A Netskope é novamente reconhecida como Líder no Quadrante Mágico do Gartner® para Plataformas SASE e Security Service Edge.

Baixe o relatório

fechar
fechar
""
O AI Security Playbook
Este manual explora os seis principais desafios de segurança que as organizações enfrentam ao adotar a IA, juntamente com estratégias comprovadas e reais para enfrentá-los.
Experimente a Netskope
Coloque a mão na massa com a plataforma Netskope
Esta é a sua chance de experimentar a plataforma de nuvem única do Netskope One em primeira mão. Inscreva-se em laboratórios práticos e individualizados, junte-se a nós para demonstrações mensais de produtos ao vivo, faça um test drive gratuito do Netskope Private Access ou participe de workshops ao vivo conduzidos por instrutores.
MQ para SASE e SSE 2026
A Netskope é novamente reconhecida como Líder no Quadrante Mágico do Gartner® para Plataformas SASE e Security Service Edge.
Veja por que o Gartner® nomeou a Netskope Líder no Magic Quadrant™ 2026 para Secure Access Service Edge Platforms e para Security Service Edge
Relatório de Riscos e Prontidão para a IA
Relatório de Riscos e Prontidão para a IA
Compare o desempenho da sua organização com base em pesquisas sobre desafios e estratégias de segurança em IA, conduzidas pela Cybersecurity Insiders.
Relatório de Riscos e Prontidão para a IA
Relatório de Riscos e Prontidão para a IA
Compare o desempenho da sua organização com base em pesquisas sobre desafios e estratégias de segurança em IA, conduzidas pela Cybersecurity Insiders.
E-book moderno sobre prevenção de perda de dados (DLP) para leigos
Prevenção Contra Perda de Dados (DLP) Moderna para Leigos
Obtenha dicas e truques para fazer a transição para um DLP fornecido na nuvem.
Livro SD-WAN moderno para SASE Dummies
SD-WAN moderno para leigos em SASE
Pare de brincar com sua arquitetura de rede
Compreendendo onde estão os riscos
O Advanced Analytics transforma a maneira como as equipes de operações de segurança aplicam insights orientados por dados para implementar políticas melhores. Com o Advanced Analytics, o senhor pode identificar tendências, concentrar-se em áreas de preocupação e usar os dados para tomar medidas.
The Lens
""
Leia as últimas notícias e opiniões da equipe da Netskope. O Lens combina nossos blogs, podcasts e estudos de caso, com conteúdo New adicionado toda semana.
Suporte Técnico Netskope
Suporte Técnico Netskope
Nossos engenheiros de suporte qualificados estão localizados em todo o mundo e têm diversas experiências em segurança de nuvem, rede, virtualização, fornecimento de conteúdo e desenvolvimento de software, garantindo assistência técnica de qualidade e em tempo hábil.
""
Inteligência Artificial na Pista Rápida
O roadshow AI in the Fast Lane da Netskope reúne profissionais de segurança para discutir como as organizações estão usando IA atualmente e como uma estratégia de segurança abrangente pode criar um modelo mais inteligente, seguro e preparado para o futuro.
Vídeo da Netskope
Treinamento Netskope
Os treinamentos da Netskope vão ajudar você a ser um especialista em segurança na nuvem. Conte conosco para ajudá-lo a proteger a sua jornada de transformação digital e aproveitar ao máximo as suas aplicações na nuvem, na web e privadas.

This report analyzes the primary cybersecurity risk trends impacting Retail organizations. It addresses the growing adoption of generative AI (AI) tools and their associated data security challenges. Furthermore, it illustrates the growing number of data policy violations, where sensitive information is increasingly being leaked through unauthorized cloud services, personal applications, and AI platforms.

12 min read

Principais conclusões link link

This report examines how AI is becoming embedded across the retail sector and the security challenges that come with that shift. The report looks at the move toward managed AI, the growing role of AI in everyday applications and agentic workflows, and the data and malware risks emerging alongside this adoption.

AI is becoming deeply embedded in retail: Retailers are moving quickly from experimentation to widespread AI adoption. While personal AI usage has fallen from 70% to 44% and organization-managed AI adoption has risen from 40% to 73%, AI is now present far beyond standalone tools. 97% of employees use applications with embedded AI features, while 90% interact with AI systems that use customer or user data for training. This makes visibility increasingly important, as AI activity can happen within applications and workflows without always being obvious to users or security teams.

