Skip to content

Posts tagged ‘securing AI’

Gartner’s AI security forecast exposes 162x services growth that still trails software 2 to 1 in new spending

Gartner AI-amplified security forecast, growth multiple versus net-new dollars by segment, 2024 to 2030

Growth multiple versus net-new dollars added, 2024 to 2030. The segment ranking inverts between the two measures.

Every chart and table in this analysis opens full size when you click it.

Security services inside Gartner’s AI-amplified security market were worth $364 million in 2024. Gartner now projects $59 billion by 2030. That is 162 times larger in six years, compounding at 133.5% annually, the steepest curve anywhere in the forecast. I have tracked this forecast through every quarterly update, and no segment has ever moved like this one.

What Is AI-Amplified Security?

Gartner’s term for the share of existing security spending flowing to products with AI built in. Endpoint protection, firewalls, identity, and network security that now embed AI-driven detection, autonomous remediation, and agent-based response. Not a new category. Existing budgets redirecting toward AI-native capabilities. The companion forecast for securing AI itself reaches $16.4 billion in 2030. Gartner publicly confirms the 75%-by-2028 adoption projection.

The share table and the dollar table tell different stories. Software’s share of this market falls from 87.1% to 61.3%, and services picks up almost every point software gives up. Read only that and you conclude software is losing. Run the arithmetic on net-new spending and software still collects $116.5 billion of the $194.4 billion the market adds between 2024 and 2030. That is 60 cents of every new dollar, and it puts software ahead of services 2 to 1 on net-new spending.

Both things are true at once, and the gap between them is where security budgets get set wrong.

The numbers come from Gartner’s Forecast Analysis: AI-Amplified Security, Worldwide, 2026 (G00846160, August 4, 2026) by Shailendra Upadhyay. It is the first time Gartner has split AI-amplified security into software, services, and network security across a full seven-year window. The totals reconcile cleanly with the 2Q26 AI spending forecast, which carried AI-amplified security at $204.5 billion in 2030 without breaking out the segments underneath it.

This is a slice of the security budget, not an addition to it

The note states plainly that AI-amplified security is a subset of the information security forecast and that the spending is not additive. It points readers to the 2Q26 information security forecast, the one where securing AI became the only accelerating segment, for the parent view.

Keep the two straight. AI-amplified security is AI defending the enterprise, and it reaches $204 billion by 2030. Securing AI is the enterprise defending its own models, pipelines, and agents, at $16.4 billion in the same year. Roughly twelve dollars of AI-powered defense for every dollar spent protecting the AI doing the defending.

Key findings

  • $204.5 billion by 2030, up from $10.0 billion in 2024. A 65.3% CAGR and 20.4x expansion. Gartner projects that by 2028, over 75% of enterprises will use AI-amplified cybersecurity products for most use cases, up from less than 25% in 2025. AI inside the product is table stakes, not a differentiator.
  • Security services grows from $364 million to $59.0 billion. Share climbs from 3.6% to 28.9%, absorbing 25.3 of the 25.8 points software gives up. The skills gap is the engine.
  • Security software reaches $125.3 billion and still wins the dollars. Share drops 25.8 points, but software adds $116.5 billion in net-new spending against services’ $58.7 billion. Services leads on rate and share. Software leads on absolute money.
  • Network security reaches $20.1 billion at a 66.8% CAGR. Its share dips to 8.3% in 2027 before recovering to 9.8% in 2030. Autonomous agents for network security operations are the catalyst.
  • The largest annual increment lands at the end. The market adds $14.3 billion in 2024-25 and $44.0 billion in 2029-30. Growth rates fall from 143% to 27% over the same span. Budget to increments, not rates.
  • 72% of organizations already deploy AI with a third-party vendor. Only 27% rely primarily on internal resources, per Gartner’s 2025 AI Buying Behavior Survey of 556 respondents. That split is where the services forecast comes from.
  • Code analysis leads GenAI security adoption at 22% in production. Combined in-use and piloting reaches 52%. Threat hunting sits at 18% in use with the highest planning rate of any use case at 44%.
  • About one-third of network security tasks are automated today. Even fewer use AI. That gap is where the $20.1 billion network security forecast originates.
Gartner AI-amplified security market by segment, US dollars, 2024 to 2030

AI-amplified security by segment, 2024 to 2030.

