Netskope Presents: Secure AI Everywhere

Reserve your seat

close
close
""
The AI Security Playbook
This playbook explores six core security challenges organizations face when adopting AI, along with proven, real-world strategies to address them.
Experience Netskope
Get Hands-on With the Netskope Platform
Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
MQ for SASE and SSE 2026
Netskope is recognized as a Leader again in the Gartner® Magic Quadrant™ for SASE Platforms and Security Service Edge
See Why Gartner® Named Netskope a 2026 Magic Quadrant™ Leader for Secure Access Service Edge Platforms and Security Service Edge
AI Risk and Readiness Report
AI Risk and Readiness Report
Benchmark your organization using research into AI security challenges and strategies, conducted by Cybersecurity Insiders.
AI Risk and Readiness Report
AI Risk and Readiness Report
Benchmark your organization using research into AI security challenges and strategies, conducted by Cybersecurity Insiders.
Modern data loss prevention (DLP) for Dummies eBook
Modern Data Loss Prevention (DLP) for Dummies
Get tips and tricks for transitioning to a cloud-delivered DLP.
Modern SD-WAN for SASE Dummies Book
Modern SD-WAN for SASE Dummies
Stop playing catch up with your networking architecture
Understanding where the risk lies
Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
The Lens
""
Read about the latest news and opinions from the team at Netskope. The Lens combines our blogs, our podcasts and case studies, with new content added every week.
Netskope Technical Support
Netskope Technical Support
Our qualified support engineers are located worldwide and have diverse backgrounds in cloud security, networking, virtualization, content delivery, and software development, ensuring timely and quality technical assistance
""
AI in the Fast Lane
Netskope’s AI in the Fast Lane roadshow brings together security professionals to discuss how organizations are using AI today, and how a comprehensive security strategy can create a smarter, safer, and future-proof model.
Netskope video
Netskope Training
Netskope training will help you become a cloud security expert. We are here to help you secure your digital transformation journey and make the most of your cloud, web, and private applications.

This report examines four key trends in cybersecurity risks facing France organizations, including AI data risks, data policy violations, and malware distribution via popular cloud applications.

11 min read

Key findings link link

This report examines how AI is becoming embedded across French organizations and the security challenges that come with that shift. It looks at the move toward managed AI, the growing role of AI in everyday applications and agentic workflows, and the data and malware risks emerging alongside this adoption.

AI is becoming deeply embedded in French organizations: Active AI users rose from 43% to 69% over the past year, and organization-managed adoption climbed from 28% to 66% as personal AI use fell from 80% to 51%. But AI now reaches far beyond standalone tools: 96% of employees use applications with embedded AI features, and 89% interact with systems that use customer or user data for training.

Sensitive data is following AI into the enterprise: Regulated data accounts for 58% of AI-related data policy violations in France, followed by source code at 26%, intellectual property at 9%, and passwords and API keys at 6%. Remote MCP activity has surged since May, with users up roughly 5000% and events up around 2800%. Organizations need to understand not just which AI applications employees use, but what those applications and agents can access.

Attackers are following the AI trend: AI lure activity has held steady at around 80 users per 100,000 since August 2025, making impersonation of trusted AI brands a persistent tactic rather than an occasional campaign. Encounters with malicious AI links have fallen from more than 100 per week per 100,000 users to around 35, though the residual volume still warrants attention. Familiar AI services are increasingly part of the attack chain.

 

AI use link link

AI: Adoption and usage trends

As organizations grow more confident in adopting AI, the technology is becoming a routine part of everyday business operations. AI use in France has continued to climb over the past year, with the share of users actively working with AI applications rising from 43% to 69%, in line with global trends.

diagram showing ai users per month median percentage with shaded area showing 1st and 3rd quartiles in France

In parallel, organizations in France have made steady progress in reducing shadow AI risk by moving users away from personal AI accounts and toward organization-managed tools. Over the past year, the use of personal AI applications fell from 80% to 51%, while adoption of organization-managed AI solutions rose from 28% to 66%. At the same time, the share of users switching between personal and enterprise accounts grew from 8% to 18%, suggesting that some employees still move between managed and personal accounts as they explore new tools. This points to the need for organizations to streamline the review and approval of new AI applications while maintaining tighter instance-level controls.

