ANZ AI Systems Expose Sensitive Data, Report Reveals
AI systems in Australia and New Zealand are exposing sensitive corporate data, according to a new report from Netskope Threat Labs. The findings point to a shift in how organizations need to think about security as AI adoption expands. It is no longer just about what employees type into a chatbot. It is increasingly about what the AI sends back.

Unauthorized exposure of sensitive data is now the second most common AI security incident across the region. Downstream data policy violations, where AI systems reveal sensitive information to people who should not see it, accounted for 666 alerts per 10,000 tracked. Upstream incidents, where users send data into AI tools, remain more common at 8,300 alerts per 10,000, but the downstream number is the one catching security teams off guard.

Agents Are Opening New Data Pathways

The rise of AI agents is driving much of this downstream risk. The report points to growing use of the Model Context Protocol (MCP), an open standard that connects AI models and agents to external data sources, as clear evidence of expanding agentic activity.

Over a two month window, ANZ organizations saw an 89% increase in agents interacting with remote MCP servers, alongside a 69% rise in MCP related events overall. Each new connection creates another channel for data to move through, and many existing security tools were never built to monitor traffic like this.

Why Attacks Land Harder Here Than Elsewhere

Prompt injection and jailbreaking attempts are twice as common in ANZ compared to the global average, with 254 alerts per 10,000 against a global rate of 129. Both attack types aim to manipulate AI behavior or coax out sensitive information the system was not supposed to share.

A newer tactic, AI Engine Optimisation, involves attackers seeding malicious links to make them appear legitimate inside public AI tools. This pushed weekly click rates on malicious links to 67 per 100,000 workers, peaking at 175 by late 2025. A related tactic impersonates trusted AI brands through fake installers and altered developer tools. In May alone, 140 out of every 100,000 ANZ workers fell for one of these AI themed lures.

  • Prompt injection and jailbreaking: 254 alerts per 10,000 in ANZ vs 129 globally
  • Malicious link clicks: peaked at 175 per 100,000 workers weekly in late 2025
  • Fake AI installer lures: 140 per 100,000 workers fell for these in May

Employees Are Bypassing Official Tools

Workplace AI usage is shifting fast, and unevenly. Anthropic’s Claude Platform leads adoption in ANZ, used by 81% of organizations, followed by ChatGPT at 68% and Microsoft 365 Copilot at 66%.

Managed AI tool adoption jumped from 34% to 75% over the reporting period, a sign that companies are actively trying to bring AI use under some kind of oversight. Despite that, 55% of employees still use personal AI accounts for work tasks. That gap, commonly called shadow AI, means a meaningful share of sensitive company data is passing through tools no security team ever approved or can see.

Phishing Is Losing Ground to AI Themed Lures

Traditional phishing appears to be working less often. Clicks on phishing links dropped by almost 60% in the report’s window, which sounds like good news until you see what replaced it. Attackers are adapting by exploiting trust in AI outputs and AI branded software instead of relying on the old email based tricks that security training has spent years addressing.

Ray Canzanese, Director of Netskope Threat Labs, described the shift as requiring a fundamentally different response. This is a whole new landscape that requires a new response, redesigning security architectures for the AI era.

Hashlytics Take

The headline stat here (data leaking out of AI systems) is really a symptom, not the disease. The actual story is that agentic AI is quietly building data pipelines faster than security teams can map them, and MCP adoption jumping 89% in two months is the clearest evidence of that. Most security tooling was designed to watch what goes into a system, not what an autonomous agent decides to pull out and hand to a downstream process. Organizations chasing shadow AI usage numbers are solving yesterday’s problem while agents open tomorrow’s.

Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates