Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags Enterprise Adoption — Threadlinqs Intelligence
As of 2026-07-28, Netskope "Beyond Shadow AI" Report: Shadow AI Data Exposure Escalates as Agentic AI/MCP Governance Lags Enterprise Adoption is a medium-severity threat intel threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1735 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_INTEL
Netskope's "Beyond Shadow AI" report (telemetry window: October 2024 - October 2025) finds organization-managed GenAI account usage rose from 25% to 62% year-over-year, yet GenAI data-policy
Netskope's "Beyond Shadow AI" report analyzes telemetry from its Security Cloud customer base over an October 2024-October 2025 window and finds a mixed security picture for enterprise generative-AI (GenAI) adoption. On the positive side, the share of GenAI users on company-approved, organization-managed accounts rose sharply from 25% to 62% year-over-year, while personal, unmanaged-account usage fell from 78% to 47%. A residual 9% of users (up from 4% the prior year) actively switch between personal and enterprise accounts for the same GenAI tools, undermining the value of managed-account controls by giving users an easy escape hatch from monitored channels.
Despite that account-management progress, GenAI data-policy violations doubled year-over-year, with the average organization recording approximately 223 violations per month, committed by roughly 3% of users. The three most common categories of leaked data were source code (42% of violations), regulated data such as PII/PHI/financial records (32%), and intellectual property (16%). Netskope names ChatGPT, Google Gemini, and Microsoft 365 Copilot as the GenAI tools most frequently accessed through personal, non-organizational credentials, stating: "A substantial share of employees are relying on tools such as ChatGPT, Google Gemini and Copilot, using credentials not associated with their organization." Netskope's own recommendation is that enterprises pair "clearer policies, better provisioning, and ongoing visibility into how AI tools are actually being used" rather than relying on blocking alone, since employee behavior is consistently outpacing governance policy.
The report separately identifies agentic AI and the Model Context Protocol (MCP) - the emerging standard integration layer that lets LLM-based agents call external tools, APIs, and data sources - as an escalating, largely ungoverned attack surface: only 8% of organizations report having any policy governing MCP use at all. This finding is corroborated by independent security research: Checkmarx documents concrete MCP-specific attack techniques including tool poisoning (hidden malicious logic embedded in tool descriptions/schemas), confused-deputy privilege escalation (MCP servers acting on a user's behalf without properly verifying authorization, enabling cross-user access via OAuth token reuse), supply-chain "rug pull" attacks (a previously trustworthy MCP server or dependency turning malicious via an update), tool shadowing/typosquatting, and context/resource poisoning of shared agent state. Cisco's AI Threat Intelligence and Security Research group (reported via Help Net Security, 2026-02-23) found only 29% of organizations feel prepared to secure agentic AI deployments, an 92% success rate for multi-turn prompt-injection/jailbreak attacks across eight tested open-weight models, and documented a real-world case of a fake npm package used in an MCP-adjacent supply chain to copy outbound agent messages to an attacker-controlled address; the same research noted China-linked threat actors have automated an estimated 80-90% of an attack chain using jailbroken AI coding assistants.
In response to the governance gap, Netskope has begun extending its own platform (Netskope One) with MCP-specific controls - Cloud Confidence Index risk scoring for MCP servers, a default-block option for unapproved MCP traffic, least-privilege access restriction for AI agents, DLP inspection of MCP traffic for IP/credential leakage, and detailed logging of MCP sessions, tool calls, and responses - per Chief Product Officer John Martin. At the regulatory level, CISA, the NSA, and the cyber agencies of Australia, Canada, New Zealand, and the UK jointly published "Careful Adoption of Agentic AI Services" on 2026-05-01, the first coordinated multinational guidance on agentic AI risk, defining five risk categories (privilege escalation, design/configuration failures, behavioral misalignment, structural brittleness, and accountability gaps
Target regions: Global
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1199, T1195, T1078, T1204, T1059, T1554, T1548, T1134, T1027, T1036