025. Securing AI itself, protecting the models, training data, inference pipelines, agent workflows, and decision outputs, stood at $2.8 billion. That is 5.5% of the AI cybersecurity market.

Enterprises are investing 17 times more in AI-powered security tools than in securing the AI on which those tools run. Gartner projects over 75% of enterprises will use AI-amplified cybersecurity products by 2028, up from less than 25% in 2025. The tools are getting funded. What the tools actually depend on to function is not.

  1. Quantum crosses the 5% budget threshold

Forrester predicts quantum security spending will exceed 5% of overall IT security budgets in 2026. Five percent sounds modest until you consider what it represents: the shift from research line items to actual procurement.

That means consulting engagements for quantum migration planning. Cryptographic discovery tools to figure out which systems need replacing first. Post-quantum algorithm testing across live production environments. Gartner calls post-quantum cryptography a force that demands organizations identify, manage, and replace traditional encryption methods now. Not eventually. The encryption market is growing at 2.0x according to the 4Q25 forecast, and the planning horizon is 2030. Starting migration in 2028 means compounding rip-and-replace costs every quarter of delay.

Forrester also predicts the EU will establish its own known exploited vulnerability database in 2026. Regulatory fragmentation adds cost. For enterprises operating across jurisdictions, quantum migration planning cannot be separated from compliance architecture.

  1. 57% of employees are already using shadow AI

A smaller Gartner survey of 175 employees conducted between May and November 2025 found that 57% use personal GenAI accounts for work. A third admitted to uploading sensitive information to tools their organizations have not sanctioned.

I keep coming back to this stat because it reframes the entire agentic AI security conversation. The firewalls most enterprises rely on were built for human-to-application communication. Protocols like MCP now enable agent-to-agent interaction at a scale and speed those tools were never designed to see. Machine identities outnumber human employees by more than 80 to 1 in most enterprises, according to CyberArk. Traditional IAM was not built for nonhuman actors operating autonomously.

Gartner’s cybersecurity trends report identifies IAM adaptation for AI agents as a top-six trend for 2026, specifically calling out identity registration, credential automation, and policy-driven authorization for machine actors. Failure to address these issues will lead to greater access-related cybersecurity incidents as autonomous agents become more prevalent.

The investment context: AI in the trough, security in the gap

Gartner places AI in the Trough of Disillusionment throughout 2026. AI will most often be sold by incumbent software providers rather than bought as part of new moonshot projects. ROI predictability has to improve before enterprises scale their deployments.

Forrester’s 2026 predictions reinforce this: enterprises will defer 25% of planned AI spending into 2027 as financial rigor slows production deployments and kills proofs of concept. Fewer than one-third of decision-makers can tie AI value to their organization’s financial growth.

Yet Gartner’s IT spending forecast shows server spending accelerating at 36.9% year-over-year and data center spending surging 31.7% past $650 billion. GenAI model spending grows at 80.8%. The infrastructure build-out is not slowing even as enterprise application adoption pauses.

Infrastructure spending runs hot. Application-layer AI spending cools. Security spending accelerates into the gap between adoption speed and governance readiness. The $244.2 billion flowing into information security is the cost of operating in an environment where AI agents are proliferating faster than the controls designed to govern them.

What these numbers add up to

For two decades, enterprise security assumed a human on the other end of every session, every credential request, every decision. That assumption is collapsing. The autonomous agent accessing your production database at 3 AM doesn’t authenticate the way your SOC analyst does, doesn’t respect the same governance boundaries, and operates at speeds no human reviewer can match.

What makes this moment different from previous security inflection points is the speed asymmetry. When cloud migration created new attack surfaces, enterprises had years to adapt. The shift from on-prem to cloud took a decade. The shift from human-operated to agent-operated environments is measured in quarters. Gartner didn’t even have a dedicated agentic AI spending segment until this forecast cycle. By the next one, the crossover will have already happened.

The practical question for 2026 is not whether to invest in AI security. That decision has been made by the spending trajectory. It is whether to govern AI agents proactively, before the first publicly disclosed agentic breach forces a reactive scramble, or to wait and pay the premium that every late mover in cybersecurity history has paid. Forrester has already predicted which outcome is more likely this year. The 17:1 ratio suggests most enterprises are betting on the wrong side of that question.

Sources

Gartner Forecast: Information Security, Worldwide, 2023–2029, 4Q25 (December 18, 2025)

Gartner Forecast Analysis: Information Security, Worldwide, 2026 (February 5, 2026)

Gartner Forecast: AI Spending, Worldwide, 2024–2029, 4Q25 (December 2025)

Gartner, Top Trends in Cybersecurity for 2026 (February 5, 2026)

Gartner, Worldwide AI Spending Will Total $2.52 Trillion in 2026 (January 15, 2026)

Gartner, Worldwide IT Spending to Grow 10.8% in 2026 (March 2026)

Gartner, 40% of Enterprise Apps Will Feature AI Agents by 2026 (August 26, 2025)

Gartner, Guardian Agents Will Capture 10-15% of Agentic AI Market by 2030 (June 11, 2025)

Forrester Predictions 2026: Cybersecurity and Risk (October 28, 2025)

Forrester, Global Tech Spend Will Grow 7.8% in 2026 (February 2, 2026)

Forrester, 2026 Technology & Security Predictions (October 28, 2025)

ISC2, 2024 Cybersecurity Workforce Study (October 2024)

CyberArk, Machine Identities Report (April 2025)

BigID, AI Risk & Readiness in the Enterprise (2025)