AI Systems Are Showing Staff Data They Should Not See

AI systems inside Australian and New Zealand organisations are surfacing sensitive information to people who are not cleared to see it. The problem is now the second most common category of AI security incident in the region according to a new report.

These downstream data policy violations account for 666 of every 10,000 AI security alerts. The finding comes from the Netskope Threat Labs Report Australia and New Zealand 2026.

The report draws on aggregated usage data from Netskope One, across a subset of the vendor's ANZ customers. It covers 1 July 2025 to 15 July 2026.

The finding shifts where the risk sits. Early enterprise AI controls were built to stop staff sending confidential material into a chatbot. Downstream violations run the other way, with the system returning material the user was never entitled to.

Upstream violations remain far more common at 8,300 of every 10,000 alerts. But downstream incidents now occur in roughly 89 per cent of organisations Netskope monitors.

Netskope attributes much of the downstream activity to AI agents. It uses Model Context Protocol traffic as a proxy for how far agentic deployment has progressed.

Over two months, the number of agents in ANZ organisations interacting with remote MCP servers rose 89 per cent. MCP-related events grew 69 per cent over the same period.

Those figures cover remote MCP only, where agents connect to servers on the internet rather than inside the organisation's network. The most common clients are coding assistants.

Each connection is a fresh pathway for data to move between AI applications and outside systems. Netskope notes that conventional security tooling was not built to inspect this traffic.

Attacks aimed at the model, not the network

Prompt injection and jailbreaking attempts against AI systems in ANZ run at twice the global rate. The region records 254 of every 10,000 alerts against 129 globally.

A second technique exploits user trust in AI answers rather than the model itself. Attackers use artificial intelligence engine optimisation, the AI equivalent of search engine optimisation, to get malicious links cited as legitimate sources.

Across the year, an average of 67 workers per 100,000 per week in ANZ clicked a malicious link returned by an AI tool. The rate ranged from about 26 to more than 175 per week, peaking at the end of 2025.

Impersonation of AI brands is also growing. Campaigns have used fake AI application installers, trojanised developer tools and other AI-themed lures. In May, 140 of every 100,000 ANZ workers fell for one.

"Our research outlines the increasing complexity of AI risks ANZ organisations are facing, and new threats are going to keep emerging as enterprise AI use increases and evolves," said Ray Canzanese, Director of Netskope Threat Labs.

He called for security architectures to be redesigned for bi-directional AI traffic, agents, model behaviours and machine-to-machine protocols such as MCP.

Regulated data accounts for the largest share of attempted leaks in AI prompts at 47 per cent. Intellectual property follows at 29 per cent and source code at 13 per cent. Passwords and API keys account for 10 per cent, and encrypted data 1 per cent.

The category subject to the tightest handling rules is therefore the one most likely to move. Netskope points to data loss prevention coverage and explicit AI usage rules as the response.

Shadow AI is shrinking, not gone

Use of organisation-managed AI tools more than doubled over the year, from 34 per cent to 75 per cent. Personal AI application use fell from 76 per cent to 55 per cent.

The share of users switching between personal and enterprise accounts almost doubled, from 11 per cent to 21 per cent. Netskope reads this as evidence that approval processes are too slow for the pace at which staff find new tools.

Direct use is only part of the exposure. In ANZ, 74 per cent of employees use AI applications directly. Ninety-seven per cent use applications with AI features embedded. Ninety-three per cent interact with systems that use customer or user data to train models.

Anthropic's Claude Platform is now the most widely adopted AI application in ANZ at 81 per cent of organisations. ChatGPT sits at 68 per cent and Microsoft 365 Copilot at 66 per cent.

The ranking inverts the global pattern, where ChatGPT still leads. Claude adoption began climbing sharply in December 2025 and overtook ChatGPT around March 2026.

Netskope's recommendations include inspecting all HTTP and HTTPS downloads and blocking applications without a business purpose. It also advises DLP policies for AI apps and isolating high risk browsing.