This report examines how AI is reshaping the digital footprint of organizations across ANZ and the security and data-protection challenges that come with it. It also discusses how attackers are abusing trusted cloud platforms to push malware into local organizations, and explores how the current patterns of data policy violations should serve as a call to action for organizations handling sensitive data.
Shadow AI is losing ground: Staff using personal AI accounts and sending potentially sensitive work-related data in prompts, has been a major AI security challenge in recent years. In the last twelve months, organizations in ANZ have made significant ground in curbing this Shadow AI vector, with usage rates of organization-managed AI tools more than doubling over the period, leading to a drop in personal applications’ usage. But as employees refine their preferences in terms of AI usage, and continue to explore new AI tools and applications, the amount of users bouncing between personal and enterprise accounts almost doubled as well, highlighting the need for organizations to implement frictionless processes for employees to submit new AI tools and applications for review and approval, and steer them away from creating personal accounts.
Anthropic has pulled ahead of ChatGPT: While ChatGPT remains the most used AI application in the large majority of organizations in the regions around the world that we monitor, Anthropic’s Claude is well in front in ANZ, having experienced a massive increase in adoption in just a few months. This trend is also reflected in AI API adoption, where Anthropic’s API has established a significant lead over competing providers.
Direct AI usage is just the tip of the iceberg: Nearly all employees now use software with embedded AI features, or features that feed user data into models for training purposes. It permeates workflows and operations, often in ways that do not manifest in direct usage, making discovery, monitoring, and governance all the more challenging.
Regulated data is the most at risk: In ANZ, regulated data is the category most exposed in data policy violations, ahead of intellectual property and source code. The type of information supposed to be the most tightly controlled is precisely the one most likely to leak. These findings highlight the need for solid DLP controls and clear AI rules.
Model Context Protocol (MCP) traffic grows quickly as AI and agentic workflows multiply: MCP is the open standard that lets AI models interact with data sources and tools, and MCP traffic is rising rapidly in ANZ. Much of this momentum is driven by the use of coding assistants like Claude Code and Codex. While MCP traffic is a sign that agentic AI adoption is progressing fast within organizations across ANZ, each of these connections is a new pathway for company data to move between AI apps and outside systems, and a vector of potential data leaks if not properly governed.