Gartner AI-amplified security market forecast by segment, US dollars millions, 2024 to 2030

Why services is the story, and where that story stops

Gartner’s 2025 AI Buying Behavior Survey quantifies the build-versus-buy split across 556 respondents. 57% deploy AI using both internal resources and third-party vendors. 27% rely primarily on internal resources. 15% go primarily through third-party vendors. Add the first and third and 72% of AI deployments already run through an outside partner.

Services did not grow 162x because buyers developed a taste for consultants. It grew because most organizations cannot staff the alternative. ISC2 measured a global cybersecurity workforce gap of 4.8 million professionals in its 2024 study, a gap that widened 19% year over year while the active workforce stayed flat. Gartner’s note describes service providers investing heavily to claim early leadership and running well ahead of their own clients in applying AI internally.

Here is the part the share chart hides. Software still captures 59.9% of all net-new spending in this market through 2030, against 30.2% for services and 9.9% for network security. A vendor reading the share decline as an exit signal would be misreading it. The software line is growing 14.3x in absolute terms while losing share to a segment growing from almost nothing.

Some CISOs will argue that services dependency creates lock-in they will pay for later. That argument is sound. It also lost. Gartner’s own numbers show in-house operation of AI security tooling has not scaled for the majority, and the 72% third-party figure is the receipt.

Growth rates decelerate while dollar increments keep climbing

Year-over-year growth falls from 142.7% in 2024-25 to 27.4% in 2029-30. That deceleration is normal for a market scaling from $10 billion to $204 billion. Services alone stays above 35% every year of the forecast, ending at 35.1% in 2029-30 after starting at 403%.

Year-over-year growth rate by segment, Gartner AI-amplified security forecast

Year-over-year growth rate by segment.

Net-new dollars move the opposite direction. The market adds $14.3 billion in 2024-25, $38.0 billion in 2027-28, and $44.0 billion in 2029-30. Growth rates fall by four-fifths. Annual dollar increments triple. A business case anchored to “the market grows 143%” reads as broken by 2028. A business case anchored to “the market adds $38 billion that year” still holds.

Net-new AI-amplified security spending added per year, services versus software and network

Net new spending added per year, split by services versus software and network.

Look at the split inside those bars. In 2029-30, services contributes $15.4 billion of the $44.0 billion increment. Software and network contribute $28.7 billion. Even in the final year of the forecast, when services carries its highest share of the market, it is still the minority of new money.

The structural shift that defines this forecast

Software’s share falls 25.8 points across the forecast period. Services absorbs 25.3 of them. Network security ends roughly where it started, though not in a straight line, dipping to 8.3% in 2027 before recovering to 9.8% by 2030.

AI-amplified security segment share shift, 2024 to 2030

Segment share of the total AI-amplified security market.

AI-amplified security segment share shift, 2024 to 2030

The mechanism is staffing, not preference. Organizations bought AI security software intending to run it themselves. The services curve records what happened next. The $3.6 billion in venture funding flowing to agentic AI security startups confirms where the market believes the answer sits, and the acquisition wave underneath it says incumbents agree.

GenAI security adoption is broader than the in-use numbers suggest

Gartner’s 2025 Cybersecurity Innovations in AI Risk Management and Use Survey polled 302 cybersecurity leaders between March 21 and May 9, 2025. Fewer than 25% of organizations use GenAI for cybersecurity today. More than 60% are piloting or planning it. Gartner warns that without a clear strategy, many of these initiatives land as superficial implementations with high project turnover, driven by executive pressure rather than operational need.

Piloting is not aspiration. It means budget allocated, vendor selected, and a proof of concept running. Combine in-use and piloting and code analysis reaches 52%, user behavior analytics 51%, vulnerability detection 47%, and incident response 46%. The $204 billion endpoint assumes most of those pilots convert.

