The 2026 Netskope Threat Labs Retail report details the increasing adoption of AI, trends in data policy violations, and malware distribution via cloud applications observed over the last year.
Key findings
This report examines how AI is becoming embedded across the retail sector and the security challenges that come with that shift. The report looks at the move toward managed AI, the growing role of AI in everyday applications and agentic workflows, and the data and malware risks emerging alongside this adoption.
AI is now built into retail work: Retailers are moving quickly from experimentation to widespread AI adoption. While personal AI usage has fallen from 70% to 44% and organization-managed AI adoption has risen from 40% to 73%, AI is now present far beyond standalone tools. 97% of employees use applications with embedded AI features, while 90% interact with AI systems that use customer or user data for training. Much of that activity happens inside apps and workflows where neither users nor security teams would notice it.
Sensitive data is following AI into the enterprise: Regulated data accounts for 56% of AI-related data policy violations in retail, making it the most exposed category, followed by source code at 20% and passwords and API keys at 16%. At the same time, remote MCP activity has surged, with agents interacting with remote MCP servers increasing by around 400% and MCP-related events growing by approximately 300%. As AI agents gain access to more data and external tools, retailers need to know what data each AI app and agent can reach, in addition to which apps employees use.
Attackers are following the AI trend: As retailers embrace AI, attackers are using the same interest in the technology to reach users. AI lure activity fell sharply from around 140 users per 100,000 in May 2025 to roughly 20 around December, before rising again to approximately 100 by March 2026. Attackers are also continuing to abuse trusted cloud platforms, with GitHub and Microsoft OneDrive used to distribute malware across 13% and 12% of retail organizations respectively. Both trends exploit the trust users already place in well-known AI and cloud brands.
AI use
AI: Adoption and usage trends
As organizations become more confident in adopting and using AI, the technology is becoming a common part of business operations. AI use across the retail sector has continued to grow over the past year, with the share of users actively using AI applications increasing from 39% to 65%, aligned with global trends.
In parallel, organizations across the retail sector have made steady progress in reducing shadow AI risk by moving users away from personal AI accounts and toward organization-managed tools. Over the past year, the use of personal AI applications declined from 70% to 44%, while adoption of organization-managed AI solutions increased from 40% to 73%. At the same time, the share of users switching between personal and enterprise accounts rose from 11% to 18%, suggesting that some employees continue to move between managed and personal AI accounts as they explore new tools. Organizations should make it faster to approve new AI apps, because a slow review gives employees a reason to fall back on personal accounts, and they should tighten instance-level controls at the same time.
Retailers have moved a long way toward managed AI, but the shift has slowed. Since the spring, the shift away from personal AI use has largely stalled, while the overlap between personal and enterprise usage remains. This suggests that shadow AI is proving harder to eliminate once organizations reach a certain level of maturity, making long-term guardrails, clear policies, and simple processes for adopting new AI tools an important part of every retail organization’s AI strategy.
Retail’s AI app preferences differ from global trends. Anthropic Claude Platform has overtaken ChatGPT as the most widely adopted AI application, used by 96% of organizations, compared with 84% for ChatGPT. Claude Code, Anthropic’s specialized coding tool, follows closely at 83%, while Anthropic Claude, the conversational assistant used for general tasks and writing, stands at 79%, and Google Gemini at 78%. Anthropic’s broader presence reflects the different roles of its products: Claude serves as a general-purpose assistant, Claude Code supports software development, and the Claude Platform provides the APIs and tools businesses use to integrate Claude into their own applications. This strong adoption across Anthropic’s products points to growing AI use beyond conversational tools and into enterprise and development workflows.
The chart below shows how adoption of the leading AI applications has evolved across the retail sector over the past year, highlighting a clear shift in application preference. ChatGPT has remained relatively stable throughout the period, maintaining consistently high levels of adoption. In contrast, Anthropic Claude Platform saw a sharp increase beginning in December 2025, with adoption accelerating rapidly in the following months and eventually overtaking ChatGPT around February 2026. Google Gemini followed a different trend, with adoption declining from April 2026.
