Cybersecurity

Gartner: GenAI Security Incidents to Nearly Triple by 2028

Gartner: by 2028, 25% of enterprise GenAI apps will see 5+ minor security incidents yearly, up from 9% in 2025. The driver is MCP-powered agentic AI outpacing security review.

Gartner: GenAI Security Incidents to Nearly Triple by 2028 — article cover

On April 9, 2026, Gartner published a forecast: by 2028, 25% of all enterprise generative AI applications will experience at least five minor security incidents per year, up from 9% in 2025. By 2029, 15% will experience at least one major security incident per year — versus 3% in 2025.

The numbers alone are not surprising. What is surprising is where Gartner points the finger: the combination of the Model Context Protocol (MCP) and agentic AI. The scaling of security incidents is no longer the old “the model isn’t safe” problem — it is a new problem where agentic architectures lay out the attack surface.

The Two Numbers: 25% and 15%

Gartner counts a “minor incident” as five or more per year, across types including data exposure, content injection attacks, supply chain threats, sensitive data disclosure, and privilege escalation — most arising when “AI tries to be helpful but makes a mistake.” The jump from 9% to 25% means that within three years, one in four enterprise GenAI applications sits in the “routinely breaks things” bracket. Notably, Gartner does not draw a hard line between minor and major incidents — it separates them by frequency alone. That choice is itself a signal: once incidents become background noise, automated triage and grading matter more than investigating each one.

The steeper curve is the major-incident line: 3% to 15%, five-fold in five years. Aaron Lord, Sr. Director Analyst at Gartner, puts it plainly: MCP “was built for interoperability, ease of use and flexibility first, so security mistakes can manifest” without continuous oversight. His recommendation is for leaders to collaborate with data, security, and infrastructure teams to create a formal security review for MCP use cases.

Why MCP Is the Center of the Storm

MCP lets AI agents attach to arbitrary tools and data sources, and it has become the de facto standard for agentic AI deployment. But its design goal was developer speed, not security enforcement: tool descriptions are untrusted input, third-party MCP components go unreviewed, and agent permissions routinely inherit the human user’s role. The incident types Gartner names — content injection, sensitive data disclosure, privilege escalation — land almost exactly on those paths.

In other words, the problem is not any single component but the combination: when an agent can read, write, and reach the network, every additional MCP server adds another interface that can be misused or injected. And the ecosystem’s actual state makes it worse: server directories are swelling, most servers are maintained by third parties, and enterprises rarely have an assigned owner or review process for them — which is exactly the gap Gartner’s “domain-oriented ownership” recommendation targets.

The No-Go Zone: Three Capabilities Combined

Gartner’s most consequential judgment is a “no-go zone”: any use case that combines access to sensitive data, ingestion of untrusted content, and external communication should be excluded outright, because that is the complete exfiltration chain. An agent reads an external page (untrusted content), is influenced by instructions inside it, and then ships internal documents out — no advanced exploit required; the flow itself is the vulnerability.

The rule’s value is enforceability: a product or security team can check three boxes at design review instead of arguing about the risk level of each individual case. In practice, the cases that most often cross the line look harmless — “summarize this customer email and draft a reply” simultaneously satisfies untrusted input, sensitive context, and outbound sending.

An Action List for Engineering and Security Teams

Four actions come straight from Gartner’s recommendations and can land in order:

  • Create a formal security review process for MCP use cases, prioritizing low-risk patterns and explicitly excluding high-risk combinations
  • Give agents their own authentication and authorization identities, never permissions inherited from human users, scoped to the minimum
  • Deploy mitigations for known threat patterns: content injection defenses and continuous review of third-party MCP components
  • Apply domain-oriented ownership of MCP servers: domain experts predefine guardrails so that client access is secure by default

Gartner’s companion research is “Best Practices to Counter MCP Security Risks,” with the topic scheduled for deep dives at its Application Innovation & Business Solutions summits in Las Vegas, Tokyo, and London. Read alongside Redwood Research’s AI risk snapshot (see the AI risk snapshot), the direction is consistent: risk is shifting from “the model says the wrong thing” to “the agent does the wrong thing” — and the latter lands squarely inside engineering and security teams’ jurisdiction, becoming a built-in engineering cost for every team adopting agentic AI.

Sources

AI-assisted summary compiled from the sources above, reviewed by a human before publishing.

SHAREXEMAIL