Singapore – AI adoption across organisations in Asia has increased significantly over the past year, while the expansion of AI-enabled applications and agentic workflows is creating new data protection and security challenges, according to a new report from Netskope Threat Labs.
The report, covering activity from 1 May 2025 to 30 July 2026, found that the share of users in Asia actively working with AI applications increased from 55% to 74%. At the same time, the use of organisation-managed AI applications rose from 41% to 74%, while personal AI account usage declined from 71% to 46%.
However, AI activity extends beyond dedicated AI tools. The report found that 98% of employees use applications with embedded AI features, while 92% interact with AI systems that use customer or user data to train models.
The growing use of AI is also creating new data exposure risks. Regulated data accounted for 61% of AI-related data policy violations in Asia, followed by intellectual property at 19%, source code at 14%, and passwords and API keys at 5%.
The report also identified increasing use of remote Model Context Protocol (MCP) connections, which allow AI models to connect with external and internal data sources and tools. The number of non-human entities interacting with remote MCP servers increased by 398%, while MCP-related events grew by 259%.
It also said the growth highlights the need for organisations to understand which AI applications and agents are operating within their environments, as well as the users and systems they interact with and the information they can access.
AI application adoption is also changing across the region. Anthropic Claude Platform became the most widely adopted AI application among organisations in Asia, used by 85% of organisations, ahead of ChatGPT and Google Gemini at 74% each.
According to the report, the popularity of Claude Platform reflects growing use of AI APIs and development tools rather than only conversational assistants. This can make visibility and control more difficult because AI activity may occur within applications and services rather than directly through a browser.
Organisations are also taking a cautious approach towards certain AI applications. DeepSeek was the most frequently blocked AI application in Asia, with 41% of organisations restricting access. ZeroGPT followed at 36%, while Emergent was blocked by 35%.
The report identified both data policy violations and AI-adjacent threats as areas of concern. Upstream data policy violations accounted for 89% of AI-related violations in Asia, while downstream violations also remained widespread.
Meanwhile, attackers are increasingly using AI-related themes to target employees. Malicious AI lures, including fake AI application installers and trojanised developer tools, increased during the period studied, with activity remaining above the normal baseline through June 2026.
Malicious links returned by AI applications were another emerging concern. The rate of user interactions with malicious AI links reached 250 per 100,000 users in February 2026 before settling at around 50 per 100,000 users.
The report said the increase in AI adoption means organisations will need to maintain visibility over both direct and embedded AI usage, while strengthening controls around data access and the movement of information.
The report recommended that organisations strengthen monitoring of web and cloud traffic, restrict access to applications that present disproportionate risks, and use data loss prevention policies to identify sensitive information being sent to personal application instances, AI applications or other unauthorised locations.
Greater visibility and control over AI applications and API interactions are also recommended by the report, alongside measures to monitor AI adoption, user activity and data loss prevention incidents.
The findings are based on aggregate usage data from a subset of Netskope One customers in Asia. Netskope said the statistics reflect attacker tactics, user behaviour and organisational policy during the reporting period.

