Skip to content

Retailers limit shadow AI but face challenges with agentic sprawl

Significant progress has been made by retailers in governing employee AI usage, yet the swift emergence of agent-based AI and gaps in oversight are fueling fresh security risks, according to a new report.

Retail Sector Expands AI Use as Oversight Strengthens

Over the last year, AI adoption in the retail industry has accelerated, moving beyond pilot projects to encompass entire organizations. Insights from a Netskope report released Tuesday highlight substantial advancements in how retailers coordinate and monitor internal AI activity. One important trend is a notable reduction in “shadow AI,” which refers to AI platforms and tools utilized without the company’s authorization.

Netskope reported that the percentage of retail staff engaging with unauthorized AI solutions dropped from 70% down to 44% over the past year. At the same time, official adoption of approved AI tools among employees rose sharply, increasing from 40% to 73%. Overall, about two-thirds of the retail workforce now incorporate standalone AI applications into their daily activities.

Security Threats Shift as Embedded AI and Agentic Tools Multiply

While use of unapproved AI by retail employees has declined, Netskope cautioned about new risks stemming from less visible sources: “As adoption expands, retailers struggle more to pinpoint where sensitive data is transferred and how it is utilized, whether through overt engagement with AI or covert, automated processes.”

A majority of employees said they work with software featuring embedded AI, and 90% indicated their AI tools are trained using customer information. Limited insight into these embedded AI activities can have serious implications, particularly regarding protected data. In its analysis, Netskope identified that 56% of all AI-related data policy breaches involved customer records protected by law, while 20% comprised incidents threatening source code, and 16% exposed passwords or API credentials.

The rise of agentic AI—tools that can independently make decisions and initiate actions—adds to security complexities. During the review window, Netskope tracked a 400% rise in the number of retail AI agents interacting with remote Model Context Protocol (MCP) servers. Such connections, the company warned, “open additional avenues for sensitive data to flow between AI platforms and third-party systems,” complicating efforts to trace where confidential information is sent and who can access it.

Phishing Trends and Security Strategies

With employees eager to experiment with emerging AI platforms, attackers are increasingly disguising phishing messages as legitimate AI software. According to Netskope, there was a fall in AI-driven phishing incidents between May 2025 to December 2025, but these cases picked up once again in early 2026. March data showed roughly 100 victims per 100,000 retail users—numbers that, in Netskope’s view, still point to a persistent threat.

To address these risks, the report suggests retailers employ several safeguards: restrict app usage, closely review all web activity, and implement strong data-loss-prevention (DLP) controls designed to keep sensitive data from escaping to unauthorized AI services.

Visibility Gaps Persist for Retailers

Relying on data from July 1, 2025, through July 30, 2026, Netskope’s report highlights that the retail industry finds itself at a crossroads. While management of approved AI tools has significantly advanced, the rapid deployment of embedded and autonomous agent AI has exposed new blind spots. Absent thorough oversight of both approved and covert AI operations, retailers continue to face risks of data exposure and regulatory violations as AI becomes increasingly integral to their business processes.