Skip to content

AI Agents and MCP Shift Enterprise AI Security Risks, New Threat Report Finds

Agentic AI and Model Context Protocol adoption are changing the enterprise AI threat landscape, with downstream data exposure and autonomous coding risks rising sharply, according to Netskope Threat Labs' latest AI Report.

Enterprise AI security has entered a new phase as organizations move beyond trying to control shadow AI and instead grapple with governing autonomous AI agents, according to a new report from Netskope Threat Labs.

The Netskope Threat Labs AI Report: 2026 concludes that the rapid adoption of agentic AI and the Model Context Protocol (MCP) is fundamentally changing enterprise risk, creating new concerns around unauthorized data access, malicious code execution, and increasingly interconnected AI environments.

Rather than focusing primarily on employees sending sensitive information to AI chatbots, security teams now must contend with AI systems that retrieve, process, and act on enterprise data autonomously.

Among the report's headline findings is a sharp increase in downstream data policy violations — instances where AI systems return information that users or AI agents are not authorized to access. Netskope attributes much of that increase to a fourfold rise in MCP traffic as organizations connect AI models directly to internal data stores. At the same time, autonomous coding tools have rapidly become mainstream, increasing the potential for malicious code execution and software supply chain risks.

The report notes that Claude Code is now used by 75% of organizations surveyed, while OpenAI Codex has reached 58% adoption—both representing explosive growth from almost no enterprise adoption a year ago.

Source: Netskope

AI adoption accelerates

Enterprise AI adoption continues to grow rapidly.

Netskope found that the median organization increased weekly AI usage from 34% of employees to 59% over the past year. Meanwhile, average prompt volume has more than tripled, rising from roughly 1,500 prompts per week to more than 4,700. The company expects both user adoption and prompt volume to begin leveling off during the second half of 2026 as organizations become more deliberate about AI deployments.

While managed AI applications have become more common, shadow AI has not disappeared. According to the report, 56% of AI users rely exclusively on organization-managed AI tools, while 30% still use only personal AI applications. Netskope says organizations increasingly appear to be accepting that shadow AI will persist and are shifting toward implementing governance controls instead of attempting to eliminate its use altogether.

Coding agents drive new risks

The report identifies agentic coding as one of the biggest changes in enterprise AI over the past year.

Traditional AI-assisted coding tools such as GitHub Copilot and Cursor have given way to autonomous coding agents capable of generating and executing larger amounts of code with minimal human oversight.

Netskope warns that this shift increases exposure to prompt injection, malicious code generation, and sensitive data mishandling because coding agents frequently interact with repositories, development pipelines, and external services.

The report also highlights explosive growth in MCP, the open standard that allows AI models to connect directly to external tools and data sources.

According to Netskope, MCP users increased by 250% while MCP transactions rose 375% over just ten weeks. Much of that traffic comes from AI coding agents such as Claude Code and Codex connecting to remote MCP servers.

Downstream data exposure grows

Although upstream data policy violations — employees sending sensitive information to AI tools — remain the most common AI security issue, Netskope found downstream violations growing much faster.

Average downstream violations increased from 12 to 31 incidents per week during the past year. Among the top quarter of organizations, that figure rose from 72 to 206 weekly incidents.

The report links that increase directly to growing AI interconnectedness through MCP and retrieval-augmented generation (RAG), which allow AI systems to access enterprise data repositories and business applications.

Netskope also warns that malicious code returned by AI systems represents one of the most severe enterprise AI risks, particularly as autonomous coding agents increasingly execute generated code automatically. The report says malicious outputs may originate from indirect prompt injection attacks, compromised AI tooling, vulnerable training data, or model hallucinations.

Source: Netskope

Traditional threats evolve alongside AI

Beyond AI-native attacks, Netskope says organizations should continue watching for more familiar threats adapted to AI environments.

The report points to fake AI installers, trojanized developer tools, malicious AI-generated links, and attackers exploiting AI optimization techniques to lure users toward malicious content. It predicts those attacks will continue growing as organizations accelerate AI adoption across development and business workflows.

To address the changing threat landscape, Netskope recommends organizations adopt centralized AI visibility, granular governance, and layered protection built around zero-trust principles.

Among its recommendations are deploying AI gateways to inspect all AI traffic, monitoring MCP communications, implementing real-time data loss prevention and semantic guardrails, strengthening supply chain security for AI infrastructure, and aligning governance with frameworks including MITRE ATLAS and the OWASP Top 10 for LLM Applications.

HOU.SEC.CON CTA

Latest