Retailers report real progress in reining in ad‑hoc AI use, yet a year-long Netskope analysis shows that new forms of AI — agentic agents and embedded AI features inside everyday apps — are creating blind spots that risk exposing regulated customer data.

The Netskope dataset (July 1, 2025–July 30, 2026) finds fewer employees using ungoverned AI tools, but a sharp rise in agentic activity and widespread AI features inside software mean governance must widen beyond approved chatbots and assistants.

Where governance improved — and where it didn’t

The most defensible change is centralization. Netskope reports the share of retail employees using ungoverned AI tools fell from 70% to 44%, while the share using officially approved tools rose from 40% to 73%. Roughly two‑thirds of retail staff now use some form of standalone AI tool.

That shift reduces one class of risk: unauthorized apps and shadow experimentation. But the same report shows nearly all retail employees use software with AI features, and 90% use AI tools trained on customer data. In practice, sensitive information can be processed by background AI functions embedded in routine applications as easily as by standalone models.

Netskope tracked AI‑related data‑policy violations and found 56% involved data subject to federal or state regulation. Another 20% involved source code, and 16% involved passwords or API keys. Those categories carry regulatory, contractual and reputational consequences for retailers that mishandle customer or proprietary data.

Agentic AI: a visibility and control problem

Agentic AI — autonomous agents that perform multi‑step tasks and coordinate other tools — is the report’s fast‑growing concern. Netskope observed about a 400% increase in retail‑sector agents interacting with remote Model Context Protocol (MCP) servers during the study period.

Remote MCP connections create additional pathways for data to move between internal systems and external AI services. Compounding the risk, many organizations lack the ability to trace which remote servers an agent contacts. When agents can access business databases, customer records or payment tools, that opacity becomes a governance gap.

Attackers have noticed. Netskope documents a renewed wave of AI‑themed phishing that mimics trusted tools. After a decline in late 2025, AI‑related phishing rose again in early 2026 and reached roughly 100 users per 100,000 by March 2026 — a reminder that employee discovery and onboarding of new AI tools is itself an attack surface.

Practical steps for marketing, commerce and security teams

Netskope reiterates core defenses: block unnecessary apps, inspect web traffic, and apply data‑loss‑prevention (DLP) policies to detect sensitive information flowing to ungoverned AI services. Those remain necessary but not sufficient.

For teams that handle customer data, immediate priorities are inventory and control. Map where regulated data and customer records live; identify every AI touchpoint, including embedded features inside SaaS products; and enforce access controls and targeted DLP rules. Monitor outbound connections from agentic tools and require vendors to disclose where model context and logs are stored and processed.

Employee education must match technical controls. Phishing that promises AI productivity gains is effective because staff often lack clear policies on sanctioned AI tools. Training should include specific examples of risky AI behaviors and a simple process for getting a new tool evaluated and approved.

What to watch next

Expect regulators and auditors to scrutinize incidents where regulated customer data moves through third‑party AI services. Vendors will face pressure for better provenance and controls around model‑context interactions. For retail leaders, the practical shift is conceptual: treat AI visibility as a data‑governance problem rather than only a productivity initiative. Broaden governance to include agentic flows and embedded AI features, and prioritize vendor transparency and outbound‑connection monitoring.