Skip to main content

Netskope AI Report 2026 outlines downstream policy violations and MCP-driven data exposure

Netskope’s AI report covering June 2025 through July 2026 says the security risk focus has shifted from prompt-based data leakage to downstream policy violations, with new exposure from Model Context Protocol traffic and agentic coding tools.

Research Overview

The report analyzes changes in AI-related security risks across the period from June 2025 through July 2026, referencing comparisons to Netskope’s prior report.

It frames the updates around architectural changes that affect how AI services access and process data in enterprise environments.

Key Findings

Netskope identifies downstream policy violations as the primary architectural risk.

It also reports a shift away from earlier emphasis on “upstream” prompt-based leakage toward risks that arise when systems can return data beyond intended authorization boundaries.

Technical Breakdown

The report states that it observed a fourfold increase in Model Context Protocol (MCP) traffic over a 10-week window, attributing this to MCP’s role in bridging internal data stores with external models.

Netskope says this enables a direct path for AI services to return sensitive data to users or agents that are not authorized to access it, describing the issue as an architectural vulnerability that requires granular downstream inspection.

Operational Impact

Netskope reports that agentic coding tool adoption has increased from negligible levels a year prior to 75% of organizations for Claude Code and 58% for Codex.

It characterizes each agentic interaction as a potential execution vector for malicious code, and it links the trend to new execution pathways in enterprise threat models.

Threat Analysis

The report states that attackers are expanding from simple AI baits to trojanized developer tools and fake AI installers.

Netskope also says attackers use techniques to trick AI apps into surfacing malicious content, including malicious code and links to malicious resources on the web.

Across June 2025 through July 2026, Netskope’s report points to downstream policy violations, rising MCP traffic exposure, and increased agentic coding usage as architectural drivers, while describing weaponized supply-chain tactics targeting developer tooling and AI installers. Blog Signals brief is a fact-based summary of the vendor blog.