Retailers tamp down shadow AI but struggle to oversee agentic sprawl | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Dive Brief:

  • The retail sector’s use of AI has surged over the past year, and while some trends point to greater security oversight of AI tools, others suggest that organizations still have a long way to go.
  • “Retailers are moving quickly from experimentation to widespread AI adoption,” the security firm Netskope said in a report published on Tuesday.
  • Netskope offered several recommendations for how businesses could improve their visibility and control over AI use, including to limit the exposure of sensitive data.

Dive Insight:

Retailers have tightened their grips on employees’ use of AI, Netskope found, to the point that most tools are centrally managed rather than individually installed. The share of retail employees using ungoverned AI tools fell from 70% to 44% since Netskope’s last annual report, while the share of employees using officially approved tools rose from 40% to 73%. Overall, two-thirds of retail employees use some form of standalone AI tool.

But that good news comes with a caveat, according to the report, because standalone AI tools aren’t the only security risk facing organizations. Nearly all retail employees reported using software that contained AI features, and 90% said they used AI tools that are trained on customer data.

“As this adoption continues to grow,” Netskope researchers wrote, “retailers face a greater challenge in understanding where sensitive information is being shared and how it may be used, both through direct interactions with AI tools and through AI functionality operating in the background.”

Those visibility challenges can have serious consequences for retailers if their lack of oversight leads to the exposure of customer data. Of all the AI-related data policy violations that Netskope tracked, 56% involved data subject to federal or state regulation. (An additional 20% involved the exposure of source code, while 16% involved the leak of passwords or API keys.) Customer data breaches can have serious reputational and regulatory consequences for retailers, particularly those in competitive markets.

Agentic AI has also grown as a security concern, particularly as many businesses lack the ability to track which remote servers those agents are accessing. Netskope said it observed a 400% increase in the number of retail-sector AI agents that interacted with remote Model Context Protocol (MCP) servers during the survey period.

“This growth is important because remote MCP connections introduce additional pathways for data to move between AI applications and external systems,” Netskope researchers wrote. “For retailers, this makes visibility and control over these interactions increasingly important, particularly where AI agents can access business data or other sensitive resources.”

As employees seek out new AI tools, hackers are designing lures that mimic trusted AI applications. This phishing activity declined from May 2025 to December 2025, before picking up again in early 2026, according to Netskope’s report. By March, AI-related phishing lures reached roughly 100 users per 100,000. Netskoope said this phishing strategy “remains an ongoing threat as employees continue to use and search for new AI tools.”

Retailers can take several steps to protect themselves from security crises associated with AI tools, Netskope said, including blocking access to unnecessary apps, inspecting web traffic and using data-loss-prevention policies to detect sensitive information being transmitted to ungoverned AI tools.

Netskope’s report is based on data collected between July 1, 2025, and July 30, 2026.

——————————————————-


Click Here For The Original Source.