According to a new study, Netskope AI Report: 2026, downstream data policy breaches are already the second most common AI breach in enterprises, with 924 alerts per 10,000, nearly one in ten. Only data policy violations in the upstream are more common.

Downstream breaches occur when an AI service delivers information or data to a user or agent not authorized to access it. Its frequency has more than doubled in the last year, going from an average of 12 to 31 weekly violations per organization. In the 25% of organizations with the most cases, the increase was even greater: from 72 to 206 violations per week.

Connection between AI agents and data sources

This increase is due to the rapid adoption of the Model Context Protocol (MCP), an open standard that allows AI models and agents to connect to external data sources and tools. In ten weeks, users accessing remote MCP servers grew by 250%, and MCP transactions grew by 375%.

This increase is due to the rapid adoption of the Model Context Protocol (MCP), an open standard that allows AI models and agents to connect to external data sources and tools. In ten weeks, users accessing remote MCP servers grew by 250%, and MCP transactions grew by 375%. This expands AI systems’ access to enterprise data, but also increases the risk of sensitive information reaching unauthorized recipients.

Upstream data policy violations, where users or agents send sensitive information to an AI application, remain the most common risk, with 8,752 AI alerts per 10,000. Still, the study shows that the range of threats associated with enterprise AI is expanding.

In addition to breaches in the exit phase, organizations detect incidents related to content filtering (154), command injection and jailbreaking attempts (129), and deliberate requests for sensitive information (28). Malicious code is the least common category, with five alerts per 10,000, but it is also one of the most serious, as it can be executed directly by an autonomous agent or incorporated into a broader code base.

Control over personal AI applications

The Netskope AI: 2026 study also indicates that shadow AI is unlikely to disappear. Today, 30% of enterprise AI users use only personal applications, while another 14% combine personal and organization-managed tools. Although shadow AI decreased after the implementation of managed tools, the trend stabilized in March 2026 and has since rebounded slightly. This suggests that organizations are tightening control over personal AI applications, rather than trying to move all users and use cases to a managed platform.

“The threat horizon for 2026 has moved beyond mere shadow AI detection and has entered a phase of two-way, autonomous risk,” said Ray Canzanese, director of Netskope Threat Labs. “It is no longer enough to monitor the instructions that employees send to third-party models; We must now protect the integrity of the AI ​​supply chain. The rapid integration of the Model Context Protocol (MCP) connects our internal data stores with external agents, while the rise of autonomous programming tools, such as Cursor and Claude Code, has dramatically lowered the barriers to automated execution of malicious code. For security teams, this requires moving beyond simple data monitoring to two-way inspection. “We must treat every interaction with an agent as a possible execution vector, not just a request for data.”

Other key takeaways from the data and AI report

● The average volume of AI queries tripled in the last year, from 1,498 to 4,731 per organization per week. The top 25% of organizations generate at least 19,292 queries weekly.

● Adoption of AI-based programming applications increased from 42% to 84% of organizations in the last year. Today, 75% use Claude Code and 58% use Codex, even though a year ago both had adoption rates below 1%.

● 41% of organizations use Ollama to run AI models locally, to maintain greater control over data processing and reduce dependence on cloud platforms.

● Business users accessing AI applications weekly increased from 34% to 59%. In the top 25% of organizations, at least 77% of employees use AI every week.

● Regulated data and source code each accounted for 35% of initial breaches, followed by intellectual property (20%) and passwords and keys (10%).

● The number of users exposed to malicious AI-related lures has increased markedly since March 2026. Recent campaigns include fake AI app installers, phishing pages, and Trojan-infected development tools.