AI: App usage and data policy violation
As AI adoption continues to increase across the retail sector, concerns around data exposure are becoming more relevant. Retail organizations are using AI tools to summarize documents, generate reports, assist employees, and support everyday business processes. These use cases can involve sensitive customer, business, and operational information, creating additional opportunities for data exposure. As a result, protecting sensitive information remains a key priority, particularly as retailers work to identify and control the risks associated with shadow AI.
Analysis of AI-related data policy violations in the retail sector shows that regulated data represents the largest share of attempts to include sensitive information, accounting for 56% of observed activity. Source code follows at 20%, while passwords and API keys account for 16%. Intellectual property represents the remaining 8%.
Most blocked AI apps
Organizations across the retail sector are taking a measured approach to AI adoption, with many restricting certain applications because of security, privacy, and compliance concerns. While specific policies differ by organization, the most-blocked applications offer a useful indication of where retailers see the greatest risks.
Particular Audience is the most frequently blocked AI application, restricted by 46% of organizations. ZeroGPT follows at 37%, while Landbot and DeepSeek are each restricted by 34%. These applications support a range of AI use cases, from content generation and detection to customer-facing chatbots and general-purpose AI services. Where these tools interact with business information, customer data, or internal systems, they can create additional opportunities for sensitive information to leave the organization.
Retailers appear to block tools that could move data outside existing controls rather than blocking AI as a category.
Agentic AI adoption
User adoption of AI
AI adoption is now present across multiple layers of the retail environment. In the sector, 66% of employees use AI applications directly, while 97% use applications that include AI-powered features. In addition, 90% interact with AI systems that use customer or user data to train models.
These figures show how widely AI has become part of everyday work, often through features built into applications employees already use rather than through standalone AI tools. As this adoption continues to grow, retailers face a greater challenge in understanding where sensitive information is being shared and how it may be used, both through direct interactions with AI tools and through AI functionality operating in the background.
MCP: Rapidly increasing interconnectedness
MCP, the open-source standard that allows AI models to connect with external data sources and tools, is seeing a sharp increase in adoption across the retail sector. Over the period, the number of agents interacting with remote MCP servers grew by around 400%, while MCP-related events increased by approximately 300%.
Each remote MCP connection is another route for data to move between an AI app and an outside system, so retailers need visibility into those connections, especially where agents can reach business data.
These figures relate specifically to remote MCP usage, where AI agents connect to MCP servers hosted on the internet rather than locally or within an organization’s own network. The rapid increase suggests that agentic AI is moving beyond experimentation and becoming more closely integrated into day-to-day business workflows, and security teams would do well to add MCP traffic to what they already monitor.
AI-adjacent threats
Categorizing AI Risks
Effective AI visibility, governance, and protection start with a clear understanding of the risks organizations are facing. Across the retail sector, upstream data policy violations account for 85% of AI-related violations, making them the most prevalent risk category. Downstream data policy violations are also widespread, reflecting the potential for sensitive information to be exposed both when it is entered into AI tools and when AI-generated content is shared or used elsewhere.
Malware-related violations remain less common, but they continue to represent a potentially high-impact risk because of their ability to compromise systems, applications, and sensitive business data.
Malicious AI lures
A malicious AI lure is designed to trick users into downloading malware or visiting a malicious website by posing as a trusted AI brand or tool. In the retail sector, AI lure activity reached around 140 users per 100,000 in May 2025 before gradually declining to roughly 20 users per 100,000 around December 2025.
Activity then increased again, reaching about 100 users per 100,000 by March 2026. Activity rises and falls, but it hasn’t gone away, because employees keep searching for new AI tools.
Recent campaigns have included fake AI application installers, trojanized developer tools, and other AI-themed lures designed to take advantage of the growing interest in AI. As AI adoption continues to expand, attackers are likely to keep adapting these techniques, including targeting software supply chains and distributing malicious packages that take advantage of AI-assisted development.
