Regulated data drives more than half of AI policy violations in retail, research finds

by

Bernard Parado

-

2 minutes ago

Singapore – Regulated data, including personal, financial and payment information, accounts for 56% of AI-related data policy violations observed across the global retail sector, according to new research from Netskope.

Source code makes up a further 20% of violations, while passwords and API keys account for 16%, the research found.

The findings draw on aggregated data from a subset of Netskope’s retail customers worldwide and do not offer a geographical breakdown. Even so, they carry implications for retailers in Southeast Asia and other markets as AI adoption accelerates across customer experiences, business applications and everyday workflows.

Employee use of AI has climbed sharply over the past year. The proportion of retail employees actively using AI applications rose from 39% to 65% during the period under review.

Meanwhile, 97% of employees now use applications that contain AI-powered features, and 90% interact with AI systems that draw on customer or user data to train models.

In response, retailers are moving to bring more AI activity under corporate oversight. Adoption of organisation-managed AI applications rose from 40% to 73%, while personal AI use fell from 70% to 44% over the same period.

However, the share of users switching between personal and enterprise accounts increased from 11% to 18%, suggesting that the line between managed and personal AI use is becoming increasingly blurred.

These findings underline the need for retailers to understand not just which AI applications their employees use, but also what information those applications can access, how it is processed and where it may ultimately be sent.

AI’s interaction with business systems is also growing more complex. The number of AI agents connecting to remote Model Context Protocol (MCP) servers rose by approximately 400% during the reporting period, while MCP-related activity overall increased by around 300%.

MCP allows AI systems to connect with external tools and data sources, opening additional pathways through which business and customer information may travel.

“Retailers are moving beyond simply experimenting with AI and are starting to embed it across everyday operations, customer experiences, and business workflows,” said Gianpietro Cutolo, Cloud Threat Researcher at Netskope.

“But as AI becomes more deeply connected to the data and systems that power the retail business, the risks become harder to separate from the opportunities. The challenge is no longer deciding whether to use AI, but making sure it can be used at the speed the business demands without losing control of sensitive customer and company data. Retailers that can combine rapid AI adoption with strong visibility and governance will be best placed to turn AI into a competitive advantage without creating unnecessary risk,” Cutolo further explained.

Beyond the headline figures, the research points to a growing set of risks tied to how data moves into AI tools in the first place. Some 85% of AI-related policy violations are upstream, involving data sent into AI tools rather than data returned from them.

Malicious activity themed around AI is also rising. AI-themed malicious lure activity increased by approximately 400% between December 2025 and March 2026, climbing from around 20 to approximately 100 affected users per 100,000.

Retail users, in turn, encountered malicious links returned by AI applications at rates ranging from approximately 40 to more than 160 encounters per 100,000 users each week.

On application usage, Particular Audience was the most frequently blocked AI application, restricted by 46% of retail organisations. ZeroGPT followed at 37%, while Landbot and DeepSeek were each blocked by 34%.

By contrast, Anthropic’s Claude Platform was used by 96% of retail organisations in the dataset, ahead of ChatGPT at 84%. Claude Code was used by 83% of organisations.

Trusted cloud services also continue to be exploited to distribute malware. GitHub and Microsoft OneDrive were each used to distribute malware across 13% and 12% of retail organisations respectively.

Recognise the innovators redefining commerce at the Retail & E-commerce Excellence Awards Asia Pacific 2026! Taking place this December 2026, we celebrate the region’s most impactful retail strategies, standout e-commerce experiences, and forward-thinking leaders—submit your entries today!
Honour the women shaping the future of marketing and technology at the Empowered Women Awards 2026! This December 2026, we celebrate inspiring leaders, changemakers, and rising voices driving impact across the industry—submit your entries today!
Share

RECENT ARTICLES

Regulated data drives more than half of AI policy violations in retail, research finds
Alibaba outlines full-stack AI roadmap spanning chips, cloud, models and agents
Tech giants form alliance to tackle AI agent security gap
AI-assisted tools drive more targeted malware as network attacks decline, report finds
VAST Data unveils confidential AI runtime to secure enterprise data
Ellipse 3

RELATED ARTICLES

Netskope rebrands AI security suite, launches Agent Action Control
NetskopeDataSecCommandCenter
Netskope appoints Antony Prasad as Senior Channel and Partnership Lead for Southeast Asia
Ellipse 3

FEATURED ARTICLES

'Retail & E-Commerce Innovation Summit' returns for its 2nd edition in the Philippines — initial speaker lineup revealed
‘Retail & E-Commerce Excellence Awards Asia Pacific
Empowered Women Awards 2026 to honour leading women trailblazing the technology and marketing industries

Subscribe to UpTech Media Newsletter

JOIN OUR NEWSLETTER

Subscribe to our newsletter to get the latest APAC marketing news.