AI data exposure ranks second among AI security incidents in Australia and New Zealand

0

AI systems revealing sensitive information to unauthorised users has become the second most common type of AI-related security incident inside organisations in Australia and New Zealand, according to a new regional cyber threat report from Netskope Threat Labs.

The Netskope Threat Labs Australia & New Zealand 2026 report says so-called “downstream” data policy violations—where AI systems surface information to users who should not have access—accounted for 666 out of every 10,000 AI security alerts among organisations with governance controls capable of detecting such activity.

The report argues the shift reflects a broader change in enterprise AI risk, from early deployment concerns focused on employees sending sensitive data into AI tools (upstream activity) to risks emerging from AI outputs and automated actions. Upstream data policy violations remain the most common AI risk, accounting for 8,300 of every 10,000 AI security alerts, according to the report.

Netskope links the rise in downstream incidents to growth in AI agents and new machine-to-machine connections, pointing to increasing use of the Model Context Protocol (MCP), an open standard that allows AI models and agents to connect to data sources and tools. The company said that over a two-month period the number of agents in ANZ organisations interacting with remote MCP servers increased by 89%, while MCP-related events rose by 69%.

The report also highlights an elevated regional rate of prompt injection and jailbreaking activity, stating AI systems within ANZ organisations experienced these attacks at “twice the global rate” (254 of every 10,000 alerts versus 129 globally). These techniques attempt to manipulate AI behaviour to produce harmful or sensitive outputs.

Another emerging threat described in the report is the use of “AI Engine Optimisation” techniques to influence public AI tools into citing malicious links as legitimate sources. Netskope said that over the past 12 months, for every 100,000 workers in ANZ, an average of 67 per week clicked on malicious links contained within AI responses, peaking at 175 at the end of 2025.

The report also points to “AI lures” and brand impersonation campaigns designed to trick users into installing fake applications, using trojanised developer tools, or surrendering credentials. It said that in May, 140 of every 100,000 workers in ANZ fell for AI lures.

“Our research outlines the increasing complexity of AI risks ANZ organisations are facing, and new threats are going to keep emerging as enterprise AI use increases and evolves,” said Ray Canzanese, Director of Netskope Threat Labs. “This is a whole new landscape that requires a new response; redesigning security architectures for the AI era, re-scoping the baseline for data security practices to include monitoring and securing bi-directional AI traffic, AI agents, model behaviours, and new machine-to-machine communications protocols such as the MCP, as well as more broadly preserving the integrity of the AI supply chain.”

On AI adoption, the report said Anthropic Claude Platform was the most popular AI application in ANZ, used in 81% of organisations, followed by ChatGPT (68%) and Microsoft 365 Copilot (66%). It also found “shadow AI” remained common, with 55% of employees in ANZ still using personal AI accounts at work, despite growth in organisation-managed AI tools from 34% to 75% over the period measured.

The Netskope report is based on aggregated usage data collected through the Netskope One platform from a subset of Netskope customers in Australia and New Zealand between 1 July 2025 and 15 July 2026.

You can read the full report here.

Share.