Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

The state of AI risk in ANZ: close one gap, two more open

More than half of ANZ employees use personal AI accounts at work, and AI agent connections are surging. Keeping data safe now means monitoring AI traffic both ways.

By Netskope • Thu, 08 Oct 2026 •
The state of AI risk in ANZ: close one gap, two more open

Every week brings new developments in the AI security landscape, fuelling headline-monopolising debates around international regulations and guardrails. While these conversations are important, for most organisations in Australia and New Zealand, they are beside the point. They serve as a distraction from the organisation-level responsibility needed to secure AI. AI risk is already proliferating inside local organisations' own networks, applications, and daily workflows, and it can and should be mitigated by the organisations themselves.

The risk manifests in the AI tools staff use without approval, in the agents now wired into corporate infrastructure, and in the data moving both into and out of AI applications. Regardless of international AI politics or future regulations, the responsibility will always fall on organisations to address their own existing and emerging AI risks.

The latest Netskope Threat Labs Australia & New Zealand 2026 report outlines how much AI risk has become a multi-layered problem.

With more than half of employees in ANZ (55%) still using personal AI accounts at work (accounts with no governance alignment on data ownership or controls), shadow AI is proving stubborn. This is higher than the global average (44%), and this is happening even as adoption of organisation-managed AI tools has more than doubled over the same period, from 34% to 75%.

The way AI systems interact with business data is increasingly complex. Adoption of the Model Context Protocol (MCP), an open standard letting AI models and agents connect to data sources and business systems, is a reliable indicator of how quickly agentic AI is taking hold inside organisations. In just two months, the number of agents within ANZ organisations interacting with remote MCP servers increased by 89%, and MCP-related events grew by 69%. Each connection is a new pathway for data to move between AI tools and other internal and external systems, and traditional security tools were never designed to monitor or secure that traffic.

This is also why AI risk can no longer be treated as a one-way street. Security teams have historically focused on stopping sensitive data leaving the organisation through AI prompts. But downstream data policy violations, where AI systems surface sensitive information to users who aren't authorised to see it, are now the second most common form of AI security incident in ANZ, accounting for almost 7% of all AI security alerts among organisations with the ability to detect them. AI security is not just about outbound traffic.

Adjacent AI threats compound the picture. AI systems built and hosted within ANZ organisations suffer prompt injection and jailbreaking attempts at twice the global rate (2.5% vs 1.3% of all AI-related incidents), while attackers increasingly exploit the implicit trust users place in AI-generated answers, surfacing malicious link within AI responses, and distributing fake AI installers and trojanised developer tools designed to steal credentials. For every 100,000 workers in ANZ, over the past year an average of 67 per week clicked on malicious links that were served up to them within AI responses.

This is a whole new landscape that requires a new response. Redesigning security architectures for the AI era means re-scoping the baseline for data security practices to include monitoring and securing bi-directional AI traffic, AI agents, model behaviours, and new machine-to-machine communication protocols such as MCP, as well as more broadly preserving the integrity of the AI supply chain.

A multi-layered threat demands a multi-layered response, but trying to achieve this with a stack of disparate tools, however efficient, just creates new headaches. Netskope's own research into AI security posture backs this up: 94% of organisations report visibility gaps in AI activity, and only 6% have complete visibility into their AI pipeline. Deploying appropriate tools to address the risks we discussed is one thing, but keeping a full, consolidated picture of AI operations and alerts in the process is another.

Rather than bolting on another standalone tool, organisations should prioritise consolidated AI security, built on an architecture where every layer talks to the others; with discovery and visibility across every user, app, model and agent; monitoring of how AI tools are used and data moves; control over who can use what, and what data they can share; detection of risky behaviour and policy violations as they happen; and remediation that closes the loop before a risky action becomes an incident. Built well, that architecture turns AI risk from a blind spot into something organisations can see, govern and act upon.

Netskope Skylight AI Security brings these pillars together in a single platform, giving security teams one place to discover, govern and protect AI use across employees, agents, self-hosted models and data. Learn more at https://www.netskope.com/products/ai-products.

Tags:
Cyber Daily Discover

A cloud-native platform that offers converged security and networking services to enable fast and secure AI, cloud, and...