Overall, these changes show that French organizations have made meaningful progress toward managed AI deployments, improving data protection and compliance without holding back productivity. That progress has not continued at the same pace, however. Since the spring, the shift away from personal AI use has largely stalled, and the overlap between personal and enterprise usage remains. Shadow AI appears harder to eliminate once organizations reach a certain level of maturity, making long-term guardrails, clear policies, and simple processes for adopting new AI tools an important part of every French organization’s AI strategy.

chart showing ai usage personal vs. organization account breakdown in France

AI adoption patterns in France differ noticeably from global trends. Anthropic Claude Platform has overtaken ChatGPT as the most widely adopted AI application, used by 86% of organizations. Claude Code, Anthropic’s specialized coding tool, follows at 74%, with ChatGPT close behind at 73%. Anthropic’s broader presence reflects the different roles of its products: Claude Code supports software development, while the Claude Platform provides the APIs and tools businesses use to integrate Claude into their own applications. This strong adoption across Anthropic’s products points to growing AI use beyond conversational tools and into enterprise and development workflows.

chart showing most popular ai apps by workforce adoption across organizations in France

The chart below shows how adoption of the leading AI applications has evolved in France over the past year, highlighting a clear shift in application preference. ChatGPT has remained relatively stable throughout the period, maintaining consistently high adoption. Anthropic Claude Platform, by contrast, began climbing in September 2025 and continued to gain ground over the following months before overtaking ChatGPT and settling into first position from May 2026 onward. Google Gemini followed a different trend, slipping gradually from March 2026. Overall, the changes point to a growing preference for Anthropic’s platform, while ChatGPT remains stable and Gemini loses ground.

chart showing most popular apps by percentage of organizations in France

AI: App usage and data policy violation

As AI adoption continues to increase in France, concerns around data exposure are becoming more relevant. French organizations are using AI tools to summarize documents, generate reports, assist employees, and support everyday business processes. These use cases can involve sensitive customer, business, and operational information, creating additional opportunities for data exposure. Protecting sensitive information therefore remains a key priority, particularly as organizations work to identify and control the risks associated with shadow AI.

Analysis of AI-related data policy violations in France shows that regulated data represents the largest share of attempts to include sensitive information, accounting for 58% of observed activity. Source code follows at 26%, while intellectual property accounts for 9% and passwords and API keys make up the remaining 6%.

diagram showing type of data policy violations in france

Most blocked AI apps

Organizations in France are taking a measured approach to AI adoption, with many restricting certain applications because of security, privacy, and compliance concerns. While specific policies differ by organization, the most-blocked applications indicate where French organizations see the greatest risks.

Tolk.ai is the most frequently blocked AI application, restricted by 34% of organizations. A French no-code platform for building generative AI chatbots and live chat agents for customer service, it typically connects to internal knowledge bases and CRM or ticketing systems. Particular Audience follows at 33%, and DeepSeek at 30%. Together, these applications cover a range of AI use cases, from customer-facing chatbots and personalization to general-purpose AI services. Where these tools interact with business information, customer data, or internal systems, they can create additional opportunities for sensitive information to leave the organization.

Overall, the pattern suggests that French organizations are taking a more cautious approach to AI governance, particularly around applications that could expose sensitive data or operate outside established security and compliance controls.

chart showing most blocked ai apps by percentage of organizations enacting a blanket ban on the app in france

 

Agentic AI adoption link link

User adoption of AI

AI adoption is now present across multiple layers of the French business environment. In France, 66% of employees use AI applications directly, while 96% use applications that include AI-powered features. In addition, 89% interact with AI systems that use customer or user data to train models.

These figures show how widely AI has become part of everyday work, often through features built into applications employees already use rather than through standalone AI tools. As adoption continues to grow, French organizations face a greater challenge in understanding where sensitive information is being shared and how it may be used, both through direct interactions with AI tools and through AI functionality operating in the background.

chart showing average percentage of users in france

 

MCP: Rapidly increasing interconnectedness link link

MCP, the open-source standard that allows AI models to connect with external data sources and tools, is seeing a sharp increase in adoption in France. Growth began in May and accelerated from there, with the number of users interacting with remote MCP servers rising by roughly 5000% and MCP-related events by around 2800%.

This growth matters because remote MCP connections introduce additional pathways for data to move between AI applications and external systems. For French organizations, that makes visibility and control over these interactions increasingly important, particularly where AI agents can access business data or other sensitive resources.

These figures relate specifically to remote MCP usage, where AI agents connect to MCP servers hosted on the internet rather than locally or within an organization’s own network. The scale of the increase suggests that agentic AI is moving beyond experimentation and becoming more closely integrated into day-to-day business workflows, making MCP activity an area that organizations will increasingly need to monitor and govern.

chart showing the increase in MCP adoption over time in france

 

AI-adjacent threats link link

Categorizing AI risks

Effective AI visibility, governance, and protection start with a clear understanding of the risks organizations are facing. In France, upstream data policy violations account for 86% of AI-related violations, making them the most prevalent risk category. Downstream data policy violations are also widespread, reflecting the risk of exposing sensitive information both when it is entered into AI tools and when AI-generated content is shared or used elsewhere.

