Autonomous AI agents increasing data risks: report

Netskope

Thursday, 17 September, 2026


Autonomous AI agents increasing data risks: report

The sharp pace and significant scale of enterprise AI deployments has redefined data risk. In the initial phase of deployment, organisations focused on preventing data loss when employees use AI tools (upstream activity), but the risk is no longer confined to outbound traffic. Insights from the Netskope ‘Threat Labs Report: Australia & New Zealand 2026’ show rapid growth in data security incidents caused by increased agentic AI activity among organisations in the ANZ region.

Downstream data policy violations — AI systems surfacing sensitive information to users not authorised to see it — are now the second ranked vector of AI security incidents within organisations in ANZ, accounting for 666 of every 10,000 alerts in organisations able to govern such risk. These numbers provide insight to others who do not have such visibility into their own systems.

Downstream incidents are often the result of AI agents’ activity, which is growing in scale. The Model Context Protocol (MCP) is an open standard that lets AI models and agents connect to data sources and tools, and their prevalence is a good indicator of agentic AI activity in a given environment. In just two months, the number of agents within ANZ organisations interacting with remote MCP servers increased by 89%, while MCP-related events grew by 69%. MCP connections create new pathways for data to flow between AI applications and other internal and external systems, and present a new risk of data loss as traditional security tools are not designed to monitor and secure this traffic.

Increase in MCP adoption over time in ANZ.

Increase in MCP adoption over time in ANZ. Source: Netskope. For a larger image click here.

Recent high-profile news stories have shown that AI agents operating without appropriate guardrails can behave in unintended ways. But malicious actors are also developing techniques to manipulate these systems. Among their methodologies are prompt injection and jailbreaking, which AI systems within ANZ organisations suffer at twice the global rate (254 of every 10,000 alerts vs 129 globally). These attacks are designed to disrupt the behaviour of AI systems, and trick them into delivering potentially harmful or sensitive content.

Using AI Engine Optimisation techniques (the equivalent of Search Engine Optimisation for AI), attackers are also managing to trick public AI tools into citing harmful links as legitimate sources in their responses, which redirect users to malicious websites. For every 100,000 workers in ANZ, an average of 67 per week clicked on malicious links contained within AI responses over the last 12 months. This peaked at 175 at the end of 2025. With most employees implicitly trusting AI response sources, this approach enables threat actors to target users without raising suspicions.

Attackers go further in exploiting this implicit trust, and are increasingly impersonating AI brands or tools to trick victims. These campaigns take various shapes, from fake AI application installers, to trojanised developer tools and other ‘AI lures’ designed to scam the victims or steal their corporate credentials. In May, 140 of every 100,000 workers in ANZ fell for AI lures. Threat actors are likely to keep refining their techniques, targeting various layers of the AI software supply chain.

“Our research outlines the increasing complexity of AI risks ANZ organisations are facing, and new threats are going to keep emerging as enterprise AI use increases and evolves,” said Ray Canzanese, Director of Netskope Threat Labs. “This is a whole new landscape that requires a new response; redesigning security architectures for the AI era, rescoping the baseline for data security practices to include monitoring and securing bidirectional AI traffic, AI agents, model behaviours, and new machine-to-machine communications protocols such as the MCP, as well as more broadly preserving the integrity of the AI supply chain.”

Additional findings include:

  • Stubborn shadow AI: More than half of employees in ANZ (55%) still use personal AI accounts at work, suggesting that fully eliminating shadow AI is going to be a hard battle. This is despite major strides in the adoption of organisation-managed AI tools, which more than doubled in the same period, from 34% to 75%.
  • Data in AI prompts: Upstream data policy violations, where users or agents send sensitive information to an AI application, remain by far the most common AI risk, accounting for 8300 of every 10,000 AI security alerts.
  • Traditional phishing abating: The number of users clicking on phishing links has dropped by almost 60%, from 91 to 41 clicks per 10,000 users.
     

Top image credit: iStock.com/MF3d

Related Articles

Why the Five Eyes AI warning should change the Board's cyber agenda

If you don't test your identity recovery in a real‍-‍life crisis scenario, you are...

The next cyber threat has arrived and identity security is key for survival

Frontier AI is poised to reshape cybercrime by making sophisticated attacks faster, cheaper and...

Faking a trusted brand is easier than ever, defending against impersonation isn’t

Organisations need to defend their brands with renewed vigour as AI‍-‍driven...


  • All content Copyright © 2026 Westwick-Farrow Pty Ltd