Sensitive data is following AI into the enterprise: Regulated data accounts for 56% of AI-related data policy violations in retail, making it the most exposed category, followed by source code at 20% and passwords and API keys at 16%. At the same time, remote MCP activity has surged, with agents interacting with remote MCP servers increasing by around 400% and MCP-related events growing by approximately 300%. As AI agents gain access to more data and external tools, retailers need to understand not just which AI applications employees use, but what information those applications and agents can access.

Attackers are following the AI trend: As retailers embrace AI, attackers are using the same interest in the technology to reach users. AI lure activity fell sharply from around 140 users per 100,000 in May 2025 to roughly 20 around December, before rising again to approximately 100 by March 2026. Attackers are also continuing to abuse trusted cloud platforms, with GitHub and Microsoft OneDrive used to distribute malware across 13% and 12% of retail organizations respectively. The result is a threat landscape where familiar AI and cloud services can increasingly become part of the attack chain.

 

uso de IA link link

IA: Tendências de adoção e utilização

As organizations become more confident in adopting and using AI, the technology is becoming an increasingly common part of day-to-day business operations. AI use across the retail sector has continued to grow over the past year, with the share of users actively using AI applications increasing from 39% to 65%, aligned with global trends.

chat showing ai users per month median percentage with shaded area showing 1st and 3rd quartiles in the retail sector

 

In parallel, organizations across the retail sector have made steady progress in reducing shadow AI risk by moving users away from personal AI accounts and toward organization-managed tools. Over the past year, the use of personal AI applications declined from 70% to 44%, while adoption of organization-managed AI solutions increased from 40% to 73%. At the same time, the share of users switching between personal and enterprise accounts rose from 11% to 18%, suggesting that some employees continue to move between managed and personal AI accounts as they explore new tools. This highlights the need for organizations to streamline the review and approval of new AI applications while maintaining tighter instance-level controls.

Overall, these changes show that retailers have made meaningful progress in moving toward managed AI deployments, helping improve data protection and compliance without limiting productivity. However, this progress has not continued at the same pace. Since the spring, the shift away from personal AI use has largely stalled, while the overlap between personal and enterprise usage remains. This suggests that shadow AI is proving harder to eliminate once organizations reach a certain level of maturity, making long-term guardrails, clear policies, and simple processes for adopting new AI tools an important part of every retail organization’s AI strategy.

diagram showing ai usage personal vs. organization account breakdown in the retail sector

AI adoption patterns in the retail sector differ noticeably from global trends. Anthropic Claude Platform has overtaken ChatGPT as the most widely adopted AI application, used by 96% of organizations, compared with 84% for ChatGPT. Claude Code, Anthropic’s specialized coding tool, follows closely at 83%, while Anthropic Claude, the conversational assistant used for general tasks and writing, stands at 79%, and Google Gemini at 78%. Anthropic’s broader presence reflects the different roles of its products: Claude serves as a general-purpose assistant, Claude Code supports software development. At the same time, the Claude Platform provides the APIs and tools businesses use to integrate Claude into their own applications. This strong adoption across Anthropic’s products points to growing AI use beyond conversational tools and into enterprise and development workflows.

chart showing most popular ai apps by workforce adoption across organizations in the retail sector

The chart below shows how adoption of the leading AI applications has evolved across the retail sector over the past year, highlighting a clear shift in application preference. ChatGPT has remained relatively stable throughout the period, maintaining consistently high levels of adoption. In contrast, Anthropic Claude Platform saw a sharp increase beginning in December 2025, with adoption accelerating rapidly in the following months and eventually overtaking ChatGPT around February 2026. Google Gemini followed a different trend, with adoption declining from April 2026. Overall, the changes point to a growing preference for Anthropic’s platform, while ChatGPT remains stable and Gemini loses some ground.

chart showing most popular apps by percentage of organizations on the retail sector

 

IA: Violação da política de uso e dados do aplicativo

As AI adoption continues to increase across the retail sector, concerns around data exposure are becoming more relevant. Retail organizations are using AI tools to summarize documents, generate reports, assist employees, and support everyday business processes. These use cases can involve sensitive customer, business, and operational information, creating additional opportunities for data exposure. As a result, protecting sensitive information remains a key priority, particularly as retailers work to identify and control the risks associated with shadow AI.

Analysis of AI-related data policy violations in the retail sector shows that regulated data represents the largest share of attempts to include sensitive information, accounting for 56% of observed activity. Source code follows at 20%, while passwords and API keys account for 16%. Intellectual property represents the remaining 8%.

chart showing the type of data policy violations in the retail sector

 

Aplicativos de IA mais bloqueados

Organizations across the retail sector are taking a measured approach to AI adoption, with many restricting certain applications because of security, privacy, and compliance concerns. While specific policies differ by organization, the most-blocked applications offer a useful indication of where retailers see the greatest risks.

