SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Netskope says downstream AI data breaches are surging

Netskope says downstream AI data breaches are surging

Wed, 29th Jul 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Netskope has published its 2026 AI report, which found that downstream data policy violations are now the second most common enterprise AI violation.

The data shows 924 downstream violations for every 10,000 AI alerts, second only to upstream data policy violations at 8,752 per 10,000. Netskope defines downstream violations as incidents in which an AI service returns information that a user or agent is not authorised to access.

Average downstream violations more than doubled over the past year, rising from 12 to 31 per organisation each week. Among the top 25% of organisations, the increase was steeper, climbing from 72 to 206 violations a week.

The report links that rise to the spread of the Model Context Protocol, or MCP, an open standard that allows AI models and agents to connect to external data sources and tools. Over a 10-week period, the number of users accessing remote MCP servers rose by 250%, while MCP transactions increased by 375%.

That shift points to a change in how AI risks appear inside companies. Earlier concerns focused largely on information being sent into third-party tools. The newer pattern centres on information being returned by connected systems to people or software agents without permission.

Upstream violations still dominate by volume. These incidents occur when users or agents send sensitive information to an AI application, and they remain the largest category by a wide margin.

Beyond those two categories, the report found a broader spread of threats. Content filtering violations accounted for 154 alerts per 10,000, prompt injection and jailbreaking attempts reached 129, and deliberate requests for sensitive information stood at 28.

Malicious code was the smallest category by volume, at five alerts per 10,000. Its severity remains high because code generated or handled through AI tools may be executed directly by autonomous agents or added to broader software projects.

Shadow AI

The findings also suggest that unauthorised use of personal AI tools remains entrenched in many workplaces. Netskope found that 30% of enterprise AI users access only personal AI applications, while another 14% use both personal and organisation-managed tools.

According to the report, shadow AI use had fallen as businesses introduced managed tools, but that decline levelled off around March 2026 and has since begun to edge up again. The pattern suggests some organisations are restricting personal tools rather than shifting all staff to approved platforms.

Overall AI use also continued to rise. The share of enterprise users accessing AI applications each week increased from 34% to 59%, while in the top 25% of organisations, at least 77% of employees now use AI every week.

Prompt volumes also rose sharply. Average AI prompt activity tripled over the past year, from 1,498 to 4,731 prompts per organisation per week, and the top quartile of organisations generated at least 19,292 prompts each week.

Coding tools

AI coding applications recorded some of the fastest adoption in the data. Their use rose from 42% to 84% of organisations over the past year, with Claude Code used by 75% of organisations and Codex by 58%, despite both being below 1% a year earlier.

The report also found that 41% of organisations use Ollama to run AI models locally. That points to a preference among some businesses to keep tighter control over where data is processed rather than relying entirely on cloud-based systems.

In upstream violations, regulated data and source code each made up 35% of incidents. Intellectual property accounted for 20%, while passwords and keys represented 10%.

The number of users encountering malicious AI lures also increased sharply from March 2026. Recent campaigns included fake AI application installers, phishing pages, and trojanised developer tools.

The dataset was drawn from aggregated usage data collected through the Netskope One platform from a subset of Netskope customers between June 2025 and July 2026. The report therefore reflects activity observed across customer environments rather than a survey of broader business sentiment.

Ray Canzanese, Director of Netskope Threat Labs at Netskope, described the shift as a new stage in enterprise AI security. "The 2026 threat landscape has moved beyond shadow AI discovery into a phase of bidirectional, agentic risk," he said. "We are no longer just monitoring the prompts employees send to third-party models; we are now governing the integrity of the AI supply chain. The rapid integration of the Model Context Protocol effectively bridges our internal data stores with external agents, while the surge in autonomous coding tools like Cursor and Claude Code has drastically lowered the barrier for automated, malicious code execution. For security teams, this mandates a pivot from simple data to bidirectional inspection. We need to treat every agentic interaction as a potential execution vector, not just a data request."