GenAI cybersecurity adoption by use case, 2025 Gartner survey

GenAI cybersecurity adoption by use case.

GenAI cybersecurity adoption by use case, 2025 Gartner survey

Threat hunting carries the highest planning rate in the survey at 44%, against 18% in production. No other use case has that much committed intent sitting ahead of deployment. When those budgets convert, threat hunting moves fastest in the next survey update.

Autonomous agents move from concept to production in network security

Human-centric operating models cannot absorb the scale, threat velocity, and traffic diversity that AI-driven workloads generate. Gartner describes AI-amplified network security agents that operate without predetermined workflows, adapt to security events nobody scripted, and handle threat detection, policy enforcement, and incident response while people supervise and validate rather than execute.

The trust curve is the constraint. By 2029, Gartner projects 10% of organizations will run autonomous agents with no human oversight for network security operations, up from less than 1% in 2026. Ten percent in three years is not a mass market. It is enough to reprice the segment, and the $20.1 billion forecast reflects that repricing. For how these agent numbers stack against other estimates, see my roundup of agentic AI forecasts and market estimates.

One number in the note worth checking before you quote it

Gartner’s note carries two different 2026 figures. The opening summary describes the market rising from $49 billion in 2026 to $204 billion by 2030. A later passage describes it reaching $204 billion in 2030, up from $81 billion in 2026. Table 1 puts 2026 at $48.5 billion and 2027 at $81.2 billion.

The table is the authority, and $49 billion is the number consistent with it. It also matches the $48.5 billion AI-amplified figure I reported in March from the prior forecast cycle. Anyone quoting $81 billion as a 2026 figure is quoting 2027.

What this forecast changes for CISOs and security vendors

  • Reassess build versus buy, then budget for both. The 72% third-party figure is an organizational verdict on in-house feasibility. Plan services into the operating model rather than bolting it on. Do not read the share shift as permission to stop buying software, because software still takes 60% of the new dollars.
  • Anchor business cases to dollar increments. The market adds $38.0 billion in 2027-28 and $44.0 billion in 2029-30. Those numbers stay correct. Growth percentages will look wrong inside two years.
  • Move on threat hunting next. It has the highest planning rate in Gartner’s survey at 44% against 18% in production. Organizations that move before the pipeline converts will have more mature detection models when it does.
  • Grade vendors on services delivery, not just features. A pure software licensing model captures a shrinking share of a growing market. Gartner’s note is direct about the consequence, warning that vendors who fail to operationalize AI for real-time threat detection and adaptive defense risk rapid obsolescence.
  • Start network security agent pilots now. Gartner projects 10% trusted autonomy by 2029. That leaves three budget cycles to build guardrails, validation workflows, and the evidence trail an auditor will ask for. Waiting until 2028 means arriving late with an unproven control set.
  • Watch the governance layer in parallel. Gartner’s first Hype Cycle for AI Governance puts most security-relevant governance capabilities two to five years from mainstream adoption, which is the same window in which these agents reach production.

Bottom line

I have tracked Gartner’s information security forecast through multiple quarterly updates. This is the first time the firm has published segment-level detail underneath AI-amplified security, and the segments say more than the total does. Traditional security spending is reorganizing around AI-native capability, and the delivery model is reorganizing with it.

Every CISO reading this should ask one question of their AI security strategy. Is it built around software licensing or around services delivery? The honest answer for most organizations is that it needs to be built around both, weighted differently than it is today. Services is where the growth rate lives. Software is where the money still goes.

The risk of getting this wrong is not theoretical. Forrester predicts an agentic AI deployment will cause a publicly disclosed data breach this year, leading to employee dismissals, a prediction Infosecurity Magazine reported when senior analyst Paddy Harrington framed it as a cascade of failures rather than a single point of error. Gartner’s forecast prices the defense. It does not schedule it.

