Netskope est de nouveau reconnu comme un leader dans le Magic Quadrant™ de Gartner® pour les plateformes SASE et Security Service Edge

Télécharger le rapport

fermer
fermer
«  »
Le guide stratégique pour sécuriser l'IA
Ce guide explore les six principaux défis de sécurité auxquels les organisations sont confrontées lorsqu'elles adoptent l'IA, ainsi que des stratégies éprouvées et concrètes pour les relever.
Essayez Netskope
Mettez la main à la pâte avec la plateforme Netskope
C'est l'occasion de découvrir la plateforme Netskope One single-cloud de première main. Inscrivez-vous à des laboratoires pratiques à votre rythme, rejoignez-nous pour des démonstrations mensuelles de produits en direct, faites un essai gratuit de Netskope Private Access ou participez à des ateliers dirigés par un instructeur.
MQ pour SASE et SSE 2026
Netskope est de nouveau reconnu comme un leader dans le Magic Quadrant™ de Gartner® pour les plateformes SASE et Security Service Edge
Découvrez pourquoi Gartner® a nommé Netskope Leader du Magic Quadrant™ 2026 pour les plateformes Secure Access Service Edge (SASE) et pour le Security Service Edge
Rapport sur les risques et la maturité face à l'IA
Rapport sur les risques et la maturité face à l'IA
Comparez votre organisation à l'aide d'une étude sur les défis et les stratégies de sécurité de l'IA, menée par Cybersecurity Insiders.
Rapport sur les risques et la maturité face à l'IA
Rapport sur les risques et la maturité face à l'IA
Comparez votre organisation à l'aide d'une étude sur les défis et les stratégies de sécurité de l'IA, menée par Cybersecurity Insiders.
Prévention des pertes de données (DLP) pour les Nuls eBook
La prévention moderne des pertes de données (DLP) pour les Nuls
Obtenez des conseils et des astuces pour passer à un système de prévention des pertes de données (DLP) dans le nuage.
Réseau SD-WAN moderne avec SASE pour les nuls
SD-WAN moderne pour les nuls en SASE
Cessez de rattraper votre retard en matière d'architecture de réseau
Identification des risques
Advanced Analytics transforme la façon dont les équipes chargées des opérations de sécurité utilisent les données pour mettre en œuvre de meilleures politiques. Avec Advanced Analytics, vous pouvez identifier les tendances, cibler les domaines préoccupants et utiliser les données pour prendre des mesures.
The Lens
«  »
Découvrez les dernières nouvelles et opinions de l'équipe de Netskope. La lentille combine nos blogs, nos podcasts et nos études de cas, avec New contenu ajouté chaque semaine.
Support technique de Netskope
Support technique de Netskope
Nos ingénieurs d'assistance qualifiés sont répartis dans le monde entier et possèdent des expériences diverses dans les domaines de la sécurité du cloud, des réseaux, de la virtualisation, de la diffusion de contenu et du développement de logiciels, afin de garantir une assistance technique rapide et de qualité
«  »
L'IA sur la voie rapide
Le roadshow AI in the Fast Lane de Netskope réunit des professionnels de la sécurité pour discuter de la façon dont les organisations utilisent l'IA aujourd'hui et de la manière dont une stratégie de sécurité globale peut créer un modèle plus intelligent, plus sûr et à l'épreuve du temps.
Vidéo Netskope
Formation Netskope
Grâce à Netskope, devenez un expert de la sécurité du cloud. Nous sommes là pour vous aider à achever votre transformation digitale en toute sécurité, pour que vous puissiez profiter pleinement de vos applications cloud, Web et privées.

This report analyzes the primary cybersecurity risk trends impacting Retail organizations. It addresses the growing adoption of generative AI (AI) tools and their associated data security challenges. Furthermore, it illustrates the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and AI platforms.

12 min read

Principales conclusions lien lien

This report examines how AI is becoming embedded across the retail sector and the security challenges that come with that shift. The report looks at the move toward managed AI, the growing role of AI in everyday applications and agentic workflows, and the data and malware risks emerging alongside this adoption.

AI is becoming deeply embedded in retail: Retailers are moving quickly from experimentation to widespread AI adoption. While personal AI usage has fallen from 70% to 44% and organization-managed AI adoption has risen from 40% to 73%, AI is now present far beyond standalone tools. 97% of employees use applications with embedded AI features, while 90% interact with AI systems that use customer or user data for training. This makes visibility increasingly important, as AI activity can happen within applications and workflows without always being obvious to users or security teams.

