Netskope report: AI usage is increasing in retail, but the data challenge is growing

Netskope report: AI usage is increasing in retail, but the data challenge is growing

Netskope report: AI usage is increasing in retail, but the data challenge is growing

Information
redazione

According to new research by Netskope Threat Labs, regulated data, including sensitive information such as personal or payment data, accounts for 56% of AI-related data policy violations in the retail sector.

Source code represents a further 20% of violations, while passwords and Api keys account for 16%.

AI in retail

Artificial intelligence is becoming increasingly integrated into retail activities, and the percentage of employees actively using AI applications rose from 39% to 65% over the past year, while 97% now use applications that include AI-based functionality and 90% interact with AI systems that use customer or user data to train models.

Retailers are responding by seeking to bring a greater proportion of these activities under corporate control: the adoption of AI tools managed by the organisation has in fact increased from 40% to 73%. Personal use of AI has fallen compared with the 70% in the previous year, but remains significant, with 44% of employees continuing to use personal tools. The boundary between personal and corporate use is also becoming less distinct: the percentage of users switching from personal accounts to corporate accounts and vice versa rose from 11% to 18%.

AI interaction with corporate systems

The way AI interacts with corporate systems is also becoming more complex. The number of AI agents interacting with remote Mcp (Model Context Protocol) servers has increased by approximately 400%, while activities related to Mcp have grown by approximately 300%. These connections allow AI systems to interact with external tools and data sources. Consequently, it will become increasingly important for retailers to understand not only which AI applications are being used, but also what information these systems can access.

“Retailers are moving beyond simply experimenting with AI and are beginning to integrate it into daily activities, customer experiences and business workflows,” said Gianpietro Cutolo, cloud threat researcher at Netskope. “But the more deeply AI becomes connected to the data and systems on which the retail business relies, the more difficult it becomes to separate risks from opportunities. The challenge is no longer deciding whether to use AI, but ensuring that it can be adopted at the speed the business requires without losing control over customers’ and the company’s sensitive data. Retailers that manage to combine rapid AI adoption with strong visibility and governance will be best positioned to turn artificial intelligence into a competitive advantage without introducing unnecessary risks.”

Other research findings

  • 85% of AI-related violations occur upstream, meaning they concern data sent to AI tools, compared with 9,5% downstream, relating to AI-generated outputs, and 2,5% attributable to content filtering.
  • Activities related to AI-themed malicious lures increased by 400% between December 2025 and March 2026.
  • Retail users encountered and clicked on malicious links returned by AI applications at a rate ranging from approximately 40 to more than 160 cases per 100.000 users per week.
  • Particular Audience is the most frequently blocked AI application, with restrictions applied by 46% of retail organisations, followed by ZeroGpt at 37% and Landbot and DeepSeek, both at 34%.
  • Anthropic Claude Platform is now used by 96% of the retail organisations included in the dataset, ahead of ChatGpt, used by 84%, and Claude Code, at 83%.

This article was translated from the original Italian version with the assistance of artificial intelligence. In case of discrepancies, please refer to the original Italian version.

Advertisement Advertisement