The $4.8 billion AI-security forecast points to a changing security architecture
Gartner expects spending on securing AI to rise from USD $2.835 billion in 2026 to USD $4.783 billion in 2027, an increase of 68.7%, before approaching USD $7.7 billion in 2028. Gartner defines the category as software and platforms that protect AI models, applications and organisational AI use, including support for safe use and regulatory compliance. Cybersecurity products that use AI and machine learning to detect or respond to threats sit outside this definition.
The forecast points to a change in how enterprises may assemble security controls. Gartner expects enterprises to combine existing security systems with dedicated AI-security products as they deploy more AI. Established governance, data and API-management platforms can add some AI protections, while specialised products address other risks in Gartner’s forecast. Gartner has a commercial stake in defining and tracking technology markets, so its segmentation and forecasts should be read as Gartner’s market view.
AI security addresses distinct risks
Shailendra Upadhyay, Senior Principal Analyst at Gartner, attributes the spending surge to enterprises needing to secure AI systems, address emerging vulnerabilities and strengthen defenses against cyberthreats. He also points to vulnerabilities and supply-chain attacks involving third-party and open-source software in AI projects. In Gartner’s view, inadequate security and visibility controls put enterprise AI initiatives at high risk of failure. These claims underpin Gartner’s case for controls focused on AI models, applications and their use.
Gartner expects more than half of successful cyberattacks on AI agents by 2029 to exploit access-control weaknesses and prompt injections. Prompt injection means supplying instructions that manipulate an AI system into behaving in ways its operator did not intend. Access control is an established security discipline, and an AI agent can use the permissions, systems and information available to it when taking actions.
Gartner says organisations face pressure to identify, monitor and protect AI models against threats that differ from those in conventional software environments. Upadhyay argues that traditional security tools often treat AI applications like other software and need significant updates to address AI-specific threats. Under that framing, controls around identities, software, data and infrastructure remain relevant, while AI applications add requirements around instructions, outputs and model behavior. Gartner expects specialised areas such as AI usage control and AI application security to grow rapidly as enterprises address those requirements.
The software supply chain adds another exposure identified by Upadhyay. Enterprise AI projects can depend on third-party and open-source software, and he links vulnerabilities and supply-chain attacks in those dependencies to the need for stronger AI security. Autonomous AI widens that concern. Upadhyay says expanded AI initiatives, particularly autonomous AI, introduce vulnerabilities beyond the reach of traditional monitoring and increase demand for specialised security solutions.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
The spending breakdown points to a hybrid security stack
Gartner divides securing AI into AI application security, AI usage control, AI governance platforms, AI gateways and a fifth category called other securing AI. Its figures show different growth rates across the named segments and a large residual category. Gartner expects some spending to flow to specialist products as established vendors add AI functions to governance, data and API-management systems. This market structure underpins Gartner’s expectation that existing systems and dedicated AI-security products will coexist.
AI usage control has the fastest annual increase among Gartner’s named categories, making it a prominent area for specialist suppliers. AI application security is the largest specifically named segment that year. Gartner expects newer entrants and startups to move into both areas as buyers seek products tailored to newer AI risks. That forecast reflects Gartner’s view of where specialist suppliers can gain ground.
Governance platforms and gateways have a different competitive pattern in Gartner’s forecast. A gateway is a controlled point through which AI interactions can be managed, placing the category close to capabilities already found in API and data-management systems. Gartner expects larger established vendors to retain stronger positions in these areas by adding AI-related functions or integrating specialist products into existing governance, data and API-management systems.
Upadhyay expects organisations to gain confidence as defenses such as AI runtime protection and dedicated gateways become more reliable, accelerating adoption. Runtime protection means controls applied while an AI system is operating, when actual inputs, outputs and behavior can be observed. He also expects competitive pressure to drive consolidation and acquisitions, with larger cybersecurity companies buying startups to broaden their offerings. These are Gartner analyst expectations about how the supplier market may develop, rather than established outcomes.
The “other securing AI” category is a large share of the forecast
Based on Gartner’s figures, “other securing AI” represents roughly 48% of the projected total. The four specifically named segments therefore account for only part of the headline market. Executives using the forecast for planning should distinguish the total market-growth estimate from the more specific signals in the named categories.
This distinction also affects vendor evaluation. Gartner’s named categories identify different expected roles for application security, usage control, governance and gateways, while “other securing AI” remains a broad part of the total. Gartner also expects organisations to combine existing security systems with dedicated AI-security products. Buyers therefore need to map each identified AI risk to the control layer and supplier capability that addresses it.
That mapping becomes more important as autonomous AI expands. Upadhyay’s concern is that autonomous systems can introduce vulnerabilities beyond the reach of traditional monitoring, while Gartner’s forecast highlights access-control weaknesses and prompt injections as expected attack paths against AI agents. For CIOs, CISOs and AI leaders, the control boundary is an architectural question: which existing controls cover the risk, which platforms can be extended, and which risks require AI-specific protection. Those judgments determine where dedicated AI-security products fit within an enterprise’s existing security architecture.
Main highlights
- Plan for rapid AI-security growth: Gartner forecasts spending on securing AI will rise 68.7% to $4.8 billion in 2027. Leaders should assess where existing controls remain sufficient and where AI-specific protections are required.
- Prioritize AI-specific attack paths: Gartner expects access-control weaknesses and prompt injections to account for more than half of successful attacks on AI agents by 2029. Security plans should cover agent permissions, model behavior, runtime activity and software supply-chain risks.
- Build a hybrid security stack: Gartner expects enterprises to combine existing governance, data and API-management systems with specialist AI-security products. Leaders should map AI risks to specific control layers before adding new vendors.
- Scrutinize the headline market forecast: Gartner’s broad “other securing AI” category represents roughly 48% of the projected market. Executives should use the $4.8 billion forecast as a market signal while evaluating individual security categories and products on their specific capabilities.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