Sensitive data is following AI into the enterprise: Regulated data accounts for 56% of AI-related data policy violations in retail, making it the most exposed category, followed by source code at 20% and passwords and API keys at 16%. At the same time, remote MCP activity has surged, with agents interacting with remote MCP servers increasing by around 400% and MCP-related events growing by approximately 300%. As AI agents gain access to more data and external tools, retailers need to understand not just which AI applications employees use, but what information those applications and agents can access.

Attackers are following the AI trend: As retailers embrace AI, attackers are using the same interest in the technology to reach users. AI lure activity fell sharply from around 140 users per 100,000 in May 2025 to roughly 20 around December, before rising again to approximately 100 by March 2026. Attackers are also continuing to abuse trusted cloud platforms, with GitHub and Microsoft OneDrive used to distribute malware across 13% and 12% of retail organizations respectively. The result is a threat landscape where familiar AI and cloud services can increasingly become part of the attack chain.

 

Utilisation de l’IA lien lien

IA : tendances en matière d'adoption et d'utilisation

As organizations become more confident in adopting and using AI, the technology is becoming an increasingly common part of day-to-day business operations. AI use across the retail sector has continued to grow over the past year, with the share of users actively using AI applications increasing from 39% to 65%, aligned with global trends.

chat showing ai users per month median percentage with shaded area showing 1st and 3rd quartiles in the retail sector

 

In parallel, organizations across the retail sector have made steady progress in reducing shadow AI risk by moving users away from personal AI accounts and toward organization-managed tools. Over the past year, the use of personal AI applications declined from 70% to 44%, while adoption of organization-managed AI solutions increased from 40% to 73%. At the same time, the share of users switching between personal and enterprise accounts rose from 11% to 18%, suggesting that some employees continue to move between managed and personal AI accounts as they explore new tools. This highlights the need for organizations to streamline the review and approval of new AI applications while maintaining tighter instance-level controls.

Overall, these changes show that retailers have made meaningful progress in moving toward managed AI deployments, helping improve data protection and compliance without limiting productivity. However, this progress has not continued at the same pace. Since the spring, the shift away from personal AI use has largely stalled, while the overlap between personal and enterprise usage remains. This suggests that shadow AI is proving harder to eliminate once organizations reach a certain level of maturity, making long-term guardrails, clear policies, and simple processes for adopting new AI tools an important part of every retail organization’s AI strategy.

diagram showing ai usage personal vs. organization account breakdown in the retail sector

AI adoption patterns in the retail sector differ noticeably from global trends. Anthropic Claude Platform has overtaken ChatGPT as the most widely adopted AI application, used by 96% of organizations, compared with 84% for ChatGPT. Claude Code, Anthropic’s specialized coding tool, follows closely at 83%, while Anthropic Claude, the conversational assistant used for general tasks and writing, stands at 79%, and Google Gemini at 78%. Anthropic’s broader presence reflects the different roles of its products: Claude serves as a general-purpose assistant, Claude Code supports software development. At the same time, the Claude Platform provides the APIs and tools businesses use to integrate Claude into their own applications. This strong adoption across Anthropic’s products points to growing AI use beyond conversational tools and into enterprise and development workflows.

chart showing most popular ai apps by workforce adoption across organizations in the retail sector

The chart below shows how adoption of the leading AI applications has evolved across the retail sector over the past year, highlighting a clear shift in application preference. ChatGPT has remained relatively stable throughout the period, maintaining consistently high levels of adoption. In contrast, Anthropic Claude Platform saw a sharp increase beginning in December 2025, with adoption accelerating rapidly in the following months and eventually overtaking ChatGPT around February 2026. Google Gemini followed a different trend, with adoption declining from April 2026. Overall, the changes point to a growing preference for Anthropic’s platform, while ChatGPT remains stable and Gemini loses some ground.

chart showing most popular apps by percentage of organizations on the retail sector

 

AI : Utilisation de l'application et violation de la politique en matière de données

As AI adoption continues to increase across the retail sector, concerns around data exposure are becoming more relevant. Retail organizations are using AI tools to summarize documents, generate reports, assist employees, and support everyday business processes. These use cases can involve sensitive customer, business, and operational information, creating additional opportunities for data exposure. As a result, protecting sensitive information remains a key priority, particularly as retailers work to identify and control the risks associated with shadow AI.

Analysis of AI-related data policy violations in the retail sector shows that regulated data represents the largest share of attempts to include sensitive information, accounting for 56% of observed activity. Source code follows at 20%, while passwords and API keys account for 16%. Intellectual property represents the remaining 8%.

chart showing the type of data policy violations in the retail sector

 

Les applications d'IA les plus bloquées

Organizations across the retail sector are taking a measured approach to AI adoption, with many restricting certain applications because of security, privacy, and compliance concerns. While specific policies differ by organization, the most-blocked applications offer a useful indication of where retailers see the greatest risks.