Malicious AI links
A malicious AI link is a harmful link returned by an AI application that a user clicks or an AI agent follows. They are similar to the malicious links attackers place in search engine results, where users may click them believing they lead to legitimate websites. Attackers can achieve this through SEO techniques, paid advertisements, or by compromising otherwise legitimate infrastructure.
The approach is similar in the AI environment, although the way malicious content reaches users is changing. Techniques such as artificial intelligence engine optimization (AIEO) are emerging as attackers look for ways to influence the content surfaced by AI models, while advertising is also beginning to appear within AI applications.
In the retail sector, the rate at which users encountered malicious AI links ranged from around 40 to more than 160 encounters per week per 100,000 users. The variation highlights the growing need to monitor links returned by AI applications, particularly as employees rely more on AI tools for everyday tasks.
Malware downloads
Malware distribution via cloud apps
Attackers continue to take advantage of legitimate cloud platforms to distribute malware, relying on the trust users place in familiar services. Although cloud providers regularly remove malicious content, even a short window before detection can give attackers enough time to infect devices and potentially move further within an organization.
Across the retail sector, GitHub and Microsoft OneDrive are among the most commonly abused platforms for malware distribution, affecting 13% and 12% of organizations respectively. The use of trusted cloud services makes malicious activity harder to distinguish from normal business traffic and reflects a broader shift away from obviously suspicious domains toward established platforms that users and security teams already expect to see.
Recommendations
With the growing use of AI tools, both managed and personal, and the misuse of personal cloud apps, it is essential to strengthen visibility, improve policies, and prioritize proactive defenses to protect your organization in this fast-changing threat landscape.
Based on the trends uncovered in this report, Netskope Threat Labs encourages organizations across the retail sector to take a fresh look at their overall security stance:
- Inspect all HTTP and HTTPS downloads, including all web and cloud traffic, to prevent malware from infiltrating your network. Netskope customers can configure their Netskope One NG-SWG with a threat protection policy that applies to downloads across all categories and all file types.
- Block access to apps that do not serve any legitimate business purpose or pose a disproportionate risk to the organization. A good starting point is a policy to allow reputable apps currently in use while blocking all others.
- Use DLP policies to detect potentially sensitive information, including source code, regulated data, passwords and keys, intellectual property, and encrypted data, being sent to personal app instances, AI apps, or other unauthorized locations.
- Use Remote Browser Isolation (RBI) technology to provide additional protection when visiting websites in categories that may pose a higher risk, such as newly observed or newly registered domains.
- Use Netskope Skylight AI Gateway to gain visibility and control over AI applications and API interactions, helping secure data flows between users, applications, and LLMs.
- Deploy Netskope Skylight AI Guardrails to enforce consistent protections against sensitive data exposure, unsafe prompts, and policy violations across managed and unmanaged AI environments.
- Use Netskope Skylight AI App Security to discover sanctioned and unsanctioned AI applications, apply real-time controls, and enforce governance policies across personal and enterprise AI use.
- Leverage Netskope Skylight AI Analytics to monitor AI adoption trends, user activities, and DLP incidents, facilitating organizations to better understand and reduce AI-related risk exposure.
- Consider Netskope Skylight AI Red Teaming to actively identify vulnerabilities and misconfigurations in private AI deployments before they may be exploited in production environments.
Netskope Threat Labs
Staffed by the industry’s foremost cloud threat and malware researchers, Netskope Threat Labs discovers, analyzes, and designs defenses against the latest cloud threats affecting enterprises. Our researchers are regular presenters and volunteers at top security conferences, including DEF CON, Black Hat, and RSA.
About this report
Netskope provides threat protection to millions of users globally. The information presented in this report is based on aggregate use data collected by the Netskope One platform for a subset of Netskope customers in the retail industry.
The statistics in this report are based on the period from July 1, 2025, through July 30, 2026. Stats reflect attacker tactics, user behavior, and organization policy.


