The ‘chaotic rise’ of AI, geopolitical tensions, regulatory volatility, and an accelerating threat landscape are identified as the driving forces behind the top cyber security trends, according to Gartner.
The company says that six trends will have broad impacts across transforming governance, securing new frontiers, and normalising AI adoption:
Trend one: agentic AI demands cyber security oversight
Agentic AI is increasingly being used by employees and developers, creating new attack surfaces. No-code and low-code platforms and vibe coding expand this further, driving unmanaged AI agent proliferation, unsecured code, and potential regulatory compliance violations.
In response, cyber security leaders must identify both sanctioned and unsanctioned AI agents, enforce robust controls for each, and develop incident response playbooks to address potential risks.
Trend two: global regulatory volatility drives cyber resilience efforts
Shifting geopolitical landscapes and evolving global mandates have made cyber security a critical business risk with direct implications for organizational resilience. With regulators increasingly holding boards and executives liable for compliance failures, inaction can result in penalties, lost business, and reputational damage.
Gartner advises cyber security leaders to formalise collaboration across legal, business, and procurement teams to establish clear accountability for cyber risk. Aligning control frameworks to recognised standards and addressing data sovereignty concerns will help reduce compliance gaps.
Trend three: postquantum computing moves into action plans
Gartner predicts that advances in quantum computing will render the asymmetric cryptography that organizations rely on to secure data and systems unsafe by 2030. Postquantum cryptography alternatives must be adopted now to avoid potential data breaches, legal liability, and financial loss from ‘harvest now, decrypt later’ attacks targeting long-term sensitive data.
Trend four: identity and access management adapts to ai agents
The rise of AI agents is introducing challenges to traditional identity and access management (IAM) strategies, particularly in identity registration and governance, credential automation, and policy-driven authorisation for machine actors. Failure to address these issues may increase the risk of access-related cyber security incidents as autonomous agents become more prevalent.
Gartner recommends taking a targeted, risk-based approach by investing where gaps and risks are greatest, while leveraging automation where possible. This is presented as supporting innovation, compliance, and protection of critical assets in AI-centric environments.
Trend five: AI-driven SOC solutions destabilise operational norms
Driven by cost optimisation practices and increasing interest in AI, the emergence of AI-enabled security operations centres (SOCs) is introducing new complexity. This is contributing to staffing pressures, increased upskilling demands, and evolving cost considerations for AI tools, even as these technologies enhance alert triage and investigation workflows.
Trend six: GenAI breaks traditional cyber security awareness tactics
Existing security awareness efforts continue to fail to reduce cyber security risks as GenAI adoption accelerates. A Gartner survey of 175 employees conducted between May and November 2025 indicates that over 57% use personal GenAI accounts for work purposes and 33% admit inputting sensitive information into unapproved tools.
Gartner recommends shifting from general awareness training to adaptive behavioural and training programmes that include AI-specific tasks.
Strengthening governance, embedding secure practices, and establishing policies for authorised use will reduce exposure to privacy breaches and intellectual property loss.
Gartner clients can read more in Top Trends in Cybersecurity for 2026.