Related on Software Strategies Blog

Source and methodology

All market sizing data from Gartner, Forecast Analysis: AI-Amplified Security, Worldwide, 2026, published August 4, 2026 (ID G00846160), by Shailendra Upadhyay. AI-amplified security is a subset of the information security forecast and this is not additive spending. Survey data from the 2025 Gartner AI Buying Behavior Survey (n=556, fielded November through December 2025 across North America, Western Europe, and Asia/Pacific, organizations with $50 million or more in enterprisewide revenue) and the 2025 Gartner Cybersecurity Innovations in AI Risk Management and Use Survey (n=302, fielded March 21 through May 9, 2025, organizations with $250 million or more in fiscal 2024 revenue). Gartner notes that neither survey represents global findings or the market as a whole.

CAGR, growth multiples, market share percentages, year-over-year growth rates, incremental spending, net-new dollar allocation, and combined adoption rates computed by Software Strategies Blog from Gartner’s published segment data. Segment values are independently rounded by Gartner and do not always sum to the stated totals. All charts are original visualizations created by Software Strategies Blog.

This post is my personal reflection on Gartner’s AI-amplified security research from an industry analyst perspective. It does not represent my employer.

Gartner’s $5.95 trillion AI forecast puts the chatbot era on a 2027 deadline

Spending on the chatbots and assistants embedded in enterprise software peaks at $272.6 billion in 2027 and then shrinks every year through 2030. Gartner buried that projection inside the 2Q26 update of its worldwide AI spending forecast, published July 24, and it matters more than the headline total. By 2030, embedded chatbot spending falls back to $205.8 billion, a hair above its 2025 starting point.

Embedded agenticAI takes the money instead, growing from $88.2 billion in 2025 to $1 trillion by 2030, an 11.4x expansion inside a single software category.

None of that slows the topline. Worldwide AI spending reaches $2.67 trillion in 2026, up 49.5% from 2025, on its way to $5.95 trillion by 2030. The figure Gartner published in May was $2.59 trillion for this year. Ninety days later, the client-facing number runs $74.8 billion higher, and the firm added $496.8 billion to its comparable 2025 through 2030 outlook in a single quarter.

Four tables below show where the money lands, which segments stall, and what Gartner changed its mind about between April and July.

Where $5.95 trillion lands

Infrastructure stays the biggest line through 2030 at $2.79 trillion, even as its share of total spending slides from 55% in 2025 to 46.9% at the end of the window. AI-optimized servers alone reach $981.7 billion by 2030, a 3.4x jump from 2025, and AI processing semiconductors add another $656.4 billion. O

One caution before quoting the total anywhere. Gartner’s note flags the forecast as a view across the whole AI value chain, so the chip and the server it ships inside both get counted. Read $5.95 trillion as the size of the AI economy, not as net end-user budgets.

Devices carry more of the infrastructure number than most readers expect. Business and consumer AI devices combine for $904.4 billion in 2030, and $647.4 billion of that is consumer hardware, the AI PCs and phones landing in shopping carts rather than data centers.

Growth flattens fast after next year. Total spending rises 49% in 2026 and 36% in 2027, then steps down to 21%, 18% and 15% through 2030, while infrastructure decelerates from 51% growth this year to 9% at the end of the forecast.

Of the $883.8 billion in net-new AI spending arriving in 2026, infrastructure absorbs $502.5 billion, or 57 cents of every new dollar. The shape of the curve says the buildout peaks now and software inherits the growth.

Farther down the board, AI cybersecurity at $220.9 billion and AI agents and assistants at $219.9 billion finish 2030 within $1 billion of each other. Gartner created the agents category only this quarter.

Agentic AI crosses $1 trillion inside enterprise software

Gartner rebuilt its segmentation this quarter, splitting cross-functional and consumer agents out of AI software and adding consumer agents to the forecast for the first time. The new structure exposes a replacement cycle the old rollup hid. Inside enterprise software, agentic AI overtakes chatbots in 2027, the same year chatbot spending tops out, and from that peak to 2030 the embedded chatbot line surrenders $66.8 billion.

