Security

Netskope: AI data leaks at companies double in a year

3 min read

TL;DR Too Long; Didn’t read

The security provider Netskope classifies downstream violations – AI systems delivering data to unauthorized users – as the second most common type of violation in corporate AI, with 924 out of 10,000 alerts. According to the report, the main driver is the rapid spread of the Model Context Protocol (MCP), through which agents access internal systems. Netskope advises that the data traffic of AI agents should be checked in both directions in the future.

A robotic arm passes file folders through a leaking pipe to a silhouetted figure outside a locked company building, with a network of plugs and cables branching in the background. Image generated with GPT Image 2

Key takeaways

  • Netskope now counts 31 instead of twelve AI data leaks per company per week – more than a doubling within a year.
  • At the most affected companies, the number of incidents rose from 72 to 206 weekly.
  • The main driver is the Model Context Protocol: MCP user numbers grew by 250 percent in ten weeks.
  • MCP transactions increased by 375 percent in the same period, while companies connect AI agents to internal systems.
  • A security vulnerability in the Ruflo platform already showed in June how unprotected MCP interfaces can be exploited.
  • Netskope recommends bidirectional checking: treat agent interactions as execution paths in the future, not just as data requests.

The security provider Netskope is increasingly registering cases in companies where AI systems share sensitive data with unauthorized users. The number of such incidents per company rose on average from twelve to 31 per week within a year. As a driver, the Netskope report from July 28, 2026, cites the rapid spread of the open connection standard Model Context Protocol.

Netskope classifies downstream violations as a growing risk

Netskope refers to these incidents as “downstream violations”: cases where an AI system provides a user or an agent with information they should not actually have access to – for example, when an internal assistant accidentally outputs salary data or contract drafts to the wrong department. The Netskope AI Report 2026 now classifies such violations as the second most common type of violation in corporate AI systems, with 924 out of 10,000 evaluated alerts. In the most affected quarter of the companies surveyed, the number rose from 72 to 206 incidents per week – a significantly steeper increase than in classic violations, where employees themselves send sensitive data to an AI model. The figures come from Netskope’s own telemetry on its self-operated security platform and are independently unverified. Ray Canzanese, head of Netskope Threat Labs, concludes that security teams will need to monitor not only which prompts employees send to AI models, but also what data the systems return and to whom.

Model Context Protocol connects agents with internal systems

As a central driver, the report identifies the Model Context Protocol (MCP), an open standard through which AI agents access external data sources and tools. According to Netskope, within ten weeks the number of users accessing remote MCP servers increased by 250 percent, and the number of MCP transactions rose by 375 percent. The more companies connect their AI agents to databases, file repositories, or ticket systems via MCP, the larger the attack surface for incorrect permissions becomes. How real this risk is was demonstrated in June 2026 by a security vulnerability in the open-source platform Ruflo: a single HTTP call without login credentials was enough to open foreign server shells and steal access keys for language models. In response, Netskope announced its own control functions for MCP communication, intended to check traffic between agents and connected services in both directions.

More AI security incidents are piling up this year

The report joins a series of AI security incidents in 2026. Just at the beginning of August, Meta admitted that its model Muse Spark 1.1 had unlawfully breached another company due to a misconfiguration at testing partner Irregular – previously, Anthropic had already acknowledged three similar incidents with Claude models. In response to this accumulation, OpenAI, Google, Anthropic, and Meta agreed in August with the White House on a voluntary testing regime for the hacking capabilities of their models. The Netskope figures concern a different risk than the previous incidents, however: it is not about AI models actively breaching foreign systems, but about authorized corporate AI inadvertently passing information to the wrong recipients during everyday operations – a risk that, according to Netskope, grows with each new MCP connection.

It remains to be seen how quickly companies will adjust their access rights to the new attack surface before the next Netskope survey delivers new figures. The report recommends that security teams treat every agent interaction as a potential execution path going forward, not just as a simple data request. Whether this so-called bidirectional checking takes hold in practice will only become clear once MCP connections become standard at even more companies.

Frequently asked questions

What exactly is a downstream violation?

Netskope refers to cases where an AI system or agent provides a user with information for which they do not have access rights – for example, because internal permissions were not properly transferred to the AI connection.

What distinguishes MCP from classic AI chatbots?

The Model Context Protocol connects AI agents directly with external tools and data sources such as databases or document repositories, rather than just responding to text inputs. This allows an agent to independently perform actions and retrieve data.

Are European companies also affected by the numbers?

The report does not differentiate by region; Netskope describes the development as a global trend among its international customer base. The company does not provide specific numbers for Germany or the EU.

How can companies reduce the risk?

Netskope recommends continuously checking the permissions of AI agents and controlling data traffic in both directions, rather than only monitoring outgoing prompts.

Where can the full report be viewed?

Netskope publishes the AI Report 2026 on its own website; several trade outlets summarize the key figures without registration.

Sources (3)
  1. Netskope AI Report 2026
  2. cybrsecmedia: AI Agents and MCP Expand Enterprise AI Security Risks
  3. itbrief.com.au: Netskope says downstream AI data breaches are surging

Your AI update for the work week

Once a week, the most important AI news – plus one practical tip to try right away. No spam, unsubscribe anytime.

← Back to the blog