Particular Audience is the most frequently blocked AI application, restricted by 46% of organizations. ZeroGPT follows at 37%, while Landbot and DeepSeek are each restricted by 34%. These applications support a range of AI use cases, from content generation and detection to customer-facing chatbots and general-purpose AI services. Where these tools interact with business information, customer data, or internal systems, they can create additional opportunities for sensitive information to leave the organization.

Overall, the pattern suggests that retailers are taking a more cautious approach to AI governance, particularly around applications that could expose sensitive data or operate outside established security and compliance controls.

chart showing most blocked ai apps by percentage of organizations enacting a blanket ban on the app in the retail sector

 

Adoption de l'IA agentique lien lien

Adoption de l'IA par les utilisateurs

AI adoption is now present across multiple layers of the retail environment. In the sector, 66% of employees use AI applications directly, while 97% use applications that include AI-powered features. In addition, 90% interact with AI systems that use customer or user data to train models.

These figures show how widely AI has become part of everyday work, often through features built into applications employees already use rather than through standalone AI tools. As this adoption continues to grow, retailers face a greater challenge in understanding where sensitive information is being shared and how it may be used, both through direct interactions with AI tools and through AI functionality operating in the background.

chart showing average percentage of users in the retail sector

 

MCP : Interconnexion croissante lien lien

MCP, the open-source standard that allows AI models to connect with external data sources and tools, is seeing a sharp increase in adoption across the retail sector. Over the period, the number of agents interacting with remote MCP servers grew by around 400%, while MCP-related events increased by approximately 300%.

This growth is important because remote MCP connections introduce additional pathways for data to move between AI applications and external systems. For retailers, this makes visibility and control over these interactions increasingly important, particularly where AI agents can access business data or other sensitive resources.

These figures relate specifically to remote MCP usage, where AI agents connect to MCP servers hosted on the internet rather than locally or within an organization’s own network. The rapid increase suggests that agentic AI is moving beyond experimentation and becoming more closely integrated into day-to-day business workflows, making MCP activity an area that organizations will increasingly need to monitor and govern.

increase in MCP adoption over time in the retail sector

 

Menaces proches de l’IA lien lien

Catégorisation des risques liés à l’IA

Effective AI visibility, governance, and protection start with a clear understanding of the risks organizations are facing. Across the retail sector, upstream data policy violations account for 85% of AI-related violations, making them the most prevalent risk category. Downstream data policy violations are also widespread, reflecting the potential for sensitive information to be exposed both when it is entered into AI tools and when AI-generated content is shared or used elsewhere.

Malware-related violations remain less common, but they continue to represent a potentially high-impact risk because of their ability to compromise systems, applications, and sensitive business data.

chart showing the ai violation breakdown per 10k alerts in the retail sector

 

Menaces proches de l’IA lien lien

Leurres d’IA malveillants

A malicious AI lure is designed to trick users into downloading malware or visiting a malicious website by posing as a trusted AI brand or tool. In the retail sector, AI lure activity reached around 140 users per 100,000 in May 2025 before gradually declining to roughly 20 users per 100,000 around December 2025.

Activity then increased again, reaching about 100 users per 100,000 by March 2026. The pattern shows that, while AI lure activity can fluctuate significantly, it remains an ongoing threat as employees continue to use and search for new AI tools.

Recent campaigns have included fake AI application installers, Outils de développement trojanisés, and other AI-themed lures designed to take advantage of the growing interest in AI. As AI adoption continues to expand, attackers are likely to keep adapting these techniques, including targeting software supply chains and distributing malicious packages that take advantage of AI-assisted development.

chart showing users encountering AI lure threats in the retail sector

 

Liens d’IA malveillants

A malicious AI link is a harmful link returned by an AI application that a user clicks or an AI agent follows. They are similar to the malicious links attackers place in search engine results, where users may click them believing they lead to legitimate websites. Attackers can achieve this through SEO techniques, paid advertisements, or by compromising otherwise legitimate infrastructure.

The approach is similar in the AI environment, although the way malicious content reaches users is changing. Techniques such as artificial intelligence engine optimization (AIEO) are emerging as attackers look for ways to influence the content surfaced by AI models, while advertising is also beginning to appear within AI applications.

