Risk of AI model collapse will push zero trust data governance, Gartner says

March 23, 20262 min read2 sources
Share:
Risk of AI model collapse will push zero trust data governance, Gartner says

Gartner predicts that by 2028, half of organizations will adopt zero trust data governance to reduce the risk of AI model collapse, according to reporting by Infosecurity Magazine. The forecast reflects growing concern that enterprise AI systems will be trained on polluted, low-quality, or synthetic data that weakens model performance over time.

Model collapse describes a failure mode where models increasingly trained on AI-generated content begin to lose accuracy, diversity, and fidelity to real-world data. In practice, that can mean more hallucinations, amplified bias, weaker performance on edge cases, and less reliable outputs. Gartner’s framing treats this as a data integrity problem: organizations should not implicitly trust data simply because it comes from internal systems, known pipelines, or widely available online sources.

Zero trust data governance applies familiar security principles to AI data pipelines. That includes verifying data provenance, maintaining lineage, classifying data by trust level and sensitivity, enforcing access controls, and continuously checking datasets for contamination or drift. For security teams, the issue sits close to data poisoning and supply chain risk, even if it does not map to a specific vulnerability or CVE.

The timing matters because generative AI use has surged since 2022, while the public web is filling with machine-generated text, images, and code. Researchers have warned that recursive training on generated data can cause models to “forget” rare but important patterns and drift away from the original distribution. A widely cited paper, “The Curse of Recursion: Training on Generated Data Makes Models Forget,” helped establish model collapse as a serious technical concern.

For enterprises, the likely impact is higher spending on governance tooling, provenance tracking, and policy controls around what data can be used for training and fine-tuning. Regulated sectors such as finance, healthcare, and government may move first, especially where AI outputs affect high-stakes decisions. The broader message is that AI security is expanding beyond model behavior and application controls into the trustworthiness of the data itself.

Organizations building AI systems may also pair governance controls with privacy and secure access measures such as a VPN for remote teams handling sensitive datasets, though provenance and validation remain the central issue.

Share:

// SOURCES

// RELATED

Meta settles bellwether lawsuit alleging addictive design harmed student mental health

Meta's confidential settlement with a Washington school district marks a pivotal moment in the massive litigation against social media's psychological

6 min readMay 24

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

A sophisticated zero-day attack on Huawei routers allegedly caused Luxembourg's 2023 national telecom outage, raising severe global security concerns.

6 min readMay 23

MiniPlasma Windows 0-day enables SYSTEM privilege escalation on fully patched systems

A newly disclosed 0-day flaw, MiniPlasma, allows attackers to gain full SYSTEM control on patched Windows systems, with a public PoC accelerating risk

6 min readMay 18

The ransomware dilemma: why more than half of security chiefs would pay the price

A new survey reveals 56% of CISOs would consider paying a ransom, highlighting the intense pressure to restore operations despite official guidance.

6 min readMay 16