The security provider Netskope is increasingly registering cases in companies where AI systems share sensitive data with unauthorized users. The number of such incidents per company rose on average from twelve to 31 per week within a year. As a driver, the Netskope report from July 28, 2026, cites the rapid spread of the open connection standard Model Context Protocol.
Netskope classifies downstream violations as a growing risk
Netskope refers to these incidents as “downstream violations”: cases where an AI system provides a user or an agent with information they should not actually have access to – for example, when an internal assistant accidentally outputs salary data or contract drafts to the wrong department. The Netskope AI Report 2026 now classifies such violations as the second most common type of violation in corporate AI systems, with 924 out of 10,000 evaluated alerts. In the most affected quarter of the companies surveyed, the number rose from 72 to 206 incidents per week – a significantly steeper increase than in classic violations, where employees themselves send sensitive data to an AI model. The figures come from Netskope’s own telemetry on its self-operated security platform and are independently unverified. Ray Canzanese, head of Netskope Threat Labs, concludes that security teams will need to monitor not only which prompts employees send to AI models, but also what data the systems return and to whom.
Model Context Protocol connects agents with internal systems
As a central driver, the report identifies the Model Context Protocol (MCP), an open standard through which AI agents access external data sources and tools. According to Netskope, within ten weeks the number of users accessing remote MCP servers increased by 250 percent, and the number of MCP transactions rose by 375 percent. The more companies connect their AI agents to databases, file repositories, or ticket systems via MCP, the larger the attack surface for incorrect permissions becomes. How real this risk is was demonstrated in June 2026 by a security vulnerability in the open-source platform Ruflo: a single HTTP call without login credentials was enough to open foreign server shells and steal access keys for language models. In response, Netskope announced its own control functions for MCP communication, intended to check traffic between agents and connected services in both directions.
More AI security incidents are piling up this year
The report joins a series of AI security incidents in 2026. Just at the beginning of August, Meta admitted that its model Muse Spark 1.1 had unlawfully breached another company due to a misconfiguration at testing partner Irregular – previously, Anthropic had already acknowledged three similar incidents with Claude models. In response to this accumulation, OpenAI, Google, Anthropic, and Meta agreed in August with the White House on a voluntary testing regime for the hacking capabilities of their models. The Netskope figures concern a different risk than the previous incidents, however: it is not about AI models actively breaching foreign systems, but about authorized corporate AI inadvertently passing information to the wrong recipients during everyday operations – a risk that, according to Netskope, grows with each new MCP connection.
It remains to be seen how quickly companies will adjust their access rights to the new attack surface before the next Netskope survey delivers new figures. The report recommends that security teams treat every agent interaction as a potential execution path going forward, not just as a simple data request. Whether this so-called bidirectional checking takes hold in practice will only become clear once MCP connections become standard at even more companies.


