Decoding the world of cybersecurity

Gartner forecasts agent abuse in enterprise breaches

Gartner predicts ungoverned AI-agent abuse will drive 25% of enterprise breaches by 2028 as agent identity, authority, and oversight become security-control problems.

Gartner forecasts agent abuse in enterprise breaches
Summary
  • Gartner predicts ungoverned AI-agent abuse will drive 25% of enterprise breaches by 2028.
  • It separately forecasts that 30% of multinational organisations will restructure AI architecture because of national sovereignty requirements.
  • Both figures are forward-looking Gartner forecasts, not measurements of current breach activity.

Ungoverned AI-agent abuse will drive 25% of enterprise breaches by 2028, Gartner has forecast, putting autonomous software identity and authority among the emerging control problems organisations will face as agent deployment expands.

The prediction was issued at Gartner’s Security & Risk Management Summit in London as part of a wider set of forecasts covering agent sprawl, sovereignty, workforce change, unexplainable AI, and software supply-chain exposure.

The 25% figure is not a current breach statistic. Gartner is forecasting a future proportion rather than reporting that AI agents already account for one quarter of enterprise compromises.

The underlying control problem is becoming more tangible as businesses give agents access to applications, data, APIs, browsers, development tools, and cloud resources. An agent capable of taking actions on behalf of a user or service inherits some combination of those permissions, creating questions that model-governance frameworks alone do not resolve.

A model can generate an unsafe response without having authority to alter a production system. An agent with valid credentials and tools can turn a flawed decision into an action. Security therefore depends not only on model behaviour but identity, authorisation, environment boundaries, logging, approval mechanisms, and the ability to revoke access.

Gartner’s forecast specifically refers to ungoverned agent abuse. The analyst says organisations will require zero-trust governance and agent-specific mechanisms capable of stopping activity when necessary.

Those requirements overlap with established identity disciplines. Organisations already govern employees, privileged administrators, service accounts, application identities, and workloads. Agents add scale and autonomy to that problem rather than replacing the need for those controls.

They can also blur ownership. An employee account usually has a manager, role, employment status, and defined lifecycle. An agent might be created inside a business unit, use an identity managed by IT, call a third-party model, connect through APIs owned by several teams, and act on data governed elsewhere.

Without an authoritative inventory and owner, withdrawing access can become difficult even when an organisation decides an agent should no longer operate.

The market is already responding to that problem. A group of major technology vendors has proposed a shared architecture for governing AI agents, while identity and security providers are extending existing controls towards non-human and autonomous identities.

Gartner also predicts that 30% of multinational organisations will be forced to restructure AI architecture by 2028 to comply with national sovereignty requirements, increasing operating costs by 20%.

That forecast connects autonomous systems with jurisdiction, data location, and procurement. European organisations already examine where sensitive information is processed and which legal regimes apply to suppliers. Agentic systems can complicate those flows by adding model providers, tool integrations, memory stores, external APIs, and automated actions across several services.

The two forecasts therefore converge around control: one concerns what autonomous systems are permitted to do, while the other concerns where systems and data can operate under different national requirements.

Neither percentage is a certainty. Analyst forecasts depend on definitions, adoption patterns, and future technology deployment that can change materially over two years.

What is already visible is the expansion of the enterprise identity surface. As organisations move from AI systems that generate information to systems that act, the boundary between AI governance and ordinary cybersecurity becomes increasingly difficult to maintain.

×