Gartner has a forecast worth sitting with: by 2029, most privacy problems will not come from stolen data. They will come from AI guessing things about people that were never written down anywhere in the first place.
Here is what that means in plain terms. An AI system can look at scattered, harmless pieces of information: who emails whom inside a company, what conference someone attended, an old forum post, a shopping pattern, and stitch them into a private fact, like a health condition, a salary range, or a personal weakness someone could exploit. None of that information was ever stolen. It was sitting in plain sight, just spread out.
This is not a future problem. A 2019 study found that 99.98 percent of Americans could be correctly identified in a supposedly anonymous dataset using just 15 basic details like age, gender, and zip code. A newer 2026 study went further: researchers built an AI agent that unmasked anonymous online users across sites like Hacker News, Reddit, and LinkedIn correctly two out of three times, for a cost of one to four dollars per person. A task that used to take a skilled human investigator hours now takes a script and pocket change.
The business risk here is not abstract. Andrew Obadiaru, a cybersecurity executive quoted in the original reporting, points out that AI can figure out who has spending authority, who runs a critical system, or who is likely to click a phishing link, just by connecting an employee directory to social media activity and public filings. None of that requires breaking in anywhere. This is exactly why business email scams keep getting more expensive: the FBI's most recent crime report logged over 3 billion dollars in losses from these scams in a single year, up 16 percent from the year before. Attackers now know who to target before they send the first message.
The uncomfortable part is that privacy law has not caught up. Rules like GDPR and HIPAA were built to protect names, addresses, and medical records directly. They were not built for a world where AI can arrive at the same sensitive conclusion without ever touching a protected record. Some regulators are starting to argue that inferred personal data should count too, but that is not settled law anywhere yet.
For a business, the practical shift is this: stop asking only "is this data sensitive" and start asking "what could this data reveal once combined with everything else out there." Employee directories, supplier lists, old customer records, none of it looks dangerous alone. Combined and run through AI, it becomes a map of your organization that a stranger can build for the price of a coffee. Deleting data you no longer need is no longer just good housekeeping. It is the cheapest defense you have against a threat that did not exist five years ago.