This report details the increasing adoption of AI, trends in data policy violations, and AI-adjacent threats observed over the last year within organizations based in Asia.
Key findings
AI systems, tools, and applications are increasingly embedded across organizations in Asia. More organizations are deploying managed AI applications, AI’s role in everyday applications and agentic workflows is growing, and security, data, and malware risks are emerging with these shifts.
AI use continues to grow: Over the past year, active AI users rose from 55% to 74% of total users based in Asia. The use of organization-managed AI applications climbed from 41% to 74%, while the use of personal AI accounts fell from 71% to 46%. But AI activity within organizations isn’t limited to dedicated tools or direct usage: 98% of employees use applications with embedded AI features, and 92% interact with systems that use customer or user data for training.
Sensitive data travels through AI workflows: Regulated data accounts for 61% of AI-related data policy violations in Asia, followed by intellectual property at 19%, source code at 14%, and passwords and API keys at 5%. Remote Model Context Protocol (MCP) activity has surged over the period, with the volume of users up to 398%, and volume of events up to 259%. Organizations need to understand which AI applications and agents are operating within their environments, but also the users and systems they interact with, and what they can access.
Attackers are capitalizing on the AI trend: AI lures are consistently targeting corporate users, with activity rising steadily from February through June 2026 rather than in a single short burst. The rate climbed to a sustained level well above the earlier baseline over those months, with a modest peak in May reaching around 170 users per 100,000. Malicious AI link interactions followed a similar pattern, peaking at 250 per week per 100,000 users in February 2026 before settling back to around 50. Popular AI services are increasingly part of the attack chain.
AI use
Adoption and usage trends
As organizations across Asia grow more confident in adopting AI, the technology is becoming part of everyday business operations. AI use in the region has continued to climb over the past year, with the share of users actively working with AI applications rising from 55% to 74%, in line with global trends.
In parallel, organizations in Asia have made steady progress in reducing shadow AI risk within their environment by steering users away from personal AI accounts and toward organization-managed tools. Over the past year, the use of personal AI applications fell from 71% to 46%, while adoption of organization-managed AI solutions rose from 41% to 74%. At the same time, the share of users switching between personal and enterprise accounts grew from 13% to 21%, suggesting that some employees still move between managed and personal accounts as they explore new tools. This points to the need for organizations to streamline the review and approval of new AI applications while maintaining tighter instance-level controls.
Overall, these dynamics show that organizations in Asia have made progress toward managed AI deployments, improving data protection and compliance without holding back productivity. However, the shift away from personal AI use has largely stalled since March, and the overlap between personal and enterprise usage remains. Shadow AI appears harder to eliminate once organizations reach a certain level of maturity, making long-term guardrails, clear policies, and simple processes for adopting new AI tools an important part of every organization’s AI strategy in the region.
In less than a year, Anthropic Claude Platform has overtaken ChatGPT as the most widely adopted AI application in the region, used by 85% of organizations. ChatGPT and Google Gemini sit behind it, each at 74%.
Unlike ChatGPT and Gemini, the Claude Platform is not a conversational assistant but a set of APIs and tools used to build Claude into software. Its popularity suggests that much of the AI activity occurring within organizations based in the region is linked to development and integration work rather than employees chatting with an assistant. This makes visibility and control harder, because this kind of usage tends to occur within applications and services rather than in a browser tab.
The chart below shows how adoption of the leading AI applications has evolved in Asia over the past year, highlighting Anthropic Claude Platform’s swift growth in popularity. ChatGPT and Google Gemini have both maintained consistently high adoption rates throughout the period.
AI-related data policy violations
As AI adoption continues to increase in Asia, concerns around data exposure are becoming more prevalent. Employees across the region are using AI tools to summarize documents, generate reports, assist them, and streamline everyday business processes. These use cases can involve sensitive customer, business, and operational information, creating new opportunities for data exposure. Protecting sensitive information therefore remains a key priority, particularly as organizations work to identify and control the risks associated with shadow AI.
In Asia, our analysis shows that regulated data is the type of sensitive information most frequently involved in AI-related data policy violations, accounting for 61% of such events. Intellectual property follows at 19%, source code at 14%, and passwords and API keys at 5%.
Most blocked AI apps
Many organizations in Asia are restricting certain applications because of security, privacy, and compliance concerns. While specific policies differ in each organization, some applications are more consistently blocked than others, providing an indication of where organizations see the greatest risks.
DeepSeek is the most frequently blocked AI application in Asia, with 41% of organizations restricting access. Security teams point to limited transparency, data sovereignty concerns, and a platform whose behavior has been changing quickly, along with the wider uncertainty that comes with emerging AI ecosystems.
ZeroGPT follows at 36%. Many organizations treat AI-detection services as high risk because they usually require users to paste in full text, source code, or other sensitive material for analysis, meaning content leaves the organization simply to be checked.
Emergent is close behind at 35%. It is an agentic development platform that builds and deploys complete applications from natural language prompts, so it can generate code, connect to repositories, and push to live infrastructure with little human review. That mix of broad access and limited oversight is what makes security teams cautious about it.
Where these tools interact with business information, customer data, or internal systems, they create additional opportunities for sensitive information to leave the organization.
Overall, organizations in Asia are taking a cautious approach with applications that could expose sensitive data or operate outside established security and compliance controls.
Agentic AI adoption
User adoption of AI
Across the region, 75% of employees use AI applications directly, while 98% use applications that include AI-powered features. In addition, 92% interact with AI systems that use customer or user data to train models.
These figures show that AI activity often manifests through features built into applications employees already use rather than through standalone AI tools. As adoption continues to grow, organizations in Asia face a greater challenge in understanding where sensitive information is being shared and how it may be used, both through direct interactions with AI tools and through AI functionality operating in the background.