Cross-functional agents, the ones that work across software from multiple vendors, start from a base of zero. Gartner books $347 million for cross-functional agentic AI in 2026 and $78.1 billion in 2030, a number it raised this quarter on the thesis that these agents begin cannibalizing traditional SaaS by decade’s end. The ceiling matters as much as the curve. Against $1.21 trillion in total 2030 AI software spending, $78.1 billion says the incumbents hold the decade, because data access, integration complexity and execution reliability hold the category back from serious SaaS competition until 2030, in Gartner’s read.

The buy-versus-build verdict is just as lopsided. Agent builder platforms, the tooling for constructing your own agents, reach only $12.6 billion by 2030, so embedded agentic AI outspends them nearly 80 to 1. The first production agent most companies run will ship inside software they already own. Gartner describes exactly that race, with vendors across software categories embedding agentic AI to defend their installed bases against cross-functional challengers.

Consumer agents barely register yet in dollar terms. Gartner carries $26.9 million for consumer agentic AI in 2026, then $17.7 billion in 2027 as paid consumer agents arrive at scale, building to $51.8 billion by 2030. Adding consumer agents and assistants lifted Gartner’s 2030 total by $133 billion. For how these agent numbers stack against other analyst estimates, see my roundup of agentic AI forecasts and market estimates, 2026.

AI security expands 8.5x and splits in two

AI cybersecurity grows from $25.9 billion in 2025 to $220.9 billion in 2030, an 8.5x expansion at a 53.5% compound rate. Spending in the category grew 140% in 2025, and Gartner models another 98% jump this year. AI cybersecurity and AI data were also the only two markets left completely untouched between the 1Q26 and 2Q26 forecasts, which makes security the steadiest conviction in the entire model. For the standalone security spending outlook, see my breakdown of Gartner’s 2Q26 information security forecast.

Two markets move at different speeds inside the category. AI-amplified security, meaning AI capability inside security tooling, carries the volume and reaches $204.5 billion by 2030. Securing AI, the discipline of protecting AI systems themselves, runs smaller and faster, from $1.5 billion in 2025 to $16.4 billion in 2030 at a 60.4% compound rate.

Set the security numbers against the agent forecast and an exposure gap opens. The 2030 outlook has enterprises running $1.08 trillion of embedded and cross-functional agentic software while spending $16.4 billion to secure AI systems, roughly $66 of agentic software for every $1 of securing-AI budget. AI observability and governance tooling adds just $3.9 billion more. A software wave that large riding on a security ratio that thin is the budget argument CISOs should be starting now.

The fastest growth goes to whatever cuts the bill

Rank every segment by compound growth and one pattern jumps out, because the fastest-growing lines are the ones that make AI cheaper. Synthetic data generation leads the entire forecast at a 142.5% compound rate, expanding 84x from $146 million in 2025 to $12.2 billion in 2030. AI-ready datasets, the licensed real-data alternative, peak at $583 million in 2029 and then decline, leaving synthetic data outselling licensed data 22 to 1 by 2030. Gartner is forecasting the substitution of purchased data itself.

Domain-specific language models tell the same cost story at larger scale. DSLMs and specialized models grow 210% in 2026 and compound at 84.5% through 2030, rising from 12.2% of all model spend to 24.3%. Cost pressure also explains the strangest revision in the update. Gartner cut $57.8 billion in cumulative dollars from its generative AI model forecast while raising the segment’s 2026 growth rate from 110% to 117%, which nets out to more deployments running on cheaper models and smaller checks. Arunasree Cheparthi, a senior principal research analyst at Gartner and one of the forecast’s authors, said in the firm’s July 20 platforms and models announcement that spending “is shifting toward providers who can demonstrate clear value.”

What Gartner changed in 90 days

Between the April forecast and this one, Gartner added $500.8 billion to AI infrastructure across the 2025 through 2030 window, the largest revision in the update, and did it while flagging memory-related price increases. The note calls infrastructure demand inelastic to that pricing pressure, because hyperscalers keep buying AI-optimized servers on the conviction that model capabilities improve through 2030.

