This report examines how AI is becoming embedded across the retail sector and the security challenges that come with that shift. The report looks at the move toward managed AI, the growing role of AI in everyday applications and agentic workflows, and the data and malware risks emerging alongside this adoption.
AI is becoming deeply embedded in retail: Retailers are moving quickly from experimentation to widespread AI adoption. While personal AI usage has fallen from 70% to 44% and organization-managed AI adoption has risen from 40% to 73%, AI is now present far beyond standalone tools. 97% of employees use applications with embedded AI features, while 90% interact with AI systems that use customer or user data for training. This makes visibility increasingly important, as AI activity can happen within applications and workflows without always being obvious to users or security teams.
Sensitive data is following AI into the enterprise: Regulated data accounts for 56% of AI-related data policy violations in retail, making it the most exposed category, followed by source code at 20% and passwords and API keys at 16%. At the same time, remote MCP activity has surged, with agents interacting with remote MCP servers increasing by around 400% and MCP-related events growing by approximately 300%. As AI agents gain access to more data and external tools, retailers need to understand not just which AI applications employees use, but what information those applications and agents can access.
Attackers are following the AI trend: As retailers embrace AI, attackers are using the same interest in the technology to reach users. AI lure activity fell sharply from around 140 users per 100,000 in May 2025 to roughly 20 around December, before rising again to approximately 100 by March 2026. Attackers are also continuing to abuse trusted cloud platforms, with GitHub and Microsoft OneDrive used to distribute malware across 13% and 12% of retail organizations respectively. The result is a threat landscape where familiar AI and cloud services can increasingly become part of the attack chain.