MCP: Rapidly increasing interconnectedness
MCP, the open-source standard that allows AI models to connect with external and internal data sources and tools, is seeing a sharp increase in adoption in Asia. Over the period, the number of non-human entities interacting with remote MCP servers rose by 398%, while MCP-related events grew by 259%.
MCP connections introduce additional pathways for data to move between AI applications and external systems. For organizations in the region, that makes visibility and control over these interactions increasingly important, particularly where AI agents can access business data or other sensitive resources.
These figures relate specifically to remote MCP usage, where AI agents connect to MCP servers hosted on the internet rather than locally or within an organization’s own network. They suggest that agentic AI is moving beyond experimentation, and becoming more closely integrated into day-to-day business workflows, making MCP activity an area that organizations will increasingly need to monitor and govern.
AI-adjacent threats
Categorizing AI risks
Effective AI visibility, governance, and protection start with a clear understanding of the risks organizations are facing. In Asia, upstream data policy violations account for 89% of AI-related violations, making them the most prevalent risk category. Downstream data policy violations are also widespread, reflecting the risk of exposing sensitive information both when it is entered into AI tools and when AI-generated content is shared or used elsewhere.
Malicious code-related violations remain less common, but they still pose a potentially high-impact risk because they can compromise systems, applications, and sensitive business data.
Malicious AI lures
A malicious AI lure is designed to trick users into downloading malware or visiting a malicious website by posing as a trusted AI brand or tool. In Asia, this technique caught up to 250 of every 100,000 users in May 2025. A second wave began in February 2026, when 170 of every 100,000 employees encountered a lure, and activity stayed above the normal baseline through June, with a further bump in May.
The shape of that pattern matters as much as the peaks. Lure activity in the region arrives in waves rather than at a consistent rate, and the second wave stayed well above baseline for several months rather than passing quickly, suggesting campaigns that kept working long after they were first observed.
Recent campaigns have included fake AI application installers, trojanized developer tools, and other AI-themed lures designed to take advantage of the growing interest in AI. As AI adoption continues to expand, attackers are likely to keep refining these techniques, including targeting software supply chains and distributing malicious packages that take advantage of AI-assisted development.
Malicious AI links
A malicious AI link is a harmful link returned by an AI application that a user clicks or an AI agent follows. They are similar to the malicious links attackers place in search engine results, where users may click them believing they lead to legitimate websites. Attackers can achieve this through SEO techniques, paid advertisements, or by compromising otherwise legitimate infrastructure.
The approach is similar in the AI environment, although malicious content reaches users differently. Techniques such as artificial intelligence engine optimization (AIEO) are emerging as attackers look for ways to influence the content AI models surface, while advertising is also beginning to appear within AI applications.
In Asia, the rate at which users interact with malicious AI links ranged from 50 to 120 per week per 100,000 users from June through February, before a sharp spike in February 2026 pushed it to 250. It has since held at around 50, against a typical week of roughly 82 per 100,000 users across the period. The current level sits below that, and below much of the preceding year. Still, the February spike shows how effective this technique can be, which is a reason to keep monitoring links returned by AI applications as employees increasingly rely on AI tools for more of their everyday work.
Recommendations
With the growing use of AI tools, both managed and personal, and the misuse of personal cloud apps, it is essential to strengthen visibility, improve policies, and prioritize proactive defenses to protect your organization in this fast-changing threat landscape.
Based on the trends uncovered in this report, Netskope Threat Labs strongly encourages organizations across Asia to take a fresh look at their overall security stance:
- Inspect all HTTP and HTTPS downloads, including all web and cloud traffic, to prevent malware from infiltrating your network. Netskope customers can configure their Netskope One NG-SWG with a threat protection policy that applies to downloads across all categories and all file types.
- Block access to apps that do not serve any legitimate business purpose or pose a disproportionate risk to the organization. A good starting point is a policy to allow reputable apps currently in use while blocking all others.
- Use DLP policies to detect potentially sensitive information, including source code, regulated data, passwords and keys, intellectual property, and encrypted data, being sent to personal app instances, AI apps, or other unauthorized locations.
- Use Remote Browser Isolation (RBI) technology to provide additional protection when visiting websites in categories that may pose a higher risk, such as newly observed or newly registered domains.
- Use Netskope Skylight AI Gateway to gain visibility and control over AI applications and API interactions, helping secure data flows between users, applications, and LLMs.
- Deploy Netskope Skylight AI Guardrails to enforce consistent protections against sensitive data exposure, unsafe prompts, and policy violations across managed and unmanaged AI environments.
- Use Netskope Skylight AI App Security to discover sanctioned and unsanctioned AI applications, apply real-time controls, and enforce governance policies across personal and enterprise AI use.
- Leverage Netskope Skylight AI Analytics to monitor AI adoption trends, user activities, and DLP incidents, facilitating organizations to better understand and reduce AI-related risk exposure.
- Consider Netskope Skylight AI Red Teaming to actively identify vulnerabilities and misconfigurations in private AI deployments before they may be exploited in production environments.
Netskope Threat Labs
Staffed by the industry’s foremost cloud threat and malware researchers, Netskope Threat Labs discovers, analyzes, and designs defenses against the latest cloud threats affecting enterprises. Our researchers are regular presenters and volunteers at top security conferences, including DEF CON, Black Hat, and RSA.
About this report
Netskope provides threat protection to millions of users globally. The information presented in this report is based on aggregate use data collected by the Netskope One platform for a subset of Netskope customers in Asia.
The statistics in this report are based on the period from May 1, 2025, through July 30, 2026. Stats reflect attacker tactics, user behavior, and organization policy.