Software took the other side of the trade. AI software gained $191.9 billion and application development platforms picked up $10.7 billion. Gartner lifted the 2026 app-dev growth rate from 28% to 39% as enterprises build custom AI applications and demand usage tracking to prove the spend. The cuts land on everything that resembles consulting or plumbing. AI services lost $80.7 billion across the window, with every single year revised down, and platforms for data science and machine learning lost $68.2 billion, including an 8% cut to 2027 alone.

The services cut hides a structural shift rather than a retreat. Gartner still sizes AI services at $1.25 trillion in 2030, but the growth belongs to indirect services, which compound at 34.5% and pass direct, consulting-led engagements in 2028. Direct AI services compound at 15.7%, less than half the indirect rate. Buyers are routing transformation budgets through software and cloud purchases instead of billable hours.

Three dates to plan against

2027 is the year chatbot spending tops out and agentic AI takes over inside enterprise software, which gives any vendor still selling assistant-branded features through the end of next year to ride what growth remains. By 2028, indirect services pass consulting-led engagements and infrastructure growth drops to 15%, so the buildout stops flattering everyone’s numbers. And 2030 arrives with $1.08 trillion of agentic software guarded by $16.4 billion of securing-AI spend. The first two dates decide where the money goes, and the third decides what happens when it arrives unprotected.

This post is my personal reflection on Gartner’s AI spending research from an industry analyst perspective. It does not represent my employer.

Source: Gartner, Forecast: AI Spending, Worldwide, 2025-2030, 2Q26, Kay Arnott, Jon Erensen, Amarendra, Adrian O’Connell, Arunasree Cheparthi, Naresh Singh, Peter Middleton, Hardeep Singh, Shailendra Upadhyay, Rishi Padhi, 24 July 2026, G00855896.

Gartner’s $248.9B security forecast makes securing AI the only segment accelerating through 2030

Gartner 2Q26 forecast, securing AI turns Other Security Software into the only accelerating segment, 16.3% to 20.1% by 2030

Gartner published its 2Q26 information security forecast on June 25. Worldwide spending reaches $248.9 billion in 2026, up 12.7% in constant currency, and hits $372.6 billion by 2030. The total is not the story. For the first time, Gartner is counting what enterprises spend to secure AI itself. Securing AI flips the only accelerating growth curve in Gartner’s forecast. It captures more new dollars than any other category. By 2029 it is the largest line item in enterprise security.

I’ve tracked this forecast through every quarterly update, and the 2026 projection keeps climbing. In March, I had it at $244.2 billion. The 1Q26 update raised it to $246.2 billion. Now it stands at $248.9 billion. Two upward revisions in one quarter. The second one changes what the forecast measures, not just what it totals.

Where securing AI landed in Gartner’s forecast

Gartner folded securing AI spending into its Other Security Software segment, which now grows from $15.6 billion in 2025 to $37.6 billion by 2030. One accounting decision reshaped the entire forecast.

Start with the growth curve. The 1Q26 version of this segment decelerated from 7.3% growth in 2026 down to 3.6% by 2030. With securing AI counted, the same segment accelerates from 16.3% to 20.1% across the same window. I ran all 41 categories in Gartner’s detailed forecast file. This is the only one whose annual growth rate increases every single year through 2030.

Then the size ranking flips. Endpoint protection platforms hold the top category spot through 2028 at $27.3 billion. In 2029, the securing AI segment passes them, $31.2 billion versus $30.1 billion. By 2030, the gap will widen to $37.6 billion against $33.0 billion. The largest line item in enterprise security will be one that Gartner’s 1Q26 forecast had growing at 5.1% a year. The 2Q26 forecast has the same segment compounding at 18.5%.

Gartner 2Q26 forecast, securing AI segment passes endpoint protection in 2029 at $31.2B vs $30.1B, reaching $37.6B by 2030

The 10 fastest-growing categories through 2030

The table ranks the 41 detailed categories underneath Gartner’s 11 headline segments by 2025 to 2030 CAGR in constant currency. Market sizes are in current U.S. dollars.

