AI systems expose sensitive data in ANZ, report finds
Wed, 16th Sep 2026 (Today)
Netskope Threat Labs has published an Australia and New Zealand cyber threat report focused on AI-related security incidents. It identifies unauthorised exposure of sensitive data by AI systems as the region's second most common type of AI security incident.
The findings point to a shift in risk as companies expand their use of AI tools and autonomous agents. Organisations initially focused on stopping staff from sending sensitive information into AI systems. Attention must now also turn to what AI systems return to users and the connections they make with other tools and data sources.
Downstream data policy violations, in which AI systems surface sensitive information to people not authorised to see it, accounted for 666 out of every 10,000 alerts in organisations able to track that risk. Upstream incidents, where users or agents send sensitive information to an AI application, remained by far the largest category at 8,300 out of every 10,000 AI security alerts.
The report links many downstream incidents to the growing use of AI agents. It highlights the Model Context Protocol, or MCP, an open standard for connecting AI models and agents to data sources and software tools, as a sign of rising agentic AI activity inside organisations.
Over two months, the number of agents in Australia and New Zealand organisations interacting with remote MCP servers rose 89%, according to the report. MCP-related events increased 69% over the same period, creating new channels for data to move between AI applications and internal or external systems.
Those connections introduce risks because many existing security tools were not built to monitor or secure this type of traffic. As a result, organisations are trying to apply older controls to newer forms of machine-to-machine communication.
Attack methods
The report also found that prompt injection and jailbreaking attacks are hitting AI systems in Australia and New Zealand at twice the global rate. It recorded 254 alerts per 10,000 in the region, compared with 129 globally.
These attacks are designed to alter the behaviour of AI systems or induce them to provide harmful or sensitive material. The researchers also pointed to AI Engine Optimisation techniques used by attackers to manipulate public AI tools into citing malicious links as legitimate sources.
That tactic is producing measurable results. Over the past 12 months, an average of 67 workers a week per 100,000 in Australia and New Zealand clicked on malicious links contained in AI responses. That figure reached 175 at the end of 2025.
Attackers are also impersonating AI brands and tools to steal credentials or deceive users. These campaigns include fake AI application installers, altered developer tools, and other AI-themed lures. In May, 140 out of every 100,000 workers in the region fell for such lures.
Adoption trends
The report also charts rapid changes in which AI products are being used at work. Anthropic Claude Platform was the most widely used AI application in Australia and New Zealand, appearing in 81% of organisations in the dataset.
ChatGPT ranked second at 68%, followed by Microsoft 365 Copilot at 66%. Claude had not appeared in the top 10 until August 2025, after which adoption rose sharply.
Use of managed AI tools increased strongly over the period covered by the report, rising from 34% to 75%. Even so, 55% of employees in Australia and New Zealand were still using personal AI accounts at work, showing that shadow AI remains embedded in many workplaces.
The report suggests this mix of official and personal use complicates governance. Employers may deploy approved AI products, but employees can still access external tools outside standard oversight.
Changing phishing picture
Alongside the rise of AI-related threats, the report found signs that traditional phishing may be becoming less effective. The number of users clicking phishing links fell by almost 60%, from 91 to 41 clicks per 10,000 users.
That decline contrasts with the growth in attacks that exploit trust in AI outputs and AI-branded software. Rather than relying only on email-based deception, attackers appear to be adapting their methods to fit the growing use of AI in office work and software development.
The report is based on aggregated usage data collected through the Netskope One platform from a subset of customers in Australia and New Zealand between July 2025 and mid-July 2026.
"Our research outlines the increasing complexity of AI risks ANZ organisations are facing, and new threats are going to keep emerging as enterprise AI use increases and evolves," said Ray Canzanese, Director of Netskope Threat Labs. "This is a whole new landscape that requires a new response; redesigning security architectures for the AI era, re-scoping the baseline for data security practices to include monitoring and securing bi-directional AI traffic, AI agents, model behaviours, and new machine-to-machine communications protocols such as the MCP, as well as more broadly preserving the integrity of the AI supply chain."