Particular Audience is the most frequently blocked AI application, restricted by 46% of organizations. ZeroGPT follows at 37%, while Landbot and DeepSeek are each restricted by 34%. These applications support a range of AI use cases, from content generation and detection to customer-facing chatbots and general-purpose AI services. Where these tools interact with business information, customer data, or internal systems, they can create additional opportunities for sensitive information to leave the organization.

Overall, the pattern suggests that retailers are taking a more cautious approach to AI governance, particularly around applications that could expose sensitive data or operate outside established security and compliance controls.

chart showing most blocked ai apps by percentage of organizations enacting a blanket ban on the app in the retail sector

 

Adoção de IA Agentic link link

Adoção de IA pelos usuários

AI adoption is now present across multiple layers of the retail environment. In the sector, 66% of employees use AI applications directly, while 97% use applications that include AI-powered features. In addition, 90% interact with AI systems that use customer or user data to train models.

These figures show how widely AI has become part of everyday work, often through features built into applications employees already use rather than through standalone AI tools. As this adoption continues to grow, retailers face a greater challenge in understanding where sensitive information is being shared and how it may be used, both through direct interactions with AI tools and through AI functionality operating in the background.

chart showing average percentage of users in the retail sector

 

MCP: Interconexão em rápido crescimento link link

MCP, the open-source standard that allows AI models to connect with external data sources and tools, is seeing a sharp increase in adoption across the retail sector. Over the period, the number of agents interacting with remote MCP servers grew by around 400%, while MCP-related events increased by approximately 300%.

This growth is important because remote MCP connections introduce additional pathways for data to move between AI applications and external systems. For retailers, this makes visibility and control over these interactions increasingly important, particularly where AI agents can access business data or other sensitive resources.

These figures relate specifically to remote MCP usage, where AI agents connect to MCP servers hosted on the internet rather than locally or within an organization’s own network. The rapid increase suggests that agentic AI is moving beyond experimentation and becoming more closely integrated into day-to-day business workflows, making MCP activity an area that organizations will increasingly need to monitor and govern.

increase in MCP adoption over time in the retail sector

 

ameaças adjacentes à IA link link

Categorizando os riscos da IA

Effective AI visibility, governance, and protection start with a clear understanding of the risks organizations are facing. Across the retail sector, upstream data policy violations account for 85% of AI-related violations, making them the most prevalent risk category. Downstream data policy violations are also widespread, reflecting the potential for sensitive information to be exposed both when it is entered into AI tools and when AI-generated content is shared or used elsewhere.

Malware-related violations remain less common, but they continue to represent a potentially high-impact risk because of their ability to compromise systems, applications, and sensitive business data.

chart showing the ai violation breakdown per 10k alerts in the retail sector

 

ameaças adjacentes à IA link link

Iscas de IA maliciosas

A malicious AI lure is designed to trick users into downloading malware or visiting a malicious website by posing as a trusted AI brand or tool. In the retail sector, AI lure activity reached around 140 users per 100,000 in May 2025 before gradually declining to roughly 20 users per 100,000 around December 2025.

Activity then increased again, reaching about 100 users per 100,000 by March 2026. The pattern shows that, while AI lure activity can fluctuate significantly, it remains an ongoing threat as employees continue to use and search for new AI tools.

Recent campaigns have included fake AI application installers, ferramentas de desenvolvedor trojanizadas, and other AI-themed lures designed to take advantage of the growing interest in AI. As AI adoption continues to expand, attackers are likely to keep adapting these techniques, including targeting software supply chains and distributing malicious packages that take advantage of AI-assisted development.

chart showing users encountering AI lure threats in the retail sector

 

Links maliciosos de IA

A malicious AI link is a harmful link returned by an AI application that a user clicks or an AI agent follows. They are similar to the malicious links attackers place in search engine results, where users may click them believing they lead to legitimate websites. Attackers can achieve this through SEO techniques, paid advertisements, or by compromising otherwise legitimate infrastructure.

The approach is similar in the AI environment, although the way malicious content reaches users is changing. Techniques such as artificial intelligence engine optimization (AIEO) are emerging as attackers look for ways to influence the content surfaced by AI models, while advertising is also beginning to appear within AI applications.