# Category (Parent Segment) 2025 ($B) 2030 ($B) CAGR New $ ($B)
1 Cloud Security Posture Management $4.7B $16.1B 27.6% $+11.5B
2 Cloud Access Security Brokers $2.2B $6.6B 24.3% $+4.4B
3 Cloud Workload Protection Platforms $5.9B $15.7B 21.0% $+9.8B
4 Zero Trust Network Access $2.4B $6.4B 20.9% $+4.0B
5 Threat Intelligence $2.5B $6.1B 19.0% $+3.6B
6 Consent and Preference Management $0.8B $2.0B 18.6% $+1.2B
7 Other Security Software (incl. securing AI) $15.6B $37.6B 18.5% $+21.9B
8 Network Detection and Response $2.2B $4.1B 12.4% $+1.9B
9 Subject Rights Request Automation $1.3B $2.3B 12.3% $+1.1B
10 Vulnerability Assessment $3.5B $6.4B 12.0% $+2.8B
Total information security market $218.2B $372.6B 10.7% $154.4B

Source: Gartner, Forecast: Information Security, Worldwide, 2024–2030, 2Q26 (G00855892, June 25, 2026). CAGR is computed from constant-currency values. Dollar figures in current U.S. dollars.

Gartner 2Q26 forecast, top 10 fastest growing security categories, CSPM leads at 27.6% CAGR, securing AI at 18.5%

Seven categories compound at 18.5% or better. The whole market runs at 10.7%. Then the ranking falls off a cliff to 12.4%. Cloud security posture management leads everything at 27.6%, growing from $4.7 billion to $16.1 billion. The three cloud security categories together triple to $38.4 billion by 2030, extending the run I flagged when cloud security led the 4Q25 update at 28.8%. Zero trust network access grows 2.65x to $6.4 billion while the category it replaces, network access control, falls 61% to $382 million. That is a migration, not a decline. NAC dollars are showing up in ZTNA line items instead.

I update this Top 10 ranking every quarter as Gartner releases new forecast data. Get the next one in your inbox.

Where the next $154 billion lands

The market adds $154.4 billion in new annual spending between 2025 and 2030. Six categories capture just under half of it. The securing AI segment takes $21.9 billion, more than any other line. Endpoint protection adds $14.6 billion. CSPM adds $11.5 billion. Firewall equipment, the legacy line everyone keeps writing off, adds $9.9 billion, the fourth most in the entire forecast. The other 35 categories fight over what remains.

Gartner 2Q26 forecast, securing AI captures $21.9B of $154.4B in new security spending through 2030, most of any category

The bottom of the table tells the same story from the other direction. Consumer security software crawls at 3.5%. User authentication grows 3.1% a year, the slowest line in identity, while IDPS shrinks 8.3% and NAC contracts 17.7% annually. The standalone products that anchored enterprise security budgets a decade ago are being folded into the platforms that grew up around them, and the consolidation story vendors have pitched for years is now visible in Gartner’s own numbers.

In my 1Q26 breakdown of the Top 10 fastest growers, the securing AI segment did not exist as a distinct growth driver. One quarter later, it leads every category in new dollars. That is how fast the forecast structure moved.

What these numbers add up to

Gartner now expects more than half of the overall security market to include AI by 2030. This update prices the other side of that trade for the first time. In March, I wrote that enterprises were spending 17x more on AI tools than on securing AI itself. The catch-up spend now has its own line in the forecast, and it is the only number in the entire table that keeps accelerating.

Gartner raised its 2030 total outlook by $19.5 billion. The securing AI segment accounts for $20.3 billion of that revision. Every other segment combined has a net cut of roughly $780 million. The money is moving, and it is moving in one direction.

Gartner’s 3Q26 forecast update lands in the fall, and I’ll break down whether the securing AI acceleration holds or whether Gartner revises the trajectory once early enterprise adoption data comes in. That update will also be the first to reflect a full year of post-inclusion spending data.