In the retail sector, the rate at which users encounter malicious AI links fluctuated significantly over the period, ranging from around 40 to more than 160 encounters per week per 100,000 users. The variation highlights the growing need to monitor links returned by AI applications, particularly as employees increasingly rely on AI tools for everyday tasks.

chart showing users encountering malicious ai referrals in the reatil sector

 

Téléchargements de logiciels malveillants lien lien

Distribution de logiciels malveillants via des applications en nuage

Attackers continue to take advantage of legitimate cloud platforms to distribute malware, relying on the trust users place in familiar services. Although cloud providers regularly remove malicious content, even a short window before detection can give attackers enough time to infect devices and potentially move further within an organization.

Across the retail sector, GitHub and Microsoft OneDrive are among the most commonly abused platforms for malware distribution, affecting 13% and 12% of organizations respectively. The use of trusted cloud services makes malicious activity harder to distinguish from normal business traffic and reflects a broader shift away from obviously suspicious domains toward established platforms that users and security teams already expect to see.

chart showing top apps for malware downloads in the reatil sector

 

Recommandations lien lien

Avec l’utilisation croissante des outils d’IA, tant gérés que personnels, et l’abus des applications cloud personnelles, il est essentiel de renforcer la visibilité, d’améliorer les politiques et de prioriser des défenses proactives pour protéger votre organisation dans ce paysage de menaces en rapide évolution.

Based on the trends uncovered in this report, Netskope Threat Labs strongly encourages organizations across Retail sector to take a fresh look at their overall security stance:

  • Inspectez tous les téléchargements HTTP et HTTPS, y compris tout le trafic Web et cloud, pour empêcher les logiciels malveillants de s’infiltrer dans votre réseau. Les clients Netskope peuvent configurer leur Netskope One Next Gen Secure Web Gateway avec une politique de protection contre les menaces qui s’applique aux téléchargements dans toutes les catégories et tous types de fichiers.
  • Bloquez l'accès aux applications qui n'ont pas d'utilité professionnelle légitime ou qui présentent un risque disproportionné pour l'organisation. Un bon point de départ consiste à autoriser les applications réputées actuellement utilisées et à bloquer toutes les autres.
  • Utiliser DLP (Prévention des pertes de données) des politiques visant à détecter les informations potentiellement sensibles, notamment le code source, les données réglementées, les mots de passe et les clés, la propriété intellectuelle et les données chiffrées, envoyées à des instances d'apps personnelles, à des apps d'IA ou à d'autres emplacements non autorisés.
  • Utiliser Remote Browser Isolation (RBI) technologie pour offrir une protection supplémentaire lors de la visite de sites web dans des catégories pouvant présenter un risque plus élevé, comme les domaines nouvellement observés ou nouvellement enregistrés.
  • Utiliser Netskope Skylight AI Gateway pour obtenir visibilité et contrôle sur les applications d’IA et les interactions API, aidant ainsi à sécuriser les flux de données entre utilisateurs, applications et LLM.
  • Deploy Netskope Skylight AI Guardrails to enforce consistent protections against sensitive data exposure, unsafe prompts, and policy violations across managed and unmanaged AI environments.
  • Utiliser Netskope Skylight AI App Security découvrir des applications d’IA autorisées et non autorisées, appliquer des contrôles en temps réel et faire appliquer des politiques de gouvernance à l’égard de l’IA personnelle et professionnelle.
  • L'effet de levier Netskope Skylight AI Analytics surveiller les tendances d’adoption de l’IA, les activités des utilisateurs et les incidents DLP (Prévention des pertes de données), facilitant ainsi aux organisations une meilleure compréhension et une réduction de l’exposition aux risques liés à l’IA.
  • Considérez Netskope Skylight AI Red Teaming identifier activement les vulnérabilités et les mauvaises configurations dans les déploiements privés d’IA avant qu’ils ne soient exploités dans des environnements de production.

 

Netskope Threat Labs lien lien

Le personnel est composé des plus grands chercheurs du secteur en matière de menaces et de logiciels malveillants dans l'informatique en nuage, Netskope Threat Labs découvre, analyse et conçoit des défenses contre les dernières menaces liées à l'informatique en nuage qui affectent les entreprises. Nos chercheurs présentent régulièrement des exposés et participent bénévolement aux principales conférences sur la sécurité, notamment DEF CON, Black Hat et RSA.

 

A propos de ce rapport lien lien

Netskope offre une protection contre les menaces à des millions d’utilisateurs dans le monde. Les informations présentées dans ce rapport sont basées sur des données d’utilisation agrégées collectées par le Plate-forme Netskope One for a subset of Netskope customers in the retail industry.

The statistics in this report are based on the period from July 1, 2025, through July 30, 2026. Stats reflect attacker tactics, user behavior, and organization policy.