New research from Netskope Threat Labs has found that regulated data, including sensitive information such as personal or payment data, accounts for 56% of AI-related data policy violations in the retail sector. Source code accounts for a further 20% of violations, while passwords and API keys make up 16%, higher than the cross-industry average (10%).
But AI security is no longer confined to upstream activity, which consists in preventing sensitive data loss when employees use AI tools, and has largely been the focus for organisations in recent years. Downstream data policy violations, where AI systems surface sensitive information to users not authorised to see it, are now the second ranked vector of AI security incidents within retail organisations, now accounting for 9.5% of all AI security alerts within organisations able to govern such risk.

Meanwhile, many retailers are still focused on trying to bring more of the upstream activity from their employees under control, by deploying organisation-managed AI tools. As a result, the use of corporate AI accounts has risen from 40% to 73%. The use of personal AI accounts has fallen sharply, from 70% the previous year, but remains high, with 44% of employees in the retail sector still using personal AI accounts for work purposes. The boundary between the two is also becoming less clear, with the proportion of employees switching between personal and enterprise accounts rising from 11% to 18%.

The way AI systems interact with corporate environments is also becoming more complex. The number of AI agents interacting with remote Model Context Protocol (MCP) servers increased by around 400%, while MCP-related events rose by approximately 300%. MCP connections allow AI systems to interact with external and internal tools and data sources to achieve their goals, and are a good indicator of the evolution in the deployment of AI agents within a given environment. Retailers will need to understand what information those systems can access to govern their behaviour and actions.

“Retailers are moving beyond simply experimenting with AI and are starting to embed it across everyday operations, customer experiences, and business workflows,” said Gianpietro Cutolo, Cloud Threat Researcher at Netskope. “But as AI becomes more deeply connected to the data and systems that power the retail business, the risks become harder to separate from the opportunities. The challenge is no longer deciding whether to use AI, but making sure it can be used at the speed the business demands without losing control of sensitive customer and company data. Retailers that can combine rapid AI adoption with strong visibility and governance will be best placed to turn AI into a competitive advantage without creating unnecessary risk.”
Additional key findings include:
- AI-themed malicious lure activity rose 400% between December 2025 and March 2026.
- Retail employees encountered and clicked malicious links returned by AI applications at rates ranging from around 40 to more than 160 per 100,000 users per week.
- Particular Audience is the most frequently blocked AI application, restricted by 46% of retail organisations, followed by ZeroGPT at 37%, and Landbot and DeepSeek at 34% each.
- Anthropic Claude Platform is now used by 96% of retail organisations in the dataset, ahead of ChatGPT at 84%, with Claude Code at 83%.
The Netskope Threat Labs Report Retail 2026 report is based on aggregated usage data collected through the Netskope One platform from a subset of Netskope customers in the retail industry between 1 May 2025 and 30 July 2026.