In the retail sector, the rate at which users encounter malicious AI links fluctuated significantly over the period, ranging from around 40 to more than 160 encounters per week per 100,000 users. The variation highlights the growing need to monitor links returned by AI applications, particularly as employees increasingly rely on AI tools for everyday tasks.

chart showing users encountering malicious ai referrals in the reatil sector

 

Downloads de malware link link

Distribuição de malware por meio de aplicativos em nuvem

Attackers continue to take advantage of legitimate cloud platforms to distribute malware, relying on the trust users place in familiar services. Although cloud providers regularly remove malicious content, even a short window before detection can give attackers enough time to infect devices and potentially move further within an organization.

Across the retail sector, GitHub and Microsoft OneDrive are among the most commonly abused platforms for malware distribution, affecting 13% and 12% of organizations respectively. The use of trusted cloud services makes malicious activity harder to distinguish from normal business traffic and reflects a broader shift away from obviously suspicious domains toward established platforms that users and security teams already expect to see.

chart showing top apps for malware downloads in the reatil sector

 

Recomendações link link

Com o uso crescente de ferramentas de IA, tanto gerenciadas quanto pessoais, e o uso indevido de aplicativos de nuvem pessoais, é essencial fortalecer a visibilidade, aprimorar as políticas e priorizar defesas proativas para proteger sua organização neste cenário de ameaças em rápida evolução.

Based on the trends uncovered in this report, Netskope Threat Labs strongly encourages organizations across Retail sector to take a fresh look at their overall security stance:

  • Inspecione todos os downloads HTTP e HTTPS, incluindo todo o tráfego da Web e da nuvem, para evitar que o malware se infiltre em sua rede. Os clientes da Netskope podem configurar seus Netskope One Next Gen Secure Web Gateway Com uma política de proteção contra ameaças que se aplica a downloads em todas as categorias e tipos de arquivo.
  • Bloqueie o acesso a aplicativos que não servem a nenhum propósito comercial legítimo ou representam um risco desproporcional para a organização. Um bom ponto de partida é uma política que permita aplicativos confiáveis atualmente em uso e, ao mesmo tempo, bloqueie todos os outros.
  • Uso DLP Políticas para detectar o envio de informações potencialmente sensíveis, incluindo código-fonte, dados regulamentados, senhas e chaves, propriedade intelectual e dados criptografados para instâncias de aplicativos pessoais, aplicativos de IA ou outros locais não autorizados.
  • Uso Remote Browser Isolation (RBI) Tecnologia para fornecer proteção adicional ao visitar sites em categorias que podem representar um risco maior, como domínios recém-observados ou recém-registrados.
  • Uso Netskope Skylight AI Gateway Para obter visibilidade e controle sobre aplicações de IA e interações com APIs, ajudando a proteger o fluxo de dados entre usuários, aplicações e LLMs.
  • Deploy Netskope Skylight AI Guardrails to enforce consistent protections against sensitive data exposure, unsafe prompts, and policy violations across managed and unmanaged AI environments.
  • Uso Netskope Skylight AI App Security Descobrir aplicações de IA autorizadas e não autorizadas, aplicar controles em tempo real e fazer cumprir as políticas de governança em todo o uso de IA pessoal e empresarial.
  • Aproveitar Netskope Skylight AI Analytics Monitorar as tendências de adoção de IA, as atividades dos usuários e os incidentes de DLP, permitindo que as organizações compreendam melhor e reduzam a exposição a riscos relacionados à IA.
  • Considerar Netskope Skylight AI Red Teaming Identificar proativamente vulnerabilidades e configurações incorretas em implantações de IA privadas antes que possam ser exploradas em ambientes de produção.

 

Netskope Threat Labs link link

Com a equipe dos principais pesquisadores de ameaças e malware na nuvem do setor, Netskope Threat Labs Descobre, analisa e desenvolve defesas contra as ameaças mais recentes na nuvem que afetam as empresas. Nossos pesquisadores são palestrantes e voluntários frequentes em importantes conferências de segurança, incluindo DEF CON, Black Hat e RSA.

 

Sobre este relatório link link

A Netskope oferece proteção contra ameaças a milhões de usuários em todo o mundo. As informações apresentadas neste relatório são baseadas em dados agregados de uso coletados pela [nome da empresa/organização]. Plataforma Netskope One for a subset of Netskope customers in the retail industry.

The statistics in this report are based on the period from July 1, 2025, through July 30, 2026. Stats reflect attacker tactics, user behavior, and organization policy.