Netskope AI Report 2026 outlines downstream policy violations and MCP-driven data exposure
50th article in the last 90 days, one of 256 articles referencing Netskope. Previous coverage: Schneider Electric and AMD, agent security and sovereign cloud - Week of July 27, 2026 (Jul 2026).
Companies mentioned
Best suited for
- Seniority
- Director
- Job function
- Cybersecurity / Information Security
- Persona
- Security Operations Leader
- Buyer role
- Decision Maker / Budget Holder
- Buyer journey
- Need to Buy
- Adoption curve
- Early Adopters
- Technology maturity
- Market Correction
- Industry
- Information Technology / Software & Services / IT Services / Internet Services & Infrastructure
Our classification, not the publisher's statement. Best suited for, not only for.
Netskope’s AI report covering June 2025 through July 2026 says the security risk focus has shifted from prompt-based data leakage to downstream policy violations, with new exposure from Model Context Protocol traffic and agentic coding tools.
Research Overview
The report analyzes changes in AI-related security risks across the period from June 2025 through July 2026, referencing comparisons to Netskope’s prior report.
It frames the updates around architectural changes that affect how AI services access and process data in enterprise environments.
Key Findings
Netskope identifies downstream policy violations as the primary architectural risk.
It also reports a shift away from earlier emphasis on “upstream” prompt-based leakage toward risks that arise when systems can return data beyond intended authorization boundaries.
Technical Breakdown
The report states that it observed a fourfold increase in Model Context Protocol (MCP) traffic over a 10-week window, attributing this to MCP’s role in bridging internal data stores with external models.
Netskope says this enables a direct path for AI services to return sensitive data to users or agents that are not authorized to access it, describing the issue as an architectural vulnerability that requires granular downstream inspection.
Operational Impact
Netskope reports that agentic coding tool adoption has increased from negligible levels a year prior to 75% of organizations for Claude Code and 58% for Codex.
It characterizes each agentic interaction as a potential execution vector for malicious code, and it links the trend to new execution pathways in enterprise threat models.
Threat Analysis
The report states that attackers are expanding from simple AI baits to trojanized developer tools and fake AI installers.
Netskope also says attackers use techniques to trick AI apps into surfacing malicious content, including malicious code and links to malicious resources on the web.
Across June 2025 through July 2026, Netskope’s report points to downstream policy violations, rising MCP traffic exposure, and increased agentic coding usage as architectural drivers, while describing weaponized supply-chain tactics targeting developer tooling and AI installers. Blog Signals brief is a fact-based summary of the vendor blog.
Blog post, originally published by Ray Canzanese at netskope.com.