Malware-related violations remain less common, but they still pose a potentially high-impact risk because they can compromise systems, applications, and sensitive business data.

chart showing ai violation breakdown per 10k alerts in france

 

AI-adjacent threats link link

Malicious AI lures

A malicious AI lure is designed to trick users into downloading malware or visiting a malicious website by posing as a trusted AI brand or tool. In France, this activity spiked sharply in June 2025, reaching more than 1,000 users per 100,000, before falling back and settling at around 80 users per 100,000 from August 2025 onward.

Both parts of that pattern matter. The June spike shows how quickly a single effective campaign can reach a large share of the workforce, while the level that followed has proven persistent rather than transient, remaining an ongoing threat as employees continue to use and search for new AI tools.

Recent campaigns have included fake AI application installers, trojanized developer tools, and other AI-themed lures designed to take advantage of the growing interest in AI. As AI adoption continues to expand, attackers are likely to keep adapting these techniques, including targeting software supply chains and distributing malicious packages that take advantage of AI-assisted development.

chart showing users encountering AI lure threats in france

 

Malicious AI links

A malicious AI link is a harmful link returned by an AI application that a user clicks or an AI agent follows. They are similar to the malicious links attackers place in search engine results, where users may click them believing they lead to legitimate websites. Attackers can achieve this through SEO techniques, paid advertisements, or by compromising otherwise legitimate infrastructure.

The approach is similar in the AI environment, although malicious content reaches users differently. Techniques such as artificial intelligence engine optimization (AIEO) are emerging as attackers look for ways to influence the content AI models surface, while advertising is also beginning to appear within AI applications.

In France, the rate at which users encounter malicious AI links has fallen over the period, from more than 100 encounters per week per 100,000 users from August 2025 to January 2026, stabilizing to around 35. The decline is encouraging, but the volume still points to the need to monitor links returned by AI applications, particularly as employees increasingly rely on AI tools for everyday tasks.

chart showing users encountering malicious ai referrals in france

 

Recommendations link link

With the growing use of AI tools, both managed and personal, and the misuse of personal cloud apps, it is essential to strengthen visibility, improve policies, and prioritize proactive defenses to protect your organization in this fast-changing threat landscape.

Based on the trends uncovered in this report, Netskope Threat Labs strongly encourages organizations across France to take a fresh look at their overall security stance:

  • Inspect all HTTP and HTTPS downloads, including all web and cloud traffic, to prevent malware from infiltrating your network. Netskope customers can configure their Netskope One NG-SWG with a threat protection policy that applies to downloads across all categories and all file types.
  • Block access to apps that do not serve any legitimate business purpose or pose a disproportionate risk to the organization. A good starting point is a policy to allow reputable apps currently in use while blocking all others.
  • Use DLP policies to detect potentially sensitive information, including source code, regulated data, passwords and keys, intellectual property, and encrypted data, being sent to personal app instances, AI apps, or other unauthorized locations.
  • Use Remote Browser Isolation (RBI) technology to provide additional protection when visiting websites in categories that may pose a higher risk, such as newly observed or newly registered domains.
  • Use Netskope Skylight AI Gateway to gain visibility and control over AI applications and API interactions, helping secure data flows between users, applications, and LLMs.
  • Deploy Netskope Skylight AI Guardrails to enforce consistent protections against sensitive data exposure, unsafe prompts, and policy violations across managed and unmanaged AI environments.
  • Use Netskope Skylight AI App Security to discover sanctioned and unsanctioned AI applications, apply real-time controls, and enforce governance policies across personal and enterprise AI use.
  • Leverage Netskope Skylight AI Analytics to monitor AI adoption trends, user activities, and DLP incidents, facilitating organizations to better understand and reduce AI-related risk exposure.
  • Consider Netskope Skylight AI Red Teaming to actively identify vulnerabilities and misconfigurations in private AI deployments before they may be exploited in production environments.

 

Netskope Threat Labs link link

Staffed by the industry’s foremost cloud threat and malware researchers, Netskope Threat Labs discovers, analyzes, and designs defenses against the latest cloud threats affecting enterprises. Our researchers are regular presenters and volunteers at top security conferences, including DEF CON, Black Hat, and RSA.

 

About this report link link

Netskope provides threat protection to millions of users globally. The information presented in this report is based on aggregate use data collected by the Netskope One platform for a subset of Netskope customers in France.

The statistics in this report are based on the period from July 1, 2025, through July 30, 2026. Stats reflect attacker tactics, user behavior